Prophet Security Threat Report Finds Attackers Moving Beyond Passwords, Bypassing Controls with Stolen Sessions
Report analyzes a full quarter of Prophet AI SOC Analyst investigations, finding identity-related activity in roughly
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
Report analyzes a full quarter of Prophet AI SOC Analyst investigations, finding identity-related activity in roughly half of confirmed malicious investigations
PALO ALTO, CA, UNITED STATES, September 10, 2026 /EINPresswire.com/ — Quarterly Threat Report, Q3 2026: At a Glance:
– Identity was the objective in roughly half of all confirmed malicious activity: credential phishing accounted for about 28% of confirmed malicious investigations and direct attacks on accounts and sessions about 18%.
– Attempts that arrived with a password, such as credential stuffing, were blocked. Attempts that arrived with a stolen, already-authenticated session succeeded, and at two organizations the attacker kept working after the account was disabled.
– Every alert received a full investigation: 4.7 million questions asked by Prophet’s AI SOC Analyst, a median of 35 per investigation, to a median determination in just over five minutes. Of investigations reaching a determination, 93% were benign and 7% malicious.
Prophet Security today released its first Quarterly Threat Report, finding that authenticated sessions were the strongest predictor of successful account takeover during the May 1–July 31, 2026 analysis period. The findings highlight how attackers are using stolen authenticated sessions to bypass identity controls applied at login, including conditional access.
The report analyzes investigation data from alerts handled by the Prophet AI SOC Analyst over the three-month period. The dataset includes the full set of alerts investigated during that time, rather than a curated sample of incidents. No alerts were deprioritized or aged out based on analyst workload, providing a more complete view of the threats security teams encountered.
“We hardened the front door, so attackers stopped knocking,” said Jon Hencinski, Head of Security Operations at Prophet Security. “Every correct password that showed up from unfamiliar infrastructure got blocked by the controls teams already had in place. Those controls worked. What did not get blocked was the stolen session, because a replayed session cookie never authenticates, so no policy fires. At two organizations the attacker was still working in the account after the team disabled it. If your account compromise runbook ends at the password reset, check what it revokes to make sure all access possibilities are removed.”
Prophet Security’s Agentic AI SOC Platform autonomously investigates alerts, accelerates incident response, performs continuous threat hunting, and optimizes detections across the security operations lifecycle.
Identity was the objective in roughly half of confirmed malicious activity
Credential phishing accounted for about 28% of confirmed malicious investigations, with most campaigns focused on stealing account access. Direct attacks on accounts and sessions accounted for another 18%, including session hijacking, token replay, MFA bypass, credential stuffing, inbox rule manipulation and OAuth consent grants.
Other activities included code execution and tooling at about 23%, pre-ransomware and hands-on-keyboard activity at about 9%, vulnerability exploitation at about 7%, and command-and-control and network activity at about 1%. Environment-specific detections accounted for about 16%.
Stolen sessions were the most effective entry method
Password-based account takeover attempts were repeatedly blocked by conditional access or phishing-resistant MFA. Stolen sessions allowed attackers to reuse an authenticated state without presenting credentials again.
In one investigation, every event relied on Primary Refresh Token authentication and required no credential re-entry. A password reset would not have revoked that access. The report recommends adding session and refresh token revocation to account compromise runbooks and enabling continuous access evaluation and token protection where supported.
Infostealers often arrive through browser-downloaded software
Infostealer activity traced back to compromised legitimate websites, fake verification and CAPTCHA gates, malicious advertising and sponsored search results. Trojanized installers were confirmed at about a quarter of organizations and were the most common first foothold on an endpoint.
Fake AI tool installers appeared at multiple organizations. One trojanized build of a popular AI desktop application disabled Windows Defender, created persistence through a scheduled task and opened command-and-control channels. In both AI-lure compromises, the user was trying to install a real product.
One script extracted Microsoft authentication session cookies from the browser and used them to make authenticated API requests. Those cookies could survive a password reset if the session was not revoked.
Finance teams faced repeated email targeting
Email campaigns repeatedly targeted people and mailboxes associated with payments, including accounts payable, collections, treasury and finance leaders.
Removal time for malicious email ranged from seconds to more than a day. Automated post-delivery remediation reduced dwell time to seconds. In one case, a CEO-impersonation lure remained in a finance director’s inbox for most of a working day. In another, a spoofed message that failed SPF, DKIM and DMARC reached more than a dozen inboxes.
Pre-ransomware activity concentrated on unmonitored assets
Ransomware precursors included shadow copy destruction, credential dumping and remote access tool deployment before encryption began.
Several long-running intrusions involved assets without endpoint coverage. A multi-week credential attack targeted a production identity server with no endpoint agent, and a six-week lateral movement campaign originated from an unmanaged host. Legitimate commercial remote access tools were confirmed as a persistence layer at about 15% of organizations.
AI tools appeared in attacker activity and defensive investigations
Attackers used AI tooling to support parts of their workflow. The cookie-theft script was run through an AI coding assistant. In two account takeovers, attackers accessed the organization’s AI assistant. In one case, they planted content in the assistant’s chat files as a persistence mechanism.
AI developer tools also generated activity that resembled attacker tradecraft, including remote code execution, runtime compilation and obfuscated commands. Investigations required user and application context to separate legitimate development activity from malicious behavior. The report notes that detections relying heavily on command-line patterns may produce more false positives as these tools become more common.
Access the Report
The complete Prophet Security Quarterly Threat Report, Q3 2026 is available now at prophetsecurity.ai.
About Prophet Security
Prophet Security delivers a comprehensive Agentic AI SOC Platform that automates security operations across alert triage, investigation, incident response, threat hunting and detection engineering. Prophet AI reduces mean time to investigate and respond, delivers a 10x increase in team productivity, and helps close critical detection coverage gaps that allow attackers to operate undetected. Prophet Security’s investors include Accel, Bain Capital Ventures, Amex Ventures and Citi Ventures.
Learn more at prophetsecurity.ai.
Eric Swenson
Prophet Security
email us here
Visit us on social media:
LinkedIn
Legal Disclaimer:
EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
![]()
Media gallery



