All series

Series

Anatomy of an Identity Incident

Forensic write-ups of real public breaches, strictly at the identity layer. No vendor villains — just what broke, what would have caught it, and who was actually responsible.

Anatomy of an Identity IncidentJun 15, 2026

Fourteen Incidents, One Table: Where the Last Mile Broke

Fourteen identity breaches from this series in one table — the way in, what looked under control, the unowned work that actually failed, and who caught it. The pattern is hard to miss once they line up.

Anatomy of an Identity IncidentApr 30, 2026

The AI Tool You Connected and Forgot

Anatomy of an Identity Incident — Vercel, April 2026. An OAuth token an employee granted to an AI tool months earlier, sitting forgotten, became the way in after the AI vendor got infected.

Anatomy of an Identity IncidentSep 15, 2025

Seven Hundred Breaches, One Stolen Integration

Anatomy of an Identity Incident — the Salesloft Drift campaign, 2025. The attackers didn't breach 700 companies. They breached one integration that already had the keys to all of them.

Anatomy of an Identity IncidentJul 15, 2025

Two Years Later, the Same Phone Call

Anatomy of an Identity Incident — M&S and Co-op, 2025. The exact playbook that took down MGM in 2023, run again, against an outsourced service desk, for a few hundred million pounds.

Anatomy of an Identity IncidentJun 25, 2025

The App You Authorized Yourself

Anatomy of an Identity Incident — the UNC6040 Salesforce campaign, 2025. No password was stolen and no token was cracked. An employee was talked into authorizing a malicious app, and the app did the rest.

Anatomy of an Identity IncidentJul 15, 2024

It Wasn't a Vulnerability. It Was a Setting Left Off.

Anatomy of an Identity Incident — Snowflake, 2024. The platform was never breached. Around 165 customers were, because multi-factor authentication was optional and nobody made it mandatory.

Anatomy of an Identity IncidentFeb 5, 2024

The Test Account That Read the Executives' Email

Anatomy of an Identity Incident — Midnight Blizzard, January 2024. A forgotten test account with no MFA, and a forgotten app with too much access, were enough to reach senior leadership's inbox.

Anatomy of an Identity IncidentNov 30, 2023

When the Vendor Is Breached but the Incident Is Yours

Anatomy of an Identity Incident #1 — Okta's support case system, October 2023. What broke at the identity layer, and who was actually responsible for catching it.

Anatomy of an Identity IncidentOct 10, 2023

A Phone Call Beat Every Control

Anatomy of an Identity Incident — MGM and Caesars, September 2023. No exploit, no malware. Someone called the help desk, and the help desk issued an identity to the wrong person.

Anatomy of an Identity IncidentSep 12, 2023

Nothing Was Stolen. The Tokens Were Forged.

Anatomy of an Identity Incident — Storm-0558, 2023. A leaked signing key let an attacker mint valid identities for anyone. No password was guessed, because none was needed.

Anatomy of an Identity IncidentMar 5, 2023

The Vault Was Only as Safe as a Home Computer

Anatomy of an Identity Incident — LastPass, 2022. The decryption keys to every customer's vault backups were reachable through one engineer's personal home PC.

Anatomy of an Identity IncidentFeb 20, 2023

2FA Was On. The Session Walked Out Anyway.

Anatomy of an Identity Incident — CircleCI, January 2023. Malware lifted a 2FA-backed session off one laptop, and a CI platform's vault of customer secrets emptied out.

Anatomy of an Identity IncidentOct 5, 2022

The Push Notification Was Never the Real Problem

Anatomy of an Identity Incident — Uber, September 2022. Everyone remembers the MFA fatigue. The breach that mattered happened one layer deeper, in a script no one owned.

Anatomy of an Identity IncidentSep 12, 2022

Same Phish, Two Outcomes

Anatomy of an Identity Incident — the 0ktapus campaign, 2022. One phishing kit hit 130-plus companies. Why most got breached and at least one didn't comes down to a single control.

Anatomy of an Identity IncidentApr 5, 2022

Your Vendor's Subcontractor Is Your Attack Surface

Anatomy of an Identity Incident — Okta and Sitel, January 2022. The breach happened on a support subcontractor's laptop. The blast radius was every customer tenant that laptop could reach.