Skip to Content

Q3 Attacker Trends: Inside Todays Identity Led Attacks

10:00 AM GMT  |  1:00 PM EST

This previous quarter, attackers turned phone calls and Teams messages into persistent cloud access. Threat groups used stolen identities to download SharePoint data at scale — sometimes within minutes — and password resets didn't stop them. Ransomware Groups changed, but their playbooks stayed the same: valid accounts, remote-support tools, and SMB moving from access to encryption.

Join ReliaQuest Threat Research for a review of the quarter's findings and what they mean for defenders — including how to connect identity changes to the activity that follows and contain identity-led intrusions before data leaves.

What you'll learn:

  • Why a password reset isn't full containment. The devices, MFA methods, and refresh tokens that survive a reset, and the steps that remove them.

  • How to connect identity changes to follow-on activity. Correlating a new device or MFA enrollment with the SharePoint enumeration, bulk downloads, or SMB movement that follows.

  • How to contain identity-led intrusions in five minutes or less. Revoking sessions and tokens, removing attacker-controlled authentication methods, and isolating affected hosts before data leaves.