Nineteen years of this report had stolen credentials at or near the top. That changed, and the reason Verizon gives is speed: attackers are using AI to shorten the gap between a disclosure and a working exploit from months to hours.

The identity read on this is not that identity stopped mattering. Entry-point coding assigns one vector per breach, so a compromise that starts at an unpatched edge device and then runs on harvested credentials for three weeks is filed under the vulnerability. Credential abuse remains far more common across full attack chains than at the point of entry.

What actually changed is the window. A patch cycle designed around a monthly maintenance calendar was built for a world where the exploit arrived after the calendar did. For a security leader this is a prioritization argument rather than an identity one: the budget conversation that has been about identity posture for five years now has a competing claim with fresher data behind it.