Series
Anatomy of an Identity Incident
Forensic write-ups of real public breaches, strictly at the identity layer. No vendor villains — just what broke, what would have caught it, and who was actually responsible.
Fourteen Incidents, One Table: Where the Last Mile Broke
Fourteen identity breaches from this series in one table — the way in, what looked under control, the unowned work that actually failed, and who caught it. The pattern is hard to miss once they line up.
The AI Tool You Connected and Forgot
Anatomy of an Identity Incident — Vercel, April 2026. An OAuth token an employee granted to an AI tool months earlier, sitting forgotten, became the way in after the AI vendor got infected.
Seven Hundred Breaches, One Stolen Integration
Anatomy of an Identity Incident — the Salesloft Drift campaign, 2025. The attackers didn't breach 700 companies. They breached one integration that already had the keys to all of them.
Two Years Later, the Same Phone Call
Anatomy of an Identity Incident — M&S and Co-op, 2025. The exact playbook that took down MGM in 2023, run again, against an outsourced service desk, for a few hundred million pounds.
The App You Authorized Yourself
Anatomy of an Identity Incident — the UNC6040 Salesforce campaign, 2025. No password was stolen and no token was cracked. An employee was talked into authorizing a malicious app, and the app did the rest.
It Wasn't a Vulnerability. It Was a Setting Left Off.
Anatomy of an Identity Incident — Snowflake, 2024. The platform was never breached. Around 165 customers were, because multi-factor authentication was optional and nobody made it mandatory.
The Test Account That Read the Executives' Email
Anatomy of an Identity Incident — Midnight Blizzard, January 2024. A forgotten test account with no MFA, and a forgotten app with too much access, were enough to reach senior leadership's inbox.
When the Vendor Is Breached but the Incident Is Yours
Anatomy of an Identity Incident #1 — Okta's support case system, October 2023. What broke at the identity layer, and who was actually responsible for catching it.
A Phone Call Beat Every Control
Anatomy of an Identity Incident — MGM and Caesars, September 2023. No exploit, no malware. Someone called the help desk, and the help desk issued an identity to the wrong person.
Nothing Was Stolen. The Tokens Were Forged.
Anatomy of an Identity Incident — Storm-0558, 2023. A leaked signing key let an attacker mint valid identities for anyone. No password was guessed, because none was needed.
The Vault Was Only as Safe as a Home Computer
Anatomy of an Identity Incident — LastPass, 2022. The decryption keys to every customer's vault backups were reachable through one engineer's personal home PC.
2FA Was On. The Session Walked Out Anyway.
Anatomy of an Identity Incident — CircleCI, January 2023. Malware lifted a 2FA-backed session off one laptop, and a CI platform's vault of customer secrets emptied out.
The Push Notification Was Never the Real Problem
Anatomy of an Identity Incident — Uber, September 2022. Everyone remembers the MFA fatigue. The breach that mattered happened one layer deeper, in a script no one owned.
Same Phish, Two Outcomes
Anatomy of an Identity Incident — the 0ktapus campaign, 2022. One phishing kit hit 130-plus companies. Why most got breached and at least one didn't comes down to a single control.
Your Vendor's Subcontractor Is Your Attack Surface
Anatomy of an Identity Incident — Okta and Sitel, January 2022. The breach happened on a support subcontractor's laptop. The blast radius was every customer tenant that laptop could reach.