Accessibility Statement Skip Navigation
  • Resources
  • Data Privacy
  • Contact Us
  • Send a Release
Return to PR Newswire homepage
  • News
  • Products
    • Overview
    • Distribution by PR Newswire
    • Guaranteed Paid Placement
    • Cision Media Monitoring
    • Multichannel Amplification
    • All Products
  • Contact
    • General Inquiries
    • Request a Demo
    • Partnerships
    • Media Inquiries
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
  • News in Focus
      • Browse News Releases

      • All News Releases
      • All Public Company
      • English-only
      • All Multimedia

      • All Multimedia
      • All Photos
      • All Videos
  • Business & Money
      • Auto & Transportation

      • Aerospace & Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads & Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking & Road Transportation
      • View All Auto & Transportation

      • Business Technology

      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Accessories
      • Computer Hardware
      • Computer Networks
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High-Tech Security
      • Internet Technology
      • Nanotechnology
      • Semiconductors
      • View All Business Technology

      • Entertain­ment & Media

      • Advertising
      • Art, Culture & Design
      • Books
      • Entertainment
      • Film & Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Financial Services & Investing

      • Accounting News & Issues
      • Acquisitions, Mergers & Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Projections or Forecasts
      • Financing Agreements
      • Insurance
      • Investment Options
      • Joint Ventures
      • Mutual Funds
      • Offerings
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalization
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Venture Capital
      • View All Financial Services & Investing

      • General Business

      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing/marketing agreements
      • New Products & Services
      • Obituary
      • Outsourcing Businesses
      • Overseas Real Estate (Non-US)
      • Personnel Announcements
      • Residential Real Estate
      • Small-Business Services
      • Socially Responsible Investing
      • Surveys, Polls & Research
      • Trade Show News
      • View All General Business

  • Science & Tech
      • Consumer Technology

      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Accessories
      • Computer Electronics
      • Computer Hardware
      • Computer Networks
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Design Automation
      • Financial Technology
      • Mobile Devices/Apps
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Wireless Communications
      • View All Consumer Technology

      • Energy & Natural Resources

      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Natural Gas Utilities
      • Oil & Energy
      • Oil & Gas Discoveries
      • Utilities
      • Water Utilities
      • View All Energy & Natural Resources

      • Environ­ment

      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • Aerospace & Defense
      • Agriculture
      • Chemical
      • Computer Accessories
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation & Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking & Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • Computer Accessories
      • Computer Networks
      • Mobile Devices/Apps
      • Telecommunications
      • Telecommunications Carriers & Services
      • Telecommunications Equipment
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • Animals & Pets
      • Beers, Wine & Spirits
      • Beverages
      • Cannabis
      • Cosmetics and Personal Care
      • Fashion
      • Food
      • Furniture & Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewelry
      • Non-Alcoholic Beverages
      • Office Products
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • Advertising
      • Art, Culture & Design
      • Books
      • Entertainment
      • Film & Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Health

      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infectious Disease Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • View All Health

      • Sports

      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports
      • Sports Equipment & Accessories
      • View All Sports

      • Travel

      • Amusement Parks & Tourist Attractions
      • Gambling & Casinos
      • Hotels & Resorts
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel
      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • Animal Welfare
      • Corporate Social Responsibility
      • Economic News, Trends & Analysis
      • Education
      • Environmental Products & Services
      • European Government
      • Natural Disasters
      • Not-for-Profit
      • Public Safety
      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • Children-related news
      • Disabled Persons
      • Diversity, Equity & Inclusion
      • Hispanic-oriented news
      • LGBTQ+
      • Religion
      • Senior Citizens
      • Veterans
      • Women-Related news
      • View All People & Culture

  • Overview
  • Distribution by PR Newswire
  • Guaranteed Paid Placement
  • Cision Media Monitoring
  • Multichannel Amplification
  • All Products
  • General Inquiries
  • Request a Demo
  • Partnerships
  • Media Inquiries
  • Hamburger menu
  • PR Newswire: news distribution, targeting and monitoring Home
  • Send a Release
    • Chat

    • ALL CONTACT INFO
    • Contact Us


  • News Releases
  • Send a Release
  • Data Privacy
  • News in Focus
    • Browse All News
    • Multimedia Gallery
    • Trending Topics
  • Business & Money
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
  • People & Culture
    • People & Culture
  • News Releases
  • Send a Release
  • Data Privacy
  • Overview
  • Distribution by PR Newswire
  • Guaranteed Paid Placement
  • Cision Media Monitoring
  • Cision IR
  • SocialBoost
  • All Products
  • News Releases
  • Send a Release
  • Data Privacy
  • General Inquiries
  • Request a Demo
  • Editorial Bureaus
  • Partnerships
  • Media Inquiries
  • News Releases
  • Send a Release
  • Data Privacy

Silverfort Research Finds Two-Thirds of Businesses Sync On-prem Passwords to Cloud Environments, Opening their Cloud to Cyberattack
  • USA - English
  • France - Français
  • Deutschland - Deutsch

Silverfort is the Unified Identity Protection company

News provided by

Silverfort Ltd

26 Mar, 2024, 20:00 CST

Share this article

Share toX

Share this article

Share toX

Company Unveils its Proprietary Identity Underground Report 2024; First Identity Report 100% Dedicated to Exposing Frequency & Prevalence of Identity Threat Exposures (ITEs)

Alphv BlackCat and Lockbit ransomware threat actors abuse gaps in identity to steal credentials, escalate privileges, and move through organizations undetected

TEL AVIV, Israel & BOSTON, March 26, 2024 /PRNewswire/ -- Today, Silverfort, the Unified Identity Protection Company, unveiled its Identity Underground report, highlighting the frequency of identity security gaps that lead to successful attacks on organizations across every industry and region. Fueled by Silverfort's proprietary data, the report is the first of its kind, focusing on identity as an attack vector and offering insights into the Identity Threat Exposures (ITEs) that pave the way for cyberattacks. The data, analysis, and insights help identity and security teams benchmark their security programs, empowering them to make informed decisions on where to invest in identity security. 

The standout – and alarming – finding is that two out of every three businesses (67%) routinely synchronize most of their users' passwords from their on-premises directories to their cloud counterparts. This practice inadvertently migrates on-prem identity weaknesses to the cloud, which poses substantial security risks by creating a gateway for attackers to hack these environments from on-prem settings. The Alphv BlackCat ransomware group is known to use Active Directory as a stepping stone to compromise cloud identity providers.

Over the past decade, there has been a rush to migrate to the cloud – and for a good reason. Simultaneously, however, security gaps stemming from legacy infrastructure, misconfigurations, and insecure built-in features create pathways for attackers to access the cloud, significantly weakening a company's resilience to identity threats.

"Identity is the elephant in the room. We know that identity plays a key role in nearly every cyberattack. Lockbit, BlackCat, TA577, Fancy Bear – they all use identity gaps to break in, move laterally, and gain more permissions," said Hed Kovetz, CEO and Co-founder of Silverfort. "But we need to know how common each identity security gap is so we can start methodically fixing them. Finally, we have concrete evidence outlining the frequency of identity gaps, which we can now classify as Password Exposers, Lateral Movers, or Privilege Escalators, and they're all vehicles for threat actors to complete their attacks. We hope that by shining a light on the prevalence of these issues, identity and security teams will have the hard numbers they need to prioritize adequate security investments and eliminate these blind spots."

Key findings include:

  • Two-thirds of all user accounts authenticate via the weakly encrypted NTLM protocol, providing attackers easy access to cleartext passwords. Easily cracked with brute-force attacks, NT Lan Manager (NTLM) authentication is a prime target for attackers looking to steal credentials and move deeper into an environment. Recent research from Proofpoint security shows threat actor TA577 using NTLM authentication information to steal passwords.
  • A single misconfiguration in an Active Directory account spawns 109 new shadow admins on average. Shadow admins are user accounts with the power to reset passwords or manipulate accounts in other ways. Attackers use shadow admins to change settings and permissions and gain more access to machines as they move deeper into an environment. 
  • 7% of user accounts inadvertently hold admin-level access privileges, giving attackers more opportunities to escalate privileges and move throughout environments undetected.
  • 31% of user accounts are service accounts. Service accounts are used for machine-to-machine communication and have a high level of access and privileges. Attackers target service accounts as security teams often overlook them. Only 20% of companies are highly confident that they have visibility into every service account and can protect them.
  • 13% of user accounts are categorized as "stale accounts," which are effectively dormant user accounts that the IT team may have forgotten. They are easy targets for lateral movement and evading detection by attackers.

Silverfort's research team has meticulously categorized Identity Threat Exposures (ITE) into four distinct classes. Their goal is to arm the cybersecurity industry with a framework to classify and understand the diverse spectrum of identity issues and misconfigurations that enable credential theft, privilege escalation, and lateral movement by malicious actors.

The four ITE categories

  • Password Exposers: Enable an attacker to discover users' passwords by exposing the password hash to common compromise techniques. Examples include NTLM authentication, NTLMv1 authentication, and admins with SPN.
  • Privilege Escalators: Allow an attacker to gain additional access privileges. Typically Privilege Escalators are the result of a misconfiguration or insecure legacy settings. Examples include shadow admins and unconstrained delegation.
  • Lateral Movers: Allow an attacker to move laterally undetected. Examples include service accounts and prolific users.
  • Protection Dodgers: Potentially open legitimate user accounts up for attackers to use. Protection Dodgers stem from human error or mismanaged user accounts; they are not inherently security flaws or misconfigurations. Examples include new users, shared accounts, and stale users.

Join Silverfort's identity threat experts on April 16th in partnership with Hacker News for a deep dive into the report findings. Visit Identity Underground to access the complete report.

About Silverfort

Silverfort, the Unified Identity Protection company, pioneered the first and only platform that enables modern identity security everywhere. We connect the silos of enterprise identity infrastructure to unify identity security across all on-prem and the cloud environments. Our unique architecture and vendor agnostic approach, takes away the complexity of securing every identity, and extends protection to resources that cannot be protected by any other solution, such as legacy systems, command-line interfaces, service accounts (non-human identities), IT/OT infrastructure, amongst others. Silverfort is a top-tier Microsoft partner and was selected as Microsoft's Zero Trust Champion of the Year. Hundreds of the world's leading enterprises trust Silverfort to be their identity security provider, including multiple Fortune 50 companies. Learn more by visiting www.silverfort.com or on LinkedIn.

Media Contact:
Jill Creelman
[email protected]

SOURCE Silverfort Ltd

Modal title

Also from this source

Silverfort Breaks Identity Security Silos with Two New Capabilities: Access Intelligence & Identity Graph, Delivering End-to-end Identity Security

Silverfort Breaks Identity Security Silos with Two New Capabilities: Access Intelligence & Identity Graph, Delivering End-to-end Identity Security

Silverfort, the leading identity security company, today announced the release of two new foundational capabilities: Access Intelligence and Identity ...

Silverfort Expands its Non-Human Identity (NHI) Security Offering to the Cloud for End-to-End Identity Security

Silverfort Expands its Non-Human Identity (NHI) Security Offering to the Cloud for End-to-End Identity Security

Silverfort, the leading identity security company, today introduced expanded protection of its non-human identity (NHI) security product to include...

More Releases From This Source

Explore

Computer & Electronics

Computer & Electronics

News Releases in Similar Topics

Contact Cision

  • General Inquiries
  • Request a Demo
  • Partnerships
  • Media Inquiries

Products

  • Cision Communication Cloud®
  • For Marketers
  • For Public Relations
  • For IR & Compliance
  • For Agency
  • For Small Business
  • All Products

About

  • About PR Newswire
  • About Cision
  • Become a Publishing Partner
  • Careers
  • Accessibility Statement
  • APAC – Simplified Chinese
  • APAC
  • APAC - Traditional Chinese
  • Arabic
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Indonesia
  • Israel
  • Italy
  • Japan
  • Korea
  • Mexico
  • Middle East
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • United States
  • Vietnam

My Services

  • All New Releases
  • Platform

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921

Contact Cision

Products

About

My Services
  • All News Releases
  • Platform
[email protected]
  • Terms of Use
  • Privacy Policy
  • Information Security Policy
  • Site Map
  • RSS
  • Cookie Settings
  • Accessibility
Copyright © 2025 Cision US Inc.