Skip to main content

Cybersecurity statistics / Identity

Threat actors exploited identity issues to gain initial access in 83% of the incidents involving major cloud and SaaS-hosted environments.

PublisherGoogle Cloud
ReportCloud Threat Horizons Report H1 2026
Published10 March 2026
TopicsIdentity , Initial Access, Cloud , SaaS

Published by Google Cloud in Cloud Threat Horizons Report H1 2026, 10 March 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Related statistics

In 2025, browser privilege escalation vulnerabilities surged 183%.
Action1, 15/06/2026
Phishing accounts for 44% of AI-assisted initial access attempts.
IRONSCALES, 06/06/2026
Prior compromise accounted for 10% of initial infection vectors globally, ranking third-most common.
Mandiant, 27/05/2026
Prior compromise was the top initial infection vector in ransomware operations at 30%, up from 15% in 2024.
Mandiant, 27/05/2026
Median time between initial access and hand-off to a secondary threat group was 22 seconds in 2025, down from more than 8 hours in 2022.
Mandiant, 27/05/2026
17% of phishing cases involved voice-based social engineering (vishing).
Google Cloud, 27/05/2026

Get the newsletter

Weekly cybersecurity statistics by email.