Identity attacks cyber threats are today the most common type of intrusion according to a new report from Barracuda. Aberrant logins that are physically impossible and deviate from the user's normal behavior are one of the clearest warning signs of an ongoing breach. If an employee tries to log in from Malmö and Hanoi almost simultaneously, it is something that must be investigated immediately.
Cyber attackers are increasingly targeting user identities. The most common The most common type of security alert over the past year was logins that deviated from the user's normal behavior, such as from a new geographic location, an unknown device, or at an unusual time of day, according to the Barracuda Managed XDR Global Threat Report, which is based on analysis of over two trillion IT events and nearly 600,000 security alerts.
Identity theft cyber threats dominate modern attacks
The report shows that attacks against identities and identity security are at the top of the list of detected threats. At the top are anomalous logins in Microsoft 365 and so-called impossible travel events, where the same account logs in from two locations within a time frame that makes travel physically impossible.
These types of anomalies are a strong indicator of stolen login credentials and compromised accounts.
“Organizations today need to recognize that the user account is one of the most important entry points into the IT environment. A user attempting to log in from a location, using a device, or at a time that is inconsistent with normal behavior is a clear red flag that needs to be investigated immediately,” said Yaz Bekkar, Principal Consulting Architect XDR – EMEA, Barracuda Networks.
Hijacked accounts blend into normal IT activity
According to the report, these types of anomalies are difficult to detect because attackers uses legitimate tools and mimics normal IT activity. A hijacked account can therefore appear to be a regular user until the anomalous behavior pattern is analyzed in detail.
The most frequent alarms linked to hijacked accounts are
• anomalous logins in Microsoft 365 – 42,859 events
• impossible travel in Microsoft 365 – 22,343 events
• login attempts linked to account takeover – 5,131 events
At the same time shows the report that threats that are detected and stopped in computers, mobile phones and other physical devices, for example by SentinelOne, are also among the most common alarms in businesses' IT environments.
Together, these indicators point to attackers having already gained or attempting to gain access to an account and using it to move further in the environment, escalate their privileges, or bypass security controls.
Attackers only need to find a single weak point to succeed. This could be an account that has not been shut down, a misconfigured security setting, or an unprotected device. For organizations with limited resources and many separate security tools, discovering this in a timely manner is a major challenge, concludes Yaz Bekkar.
How organizations can strengthen identity protection
The report highlights several measures that can quickly reduce the risk of intrusion and identify suspicious activities in a timely manner.
• use multi-factor authentication, MFA
• check the assignment and changes of permissions
• monitor anomalous behavior and suspicious logins
• use an integrated security platform with full visibility across networks, devices, servers, cloud storage and email
The purpose of the report is to help organizations, especially those with limited security resources, understand how attacks are carried out in practice and which security gaps are exploited.
Identity security becomes crucial for modern cybersecurity
As more organizations move mission-critical systems to the cloud, identity security is becoming a central part of their cybersecurity strategy. User account protection, multi-factor authentication, and behavioral analytics are therefore essential to stopping identity cyberthreats before attackers can take control of systems and data.
Briefly about the study
The findings are based on the extensive data collected through Barracuda Managed XDR in 2025. The analysis includes more than two trillion IT events, nearly 600,000 security alerts, and over 300,000 protected devices, firewalls, servers, and cloud resources.








