There’s a picture most people carry of how a breach happens: malicious code, a virus slipping past the antivirus, something technical forcing its way in. That picture is about a decade out of date. In the majority of incidents we see now, nothing was broken into at all. Someone simply signed in.

The industry numbers back up what we see on the ground. In CrowdStrike’s latest global threat report, 82 percent of detections involved no malware whatsoever. No infected attachment, no virus, nothing for a traditional antivirus to catch. The attacker had a valid username and password, typed them into a real login page, and from that moment looked exactly like an employee.

Where the passwords come from

Nobody guessed them. Credentials arrive in bulk from three places: previous breaches at other companies where your staff reused a password, phishing pages that look pixel-perfect like the Microsoft 365 login, and infostealer malware on a home computer that quietly harvested every saved password in the browser. These credentials are sold in organized markets. Buying a working login for a Canadian business costs less than lunch.

Once inside a mailbox, the attacker rarely does anything loud. They read. They learn who approves payments, which clients are mid-invoice, how the owner writes. Then one day a supplier’s banking details change on an otherwise perfect-looking email, and the money is gone before anyone thinks to ask a question.

Why the old defences miss it

Here’s the uncomfortable part: everything about this activity is technically legitimate. A real account, a real login page, normal-looking email. The firewall sees nothing wrong. The antivirus has no malware to find. Defences built to spot malicious code cannot flag a session that is, by every technical measure, an authorized user.

What does catch it is a different question entirely: not “is this code malicious?” but “is this behaviour normal?” A login from a country the employee has never visited. A mail rule quietly created to hide replies from the real supplier. A sign-in at 3 a.m. from a device nobody has seen before. Identity is the new perimeter, and watching identity is a different discipline from watching for viruses.

What we hold clients to

The standard here isn’t exotic, but it is specific. Multi-factor authentication on every account, with no exceptions carved out for executives or “just this one shared mailbox,” because exceptions are precisely where attackers go. Phishing-resistant methods where it counts, since criminals have learned to fatigue people into approving push notifications. Conditional access rules that block logins from places your business has no reason to be. Monitoring that reviews sign-in activity and mailbox rules, because those rules are the single most common thing we find after a compromise. And unique passwords through a proper password manager, so a breach at some unrelated website doesn’t hand over your keys.

None of this requires an enterprise budget. It requires someone deciding that “we have antivirus” stopped being an answer years ago, and holding the line on the boring parts. The attackers changed how they get in. The only real question is whether your defences changed with them.