Skip to content
TRAC GRC Solution
 

Flexible GRC Platform

Simplify cybersecurity risk management and tackle your cybersecurity challenges with ease. TRAC is a powerful GRC tool that automates the tedious risk assessment process and delivers customized results aligned with regulations, best practices, and your strategic goals.

Blog_HeaderGradients-12
Jon WaldmanAugust 26, 2026

Trust Is the Target: The Identities You Forgot You Had

Trust Is the Target: Identity Attacks in Banking | SBS
8:58

For most of my career, we taught banks to think about security like a castle. Build the wall high enough, dig the moat deep enough, add plenty of layers, and the bad guys stay outside.

That model is not dying. It's dead.

Today's attacker doesn't want to break through your wall. Breaking in is loud, slow, and expensive. Logging in is quiet, fast, and cheap. Why pick the lock when someone will hand you the key? The cloud and SaaS dissolved the old perimeter years ago, and the most efficient path into your institution isn't a zero-day exploit. It's you: your credentials, your session, your trust. And increasingly, that "you" isn't even human. Most of the identities on your network are apps, bots, and automated AI agents, and they carry your trust, too.

That's the whole game now. Trust is the target.

 

The Front Door Was Never the Weak Point

Look at where the losses start. Verizon's "2026 Data Breach Investigations Report" shows a shift in initial access: Vulnerability exploitation now accounts for 31% of breaches, surpassing stolen credentials as the top breach entry point for the first time. But that does not make identity less important. It makes identity governance more important. Once attackers find a way in, they still rely on trusted access, believable communications, and legitimate-looking activity to move money, reset credentials, change vendor payment details, or persist quietly in your environment. Business email compromise (BEC), one of the costliest cyber-enabled fraud categories, runs on the same premise: BEC relies on trust, not malware. There is no payload to catch. Just a believable message from a name you recognize, asking you to move money or change a vendor’s bank details.

And before anyone says it: Yes, multifactor authentication (MFA) helps. I hear "but we have MFA" all the time, which is great. While MFA is extremely important and necessary, it is not a silver bullet. Phishing proxies sit in the middle and replay your token. Infostealers lift your active session right off the endpoint. AI has poured gasoline on all of it. AI-generated phishing is achieving click-through rates north of 50%, compared with roughly 12% for the old broken-English attempts. The localization is spot-on. The tone matches your CEO. The lure is built specifically for your finance team. It's cheaper, faster, and more convincing.

 

Why This Hits Banks Harder

Financial institutions have exactly the kinds of assets these attacks are built to exploit: high-value workflows and high-trust channels. Wires, ACH, payroll, vendor payment changes: Money moves on authorization, and authorization runs on identity. Your call center, your help desk, and your relationship managers are trusted lines of communication, and "trusted" is precisely what an attacker wants to impersonate.

Here's the one I want every banker to really think about: Your help desk is an identity issuance system. When someone calls in, gets a password reset, and re-enrolls MFA, your help desk has just decided who that person is. Attackers know it, and they have proven it against some of the most recognizable names in the country.

In the fall of 2023, two giants of the Las Vegas Strip, MGM Resorts and Caesars Entertainment, were breached within weeks of each other. There was no exotic exploit. The crews looked up an employee on LinkedIn, called the IT help desk posing as that person, and talked their way into a credential reset and MFA re-enrollment in just 10 minutes on the phone. That was the whole exploit. And the damage was not theoretical: MGM took an estimated $100 million hit to its operations, and Caesars paid the attackers about $15 million to make the problem go away.

And don't tell me you'd catch it on a video call. In early 2024, a finance employee at the global engineering firm Arup joined what looked like a routine video conference with his CFO and several colleagues. Every person on that call was a deepfake. He approved a series of transfers worth about $25 million before anyone realized the executives he had spoken with were AI-generated. Voice isn't identity anymore. A face on a screen isn't identity. We have to stop treating the channel as proof, remember that pretty much everything can be faked today, and verify before we trust.

 

The Identities You Forgot You Had

For most institutions, when you picture "identity," you picture people. But in many modern environments, the bigger population is software: Cloud Security Alliance research notes that nonhuman identities (NHIs) can outnumber human identities by a factor of 20 to 1. These include OAuth apps, service accounts, service principals, managed identities, API keys, automation pipelines, and now AI agents.

These NHIs are the invisible majority, and they break almost every assumption our security programs are built on:

  • They can't use MFA: They authenticate with secrets, certificates, keys, and tokens, and a stolen token can be copied and replayed with no human in the loop and no prompt to approve.
  • Most NHIs are NOT inventoried or monitored: Nobody owns them, nobody reviews them, and their sign-ins rarely reach anyone's SIEM.
  • They're chronically overprivileged: One app granted broad access to mail or SharePoint hands an attacker an enterprise-wide blast radius.
  • Their trust paths persist: OAuth app access can survive the password reset you thought closed the incident. You changed the locks, but the side door is still wide open.

 

Want to see how that plays out? Look at Microsoft's Midnight Blizzard breach. The attackers sprayed an old test account that had no MFA, pivoted to a legacy OAuth app with elevated permissions, then stood up their own OAuth apps to keep the access alive. The kicker, straight from the post-mortem: The security controls functioned as configured. The platform did exactly what it was set up to do — badly. They didn't break the front door. They found a key we forgot existed.

And now, the newest trusted identity in many environments is the AI agent. Microsoft 365 Copilot, Salesforce Agentforce, ChatGPT, Claude, and Google Gemini can act as autonomous agents, operating with delegated permissions, requesting broad access, and extending trust across systems. Most organizations are not governing these identities well yet. IBM's "2026 Cost of a Data Breach Report" found that only 46% of organizations secure NHIs in AI workflows. Treat every AI agent like the privileged OAuth app it is, before your vendors talk you into a dozen of them.

 

What to Do About It

The fix isn't a product. It's a decision to treat trust as something you verify and govern instead of something you hand out and forget.

Most institutions don't have an identity governance problem because they lack security technology. They have an identity governance problem because nobody owns the process. Security manages authentication. IT manages systems. Business units approve access. HR manages onboarding and offboarding. Identity sits across all of them, which means accountability often becomes fragmented.

We need to have some serious conversations about who is ultimately responsible for trust and identity at our institutions. Identity is no longer an IT issue. Every wire transfer, vendor change, access request, password reset, and AI agent ultimately becomes a decision about trust. Managing that trust belongs in the boardroom as much as the server room.

Here are a few places to start:

  • Upgrade authentication where it matters: Move high-risk users and money-movement workflows to phishing-resistant MFA like passkeys and FIDO2, and add step-up verification for wires, vendor changes, and admin actions.
  • Harden your issuance points: Put real verification behind help desk and call center resets. Assume the caller is a good actor, but make them prove it.
  • Treat NHIs as first-class identities: Inventory every app, service principal, and service account. Assign an owner and a purpose. Strip unused permissions. Rotate or eliminate long-lived secrets. Recertify the privileged ones quarterly.
  • Log, monitor, and respond: Pull service principal sign-ins and app activity into your SIEM, turn on app governance, and alert on new credentials, new consents, and unusual mail access.

 

If all you do in the next 30 days is identify your identity issuance points, pilot phishing-resistant MFA for your highest-risk users, and build a first inventory of your OAuth apps, you'll have closed the exact gaps these attackers are counting on.

Here's the uncomfortable truth: Most logins on your network are legitimate, right up until they aren't. Trust is the target. It's time we stopped leaving it undefended.

Blog_Lock&Line-Gray

 

avatar

Jon Waldman

Jon Waldman is the Co-Founder and President of SBS CyberSecurity, where he oversees the SBS service teams and the SBS Institute. For more than 20 years, Jon has helped hundreds of organizations identify and understand cybersecurity risks to allow them to make better and more informed business decisions. Jon's passion for cybersecurity training and education led him to be a driving force in the development of the SBS Institute. Designed for the banking industry, the Institute provides specialized cybersecurity education and now offers more than 10 certification courses, with State Association partnerships in 30+ states.

Jon maintains his CISA, CRISC, and CDPSE certifications. He received his Bachelor of Science in Computer Information Systems and his Master of Science in Information Assurance with an emphasis in Banking and Finance Security from Dakota State University, a Center of Academic Excellence in Information Assurance Education designated by the NSA.