The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Reimagining Cyber
Reimagining Cyber artwork

What Defenders Are Still Getting Wrong About Identity - #208

Reimagining Cyber · 2026-07-01 · 15 min

0:00--:--

Key moments - from our scoring

Substance score

38 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality7 / 20
Guest Caliber8 / 20
Specificity & Evidence8 / 20
Conversational Craft6 / 20

Tyler Moffitt challenges the prevailing assumption that identity security investments sufficiently protect organizations. While acknowledging identity remains a critical layer, he argues defenders fundamentally misunderstand modern attack patterns. Attackers now purchase stolen credentials, browser session cookies, OAuth tokens, and VPN access from underground marketplaces - or simply socially engineer help desk staff to reset MFA and enroll their devices. This shift from breaking in (exploiting vulnerabilities) to logging in (inheriting legitimate trust) renders traditional prevention-focused controls incomplete. The MGM casino breach exemplifies this: ransomware group Black Cat (later AlphaV) didn't break into the network - they purchased initial access from broker Scattered Spider. Moffitt emphasizes that identity security must evolve beyond MFA, SSO, and zero trust products to encompass help desk procedures, least privileged access, lifecycle management, behavior analytics, and incident response. He advocates a resilience-first mindset: assume compromise is possible, focus on rapid detection of abnormal behavior, limit lateral movement, reduce dwell time, and test recovery capabilities. This approach doesn't replace prevention but completes it through detection, response, and recovery frameworks.

Key takeaways

  • →Attackers now purchase stolen credentials and browser session cookies from underground marketplaces rather than exploiting vulnerabilities, making identity a commodity asset rather than something employees possess.
  • →Identity security is a comprehensive strategy requiring help desk procedures, least privileged access, lifecycle management, behavior analytics, and incident response - not just MFA, SSO, and zero trust products.
  • →The shift from prevention-only to prevention-plus-detection-and-resilience is essential: organizations must assume compromise is inevitable and focus on reducing dwell time and limiting lateral movement.
  • →Help desk social engineering (made popular by Scattered Spider) enables attackers to reset MFA and enroll new devices within minutes without exploits, malware, or zero-days.
  • →Cyber resilience means asking how quickly abnormal behavior can be detected, how much lateral movement can be limited, whether backups are tested, and if the organization can recover quickly - not whether attacks can be prevented entirely.

Guests

Tyler Moffitt

Topics in this episode

Zero TrustMFA (Multi-Factor Authentication)OAuth tokensScattered SpiderInitial access brokersBlack Cat ransomware groupAlphaVUnderground credential marketplacesBrowser session cookiesLumra Stealer

Questions this episode answers

Where do attackers get stolen credentials if they're not stealing them directly?

Attackers purchase credentials from underground marketplaces specializing in credential theft, where groups like those using Lumra Stealer break into organizations solely to harvest and resell credentials, browser cookies, authentication tokens, VPN access, and remote desktop credentials without deploying ransomware or exfiltrating data.

How does help desk social engineering defeat MFA without exploits or malware?

Attackers call the help desk posing as employees, convincing staff to reset MFA or enroll a new device, then gain completely legitimate access within minutes - no exploit or malware needed, just social engineering of help desk processes.

What happens after an attacker logs in with a stolen identity?

Attackers explore the environment, map networks, identify servers and administrators, find backups and sensitive data, establish persistence, disable security controls, and stage data for exfiltration or ransomware deployment - moving quietly at first to avoid detection before escalating privileges.

Why is identity a trust problem rather than just a technology problem?

Every privileged action and session represents a trust decision; modern attackers inherit that trust by possessing valid credentials, so technology products alone cannot prevent access when an attacker appears as a legitimate employee using legitimate credentials.

What is the difference between cyber resilience and prevention?

Prevention aims to stop attacks; resilience assumes compromise is inevitable and focuses on rapidly detecting abnormal behavior, limiting lateral movement, reducing dwell time, and recovering quickly to minimize business disruption.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode covers legitimate ground - IABs, session-cookie theft, info-stealers, help-desk social engineering - but most of it is standard cybersecurity practitioner knowledge packaged at a surface level. There is some conceptual framing (identity-as-strategy vs. product) but the density is diluted by repetition and summarisation from the host.

they just buy it. They just buy the stolen credentials, um, they buy the stolen browser sessions or they purchase oauth tokens
the attacker isn't defeating mfa, if that makes sense. They're basically inheriting a session where MFA was already completed

Originality

7 / 20

The 'logging in not breaking in' framing is catchy but widely circulated in security circles; the underground-marketplace description and IAB specialisation narrative are industry-standard takes. The 'identity as strategy, not product' reframe is mildly useful but not a first-principles argument.

Attackers aren't breaking in anymore. They're just logging in. They're inheriting trust
I would argue that identity is a strategy

Guest Caliber

8 / 20

Tyler Moffitt demonstrates solid practitioner knowledge of threat-actor behaviour and underground economies, but he is introduced only as 'our very own cybersecurity expert' with no stated operational seniority, track record at scale, or independently verifiable credentials - limiting caliber assessment to what the transcript itself shows.

I'm actually doing a webinar series called what Defenders are Still Getting Wrong
Black Cat at the time, which then changed into AlphaV, which then changed into Ransom Hub

Specificity & Evidence

8 / 20

The MGM/Scattered Spider/Black Cat→AlphaV→RansomHub chain and the Lumma Stealer reference are concrete and accurate; however, there are zero metrics, dollar figures, or measurable timelines, and one data point is garbled ('GDP laws' for GDPR). The specificity is illustrative rather than evidential.

Black Cat was the one made famous going after the casinos...they bought access from an access broker, specifically scattered spider at the time
use a piece of malware like Lumra or Lumra Stealer and steal these credentials

Conversational Craft

6 / 20

The host's questions are almost entirely setup prompts and restatements of what Tyler just said; there is no meaningful pushback, no probing of claims, and the episode closes with an uninterrupted plug for the guest's webinar series. Questions signal answers rather than surface new information.

So I guess they're showing up with a valid badge instead of just climbing through a window
That's arguably, I guess, uh, almost more concerning than some sophisticated exploit

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A83%
  • Speaker B17%

Most-used words

access19identity16security14attackers12trust10organizations9data8tyler7ransomware7resilience7cyber6controls6malware6become6technology5defenders5

Episode notes

For years, cybersecurity assumed attackers had to break into organizations. Today, they increasingly just log in. Valid credentials, stolen browser sessions, OAuth tokens, help desk social engineering,and underground marketplaces have fundamentally changed how attacks unfold. So why are organizations still thinking about identity the same way they did five years ago? In this episode, Tyler Moffitt discusses the biggest misconceptions around identity security, why trust has become a commodity, and why cyber resilience requires more than prevention alone. Relevant links: 'What defenders are still getting wrong' webcast series with Tyler Moffitt As featured on Million Podcasts' Best 100 Cybersecurity Podcasts Top 50 Chief Information Security Officer CISO Podcasts Top 70 Security Hacking Podcasts This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best! Follow or

Full transcript

15 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign.

Speaker B: Welcome back to reimagining cyber. Uh, now, for years we've heard that identity is the new perimeter. Organizations have invested billions in mfa, single sign on, zero trust, conditional access, identity providers, and every acronym you can imagine. Yet every week we still see another major breach making headlines. Retailers, airlines, insurance companies, technology companies. So today we're asking, what are defenders still getting wrong about identity? And the main person we're asking is our very own cybersecurity expert, Tyler Moffitt. Tyler, how are you doing?

Speaker A: Doing well. Thanks for having me on. I appreciate it.

Speaker B: Okay, if you could just kick, uh, things off for us then. What's the, I guess the first thing we should be talking about here?

Speaker A: I think the first thing that we should say is, you know, identity security isn't failing per se. Um, it's still absolutely the most important investments organizations can make. Maybe one of the most, the most important layer in a layered solution. Um, we've always talked about identity as a new perimeter, but I would say the mistake is believing that identity alone is enough to sort of stop all these attacks or most attacks, right? Attackers have adapted, essentially, and, and defenders need to adapt as well.

Speaker B: One phrase I've heard you use recently is that attackers, uh, aren't breaking in anymore, they're logging in. What do you mean by that?

Speaker A: So for years, um, cybersecurity, you know, they've always assumed attackers have to defeat security controls, right? Usually exploits, right, Come in, exploit a vulnerability, that's their back door, that's their way in. Or they drop a piece of malware from somebody falling for phishing, um, and then that's their way creating persistence, and that's the foothold, right? Um, and they bypass antivirus through, however they get people to trick. There's click fix. There's lots of things going on, right? That's all still happening. Um, but increasingly, attackers are starting from a completely different place. And this is basically, especially the past, I'd say year and a half or so, um, they just buy it. They just buy the stolen credentials, um, they buy the stolen browser sessions or they purchase oauth tokens. They basically just like socially engineer help desk, right? They, they purchased access from initial access brokers. Um, they were probably made the most famous back when that MGM casino thing happened where Black Cat at the time, which then changed into AlphaV, which then changed into Ransom Hub. I, um, know it's a lot. They always rebrand whenever the FBI goes after them. But anyway, Black Hat was the one made famous going after the casinos. And you have to realize they weren't even the ones that actually broke in. They were just the noisy ransomware payload at the end. They bought access from an access broker, specifically scattered spider at the time. And so they're just inheriting trust. Um, and that's a huge shift here.

Speaker B: So I guess they're showing up with a valid badge instead of just climbing through a window.

Speaker A: Yeah, I mean, you already have a trusted identity that you've bought. Right. You just look like every other employee. You aren't triggering any malware alerts. You aren't necessarily exploiting like a vulnerability in some unpatched VPN or appliance. Um, you know, you're using legitimate access, and that's why identity has become such an attractive attack surface.

Speaker B: One question listeners might have is, uh, that if attackers aren't breaking anymore, where are they actually getting all of these identities? Are they stealing them themselves?

Speaker A: Uh, sometimes. Sometimes, yeah. I mean, um, most of the time they're just buying them the attackers that actually leverage the device or do something with it to a point that's like, um, they're buying it themselves. But you have to realize that one of the biggest changes in cybercrime over the last few years is that these underground marketplaces, um, some of these groups are dedicated just to stealing access. They literally will break in, use a piece of malware like Lumra or Lumra Stealer and steal these credentials and then do nothing with the breach or the environment they've gone into. They just want to sell it. And so many, many corporations are currently, um, for sale accesses, but nothing has shown up on their end. They've not been breached per se, or, you know, nothing has shown up. That's noisy, if that makes sense. And so these underground marketplaces, you can just, like, they have stolen usernames and password, passwords, browser session cookies, authentication tokens, vpn, like remote desktop, you name it, all that stuff. It's, it's, it's only a growing increasing list. I mean, it's been around, I would say, for the past maybe five plus years, maybe even close to 10 years for some of this stuff. But it's now become like really well fleshed out to where they even have like a search where you can search for specific industries in countries and now like purchase it. Like you're, you're going on Amazon type thing. I mean, it's, it's pretty crazy. A trust has basically become a commodity.

Speaker B: Yeah. So attackers, they don't necessarily need to steal credentials anymore.

Speaker A: Right. Just buy it. Right. And so when we hear Terms like initial access, brokers. Um, these groups specialize in one thing. Um, and these are the groups I was telling you about that they just get into organizations. They don't deploy ransomware, they don't steal any data. Um, they just get access and then sell that access to someone else who'll then do the data exfiltration or do the ransomware. Right. Um, it's basically become specialized. Each of these groups just focuses on improving their craft of whatever they're doing, whether it's just stealing the initial access or deploying ransomware that gets past security, um, or escalating privilege with tools so that way they can gain access to the share so they can case the joint, look at finance data, see how much money is in the bank so you can't play games when it comes to ransom payments. And then data exfiltration, all those things, they've just become very specialized.

Speaker B: And buying credentials isn't the only option, right?

Speaker A: Um, not at all. We're seeing, you know, a huge increase in that help desk social engineering that scattered, uh, spider, um, made popular about a year and a half ago. Probably the best known example. I mean, they basically just made the playbook way more groups other than scattered spider are doing it. Um, but you know, instead of attacking technology with like, exploits and vulnerabilities that come out, you know, they, they're attacking processes. So they call the help desk main person and employee, um, and they convince them to reset mfa, reset a password, or even enroll their new device. That's their device. Right. Ten minutes later, they basically have a completely legitimate account. No exploit, no malware, no zero day, whatever. Just effective social engineering and they've got their way in.

Speaker B: That's arguably, I guess, uh, almost more concerning than some sophisticated exploit.

Speaker A: Yeah, I mean, because it works. You know, organizations spend millions protecting against malware, and that's what they're prepping for. Breaking in when sometimes forgetting that the trust itself can just be manipulated. And then you add info stealers into the mix. User downloads malware, their browser sessions are stolen. I mean, the cookies are stolen, save passwords, everything. You can get a lot of these tools, like, they grab it all. They grab everything you'd possibly need. And then you've got like, you know, multiple different, these bundled logs essentially have multiple different SKUs that can be sold. And, you know, the attacker isn't defeating mfa, if that makes sense. They're basically inheriting a session where MFA was already completed. And that's what's super tricky here is depending on, you know, the policies that are set With a lot of these permissioning of these tokens, um, they might last days. And then someone can just buy that token and, and then get in and completely defeat, um, or not even defeat it, just bypass it entirely, if that makes sense.

Speaker B: And we're looking then at multiple paths to exactly the same destination, right?

Speaker A: Exactly. They buy credentials, buy cookies, source engineer, the help desk, purchase access from initial access broker, uh, exploit an info stealer victim, right? There's tons of different techniques. It's ultimately the same outcome. Um, a trusted identity, right? And once attackers have that trusted identity, they're no longer trying to break into the organization, right? They're basically just walking right through the front door with access granted.

Speaker B: So what would you say is the biggest misconception that organizations still have?

Speaker A: I would say that identity is, is just a product. Um, I don't think it is. Personally. I would argue that identity is a strategy. Um, organizations sometimes think that, hey, we bought mfa, we implemented sso, you know, we rolled out zero trust, problem solved. Um, but identity security also includes the help desk procedures, the least privileged access, the lifecycle management, the monitoring, behavior analytics, incident response, security awareness, you know, governance, I mean, tons of stuff. You know, technology is incredibly important, but technology without good process still creates these opportunities for attackers.

Speaker B: It isn't then really a technology problem.

Speaker A: It's a trust problem for sure. Every privileged action is a trust decision. Every session is a trust decision. And you know, modern attackers, they, they know that if they inherit trust, they inherit the access and they can walk right in.

Speaker B: Okay, then let's say that attackers, they obtain a valid identity. What happens next?

Speaker A: So that's another place where I think defenders have an outdated mindset on what they think happens. And you know, imagine a breach happened where the attacker logged in. I mean, it's not even really a breach, I don't know, but it's when it's, you know, legitimate authorized access, um, you know, there's, there's no exploit being used. And so he's just walked right in. He's like considered legitimate traffic as an employee. The attacker is going to explore, right? They're going to map the environment, they're going to try and find servers, find what access they can, see who administrators are, right? Find backups, identify, um, sensitive data if they can, and you know, move laterally, right? Establish persistence, uh, disable security controls, um, stage data and eventually they achieve their objective. So they'll do the quieter things that don't raise suspicion first and take their time with that. But when it comes to like, um, elevating permissions or disabling security controls. Obviously, they'll be quick with that, um, because they'll usually likely have to use hacking tools to do all that. Um, and that's where they can eventually, uh, complete their objective, which is data exfiltration of sensitive, you know, personal identifying information that would violate GDP laws and be good for ransom, and then also. Also deploy ransomware. And ransomware kind of become optional now. Um, it used to be, like, obviously required, super noisy. Comes in impact interruption encryption of your files. But they don't need to now. Just the data theft alone for some of these big organizations is more than enough to justify, you know, getting a ransom payment. Um, but the login wasn't the attack, right? It was just a starting point.

Speaker B: So the question shifts from how do we stop every login? To what do we do after Compromise.

Speaker A: So, yeah, that's where cyber resilience, I think, comes incredibly important. That. That security posture, if you will.

Speaker B: Now, Tyler, sometimes when we talk about resilience or detection, people assume we're saying that prevention doesn't matter anymore. Uh, I guess you're going to refute that.

Speaker A: Yeah, no, absolutely. I mean, all that stuff matter, like, firewalls matter, email security matters, the DNS protection, endpoint, edr, mfa, like, security awareness, uh, all that stuff matters, right? Every one of those controls reduces risks. I think the mistake is expecting, you know, any one of those controls to stop most attacks. And cyber security, I feel, has always been about layers, Right? Cyber resilience is basically recognizing that compromise is possible and preparing for it. Right? It's the assumption of when, not if.

Speaker B: So resilience, it isn't replacing prevention, it's completing it. It.

Speaker A: Yeah, I mean, that's a way of looking at it, I think, uh, resilience is more like it's just a realistic mindset, right? Instead of asking, can we stop everything? We're asking, how quickly can we detect abnormal behavior? Can we limit lateral movement when we do detect it? Can we reduce the dwell time? Or can we recover quickly enough? Or have we tested our backups? Have we done tabletop exercises? Are we prepared? Right. Those. Those questions have huge impact on the business outcomes.

Speaker B: Okay, uh, we're reaching the end of the episode now, so it's takeaway time. Uh, if listeners remember one thing from today's discussion, Tyler, what should it be?

Speaker A: Um, I'm gonna cheat and give you two. Uh, first, I would say stop thinking of identities as something employees have. Start thinking of identities as, like, assets that criminals can buy, sell, rent, steal, you name it. Trade it, whatever. Um, that's the reality of today's underground economy. Uh, and second, um, don't leave this conversation thinking you need another layer or security product. Um, I would leave thinking different about identity. Attackers aren't breaking in anymore. They're just logging in. They're inheriting trust and instead of, instead of defeating security controls. Right. That's why modern cybersecurity really, you know, the posture isn't about prevention. It's about prevention as well as detection, response, recovery and like resilience and all coming together and working together.

Speaker B: And that's really the shift, I guess, isn't it? The goal isn't to create an environment that can never be compromised. It's to build an organization that could detect abnormal, uh, behavior quickly, contain it, recover, and continue operating.

Speaker A: Yeah, that's a good way of looking at cyber resilience. You know, you got to assume compromise is always possible. Reduce the dwell time, limit the lateral movement, protect your critical assets. Um, do tabletop exercises to recover quickly to minimize your business disruption. I mean, that's going to be, you know, those organizations that do that will be the most successful going forward.

Speaker B: And Tyler, if today's discussion has, ah, resonated, ah, with listeners, they can actually find out a bit more. Tell me what else is going on.

Speaker A: Yes, so, um, I'm actually doing a webinar series called what Defenders are Still Getting Wrong, where we take a much deeper dive into things like identity security or phishing or ransomware and basically what isn't stopping attacks and more importantly, what organizations can actually do about it. Um, and so I just gave one last week and so I'd be more than m happy to give you a link to the series where you can watch On Demand, what episodes I have done, and any upcoming ones.

Speaker B: Yeah, we'll put those on the episode notes. But can you give us a clue as to where we might find that?

Speaker A: Oh, yes, no, they're on Bright Talk and the series is called what Defenders Are Still Getting Wrong, but we'll provide it in the notes.

Speaker B: Tyler, fantastic. Thank you so much.

Speaker A: Thanks for having me on. Ben, always a pleasure.

Speaker B: And do remember to rate, review and recommend Reimagining Cyber. We'll be back next week, myself and Tyler with another episode. Goodbye.

Speaker A: Uh, mhm.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The Weakest Link in a Global Life Sciences Company? People. With Dr. Kevin JonesCyber Leaders · on Zero Trust88 / 100
  • Why “Cyber Is Broken”, And Building Trust in an AI World - Karl Van den Bergh CMO IllumioCyber Go-To-Market Talk · on Zero Trust87 / 100
  • When GRC Stops Watching and Starts Working ft Ryan Schoeller, Director of Security & GRC @ Treasure DataSecurity & GRC Decoded · on MFA (Multi-Factor Authentication)85 / 100
  • Decoding the Cybercriminal Mindset, with Ryan ChapmanThe Cyber Insider · on Scattered Spider85 / 100
  • Zero Trust as a Mindset: Identity, Governance, and Access | Interview with Andrew GaultSecure & Simple · on Zero Trust83 / 100
  • AI Security: Patricia Titus on Shadow AI, Non-Human Identities, and AI DefenseAI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop · on Zero Trust79 / 100

More from Reimagining Cyber

All episodes →
  • Every Breach is the Same - #207
  • Return of the Edge: Did We Forget About the Perimeter? - #206
  • Scattered Spider's Evolution: One Industry at a Time - #205
  • ClickFix Chaos! The Evolution of Social Engineering - #204
  • Vulnerability Management and the 2026 Verizon DBIR - #203
Explore the best B2B Ops podcasts →
All Reimagining Cyber episodes →