Identity is becoming the new currency in cyberwarfare. According to a new report from eSentire ’s Threat Response Unit (TRU) , attacks based on account compromise and credential theft (ID attacks) increased significantly between 2024 and the first quarter of 2025. Overall, such incidents now account for 59% of all confirmed threats to the company’s customers’ networks — a database that includes over 2,000 organizations worldwide.
See also: Increase in phishing attacks ahead of Amazon Prime Day

Phishing-as-a-Service: When scammers rent “operational tools”
The rapid increase in attacks is largely attributed to the popularity of Tycoon 2FA , a phishing-as-a-service platform that allows the theft of account credentials and session cookies. For a cost of $200 to $300 per month , cybercriminals gain access to:
- Email templates that perfectly mimic trusted sources, such as Microsoft
- Adversary-in-the-middle (AitM) mechanisms to bypass multi-factor authentication (MFA)
- Built-in Anti-debugging and detection evasion tools
- Customer support (!), even software updates
- Data extraction tools
Tycoon 2FA has already surpassed competing platforms, such as EvilProxy and Sneaky 2FA, and is mainly used in BEC (Business Email Compromise), where attackers compromise accounting or finance department emails to divert payments to bank accounts they control.
See also: Hackers abuse Vercel v0 for phishing attacks
Infostealers: The low-cost weapon of cybercriminals for ID attacks
For attackers who lack the means or skill to use phishing platforms, infostealer malware is a cheaper—but no less dangerous—alternative. Tools like Lumma Stealer harvest user files and credentials from email, banking services, VPNs, cryptocurrency wallets, and browser extensions.
These files are sold on underground digital marketplaces with prices starting at just $10, offering a huge amount of valuable data for immediate exploitation or resale. Lumma Stealer, in particular, features automated filters to identify high-value data, thus accelerating the attackers’ profit cycle.

The numbers shock: $55 billion losses from BEC attacks worldwide
The FBI has recorded more than 300,000 BEC cases since 2013, with total economic losses reaching $55 billion. At the same time, according to eSentire, infostealers accounted for 35% of all malware stopped by the company in the first quarter of 2025. ID attacks now offer a higher return than traditional exploits.
See also: Microsoft 365: Phishing attacks abuse 'Direct Send'
Antidote to the threat: Defensive tactics for organizations
ID attacks will continue and may scale. Experts recommend immediate implementation:
- Phishing-resistant authentication mechanisms (such as FIDO2, hardware keys)
- Zero Trust strategies, where access is only granted under absolutely verified circumstances
- Real-time monitoring of endpoint and continuous analysis of user behavior
Cyber identity theft is no longer a secondary threat — it’s the new battleground. Organizations that rely solely on MFA or traditional measures are already falling behind. They need proactive, intelligent defensesif they want to maintain control of their critical infrastructure.
Source: www.infosecurity-magazine.com
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
