Blog, FastPassCorp IVM Blog
50% of Data Breaches can be Attributed to Leaked Credentials | FastPass
50% of Data Breaches can be Attributed to Leaked Credentials
This article was originally published by LOGON’s partner FassPassCorp. Click here to view the original article.
Hacking an IT system is often like a puzzle; the hacker needs all the pieces to succeed. A password is required in 50% of data breaches, says Verizon DBIR 2022.
If we can prevent hackers from obtaining important passwords, we will potentially have reduced data breaches by 50%, so we need to understand how hackers get passwords. This blog focuses on corporate IT systems.
In a corporate environment, passwords must at least comply with company password policies; the most common one is the Active Directory Password Policy. This makes guessing extremely hard for a hacker, and after several failed attempts, the account locks down, and a service desk operator is required to reopen it. This method does not generate enough success for the hacker. In AD, the passwords are encrypted and hashed, so the hackers cannot even use a stolen copy.
Instead, hackers can sometimes get passwords from users through e-mail phishing. Most organizations are aware of this problem and would have implemented a solution to prevent this from occurring.
But how can you get a password if you are a hacker and need a password from a specific user (or a small user group)? Just use your phone and ask for a password!! Key people are not easy targets and will not give out passwords through a spear-phishing attack.
Alternatively, the hacker will call the service desk and pretend to be a real user with a user-id. If the hacker is well prepared, he can impersonate the user and give relevant details in the conversation. The service desk is there to help, so the odds are suitable for the hacker. Research done by Group-IB highlighted a 75% success rate for gaining information when combining e-mails and phone-based calls (Vishing).
For organizations that have a large service desk or an outsourced service desk, the service desk staff might not be familiar with most users by voice or their habits. The hackers can use this as an advantage to get details about the critical IT-staff and even get a new password for an IT user. This is a security hole for the essential It-infrastructures and might explain where the hackers get the passwords for the data breaches!
Phishing and vishing are social engineering methods and rely on human interaction. Up to now, the best mitigation has been awareness training, but research shows that sound social engineers can still fool some of us.
Robust and secure mitigation is an intelligent IT workflow to verify the identity of people calling in. This removes the social engineer’s most potent weapon, human interaction and emotions! We cannot do this for all employees, but we can do it where we have significant data and assets serviced by central service centers such as the IT service desk, the HR department, and the Finance department. In the verification process, dynamic and contextual information would make it exceedingly difficult for a hacker to impersonate a user. Combining an intelligent workflow with modern tokens like OKTA and DUO and authenticators such as Google and Microsoft makes the process easy for users and highly secure.


Stop social engineering against your service desk
Workflow for secure verification of employees phoning in to get a service, like a new password, personal information, payment transaction, etc.
Get a Free Demo
Book a demo with our specialist to discover how IVM stops social engineering attacks against your service desk



