The Organizations That Got Breached Had Strong Identity Programs
SC Media, Thursday, July 23rd, 2026
Mature identity programs still fail because ungoverned machine identities operate undetected.
Machine identities now outnumber human users by as much as 50 to 1, yet most lack lifecycle controls and clear ownership. The 2026 Data and Identity Security Report found 43% breach rates among organizations where AI expanded identity counts.
The Drift OAuth token breach illustrated how trusted but forgotten credentials enable lateral movement across systems.
Organizations should establish current inventories, defined ownership, rotation schedules and automated deprovisioning for all machine identities before deploying AI agents at scale.