Advisory
6 min read
Why Stolen Logins Go Unnoticed for Weeks
Stolen logins go unnoticed for weeks because, to most security tools, a valid username and password look exactly like an authorized employee logging in. There's no malware signature to catch, no exploit to flag. Just someone using credentials that work.
A recent breach involving a French tax agency illustrates the pattern: attackers used valid staff credentials, and public reporting describes the access going undetected for an extended stretch before anyone noticed. It's not a one-off story. It's how credential-based intrusions usually play out, in organizations of every size.
What actually happened (and why it's common)
In cases like this, the attacker doesn't hack in, in the dramatic sense. They obtain a working password, through phishing, a leaked credential dump, a reused password from another breach, or an infected personal device, and then simply log in through the front door.
From that point on, every action they take looks like legitimate user activity to systems that are only watching for obvious red flags. That's the core problem: most detection tools are tuned to catch bad code, not bad behavior by a "good" account.
Why valid credentials evade normal monitoring
Three gaps let this slip through, over and over:
No behavioral baseline. Many organizations don't track what "normal" looks like for a given user: typical login times, locations, devices. So nothing looks abnormal even when it is.
Alert fatigue. Security teams (where they exist at all) are often drowning in low-priority alerts, so a single unusual login among thousands of events gets lost.
No dedicated eyes on identity. Many SMBs have antivirus and a firewall, but nobody specifically watching login patterns, admin privilege use, or access to sensitive systems.
If you don't have a security operations function reviewing identity activity specifically, not just network traffic, this is probably true for your business too.
A simple heuristic to spot it sooner
You don't need a full security operations center to shrink this gap. Use this as a monthly check:
If a staff login occurs from a new country or device, and it isn't tied to a known trip or new hardware, treat it as suspicious until confirmed, not until proven malicious.
If an account accesses systems or data it's never touched before, flag it for review, even if the login itself looked normal.
If multi-factor authentication is disabled, bypassed, or "temporarily" turned off for convenience, put a hard deadline on turning it back on, and log who approved the exception.
If a dormant or former-employee account becomes active again, treat it as an incident first, housekeeping second.
None of this requires exotic tooling. It requires someone with the habit of asking "does this match what we'd expect?" and the authority to act when it doesn't.
The objection: "We don't have anyone to watch this"
This is the realistic blocker for most small and mid-size businesses, and it's a fair one. Most SMBs don't have a 24/7 security team, and hiring one isn't realistic at this stage.
The answer isn't to build an internal SOC from scratch. It's to put identity monitoring on someone's job description, internal or outsourced, even part-time, rather than leaving it to whoever notices. A managed security partner can take on this kind of ongoing watch, so unusual login activity gets reviewed on a regular cadence instead of discovered by accident weeks later. See our managed security page for how that works in practice.
If you suspect an account is already compromised, don't wait for certainty. Contain first, investigate second. Our incident response team exists for exactly that moment.
What to do this week
You can make real progress without a big project:
Pull a list of accounts with admin or sensitive access and confirm every one is still needed.
Check that multi-factor authentication is actually enforced, not just available, on email, cloud consoles, and remote access.
Disable any account for an employee who's left, right now, not at the next offboarding cycle.
Ask whoever manages your identity systems: "If an attacker logged in with a valid password tomorrow, how would we know, and how fast?" If the honest answer is "we probably wouldn't," that's your starting point.
In one engagement with a venture-capital-backed technology company that had no dedicated security hire, our team achieved full endpoint coverage and contained an active intrusion as part of a broader cloud and identity review. The gap this article describes is the one that work closed. You can read more in our case study.
For general guidance on protecting identities and accounts, CISA publishes practical, vendor-neutral resources.
Next step
If you're not confident you'd catch a stolen-but-valid login this month, that's worth a closer look before it becomes a worse problem. Our free security review is a low-friction way to find out where your blind spots are, no pressure, no long sales process.
Want this looked at for real?
Get a free security review and we will show you where you actually stand.