In 2026, the most dangerous cyberattacks will no longer force systems. They connect there, with the correct identifiers, before doing sometimes considerable damage.
We still too often imagine a computer hacker as someone who breaks a lock. The reality today is much more uncomfortable: he has the badge. He enters, he navigates, he exfiltrates, and everything seems like normal activity. The most dangerous attack is often clean, silent, authenticated. It operates a legitimate account, an active session, a digital access key forgotten in a corner of the infrastructure. The detection systems see nothing abnormal. Neither do IT teams. This is precisely where the danger lies.
A profound change in attack methods
For years, businesses have built their defense around a simple principle: preventing intrusion. Filter emails, protect the network, block malware. This so-called “fortified castle” model worked for a time. It is no longer enough. Now, most attack paths begin with a compromised identity: reused passwords, session theft, spyware, or access purchased through stolen data brokers. The ecosystem has become industrialized. Spyware steals credentials from a poorly protected workstation. An intermediary resells them. A criminal group uses them to quietly enter a business application. The result is formidable… The risk is no longer just that a hacker has installed malicious software. The risk is that he uses legitimate access and everything looks like normal activity. It’s much harder to detect. And much more difficult to explain to general management when the damage begins.
An underestimated application attack surface
Web applications have become the preferred playground for these new attacks. They concentrate sensitive data, user sessions, exposed interfaces. They are accessible from everywhere. And they often remain the poor relation of security strategies. The ÉduConnect attack of late 2025, for example, exploited an IDOR flaw, an application vulnerability where an identifier exposed in a URL allowed access to other users’ resources without authorization. No sophisticated malware. No spectacular intrusion. A simple flaw in application logic… and millions of pieces of data exposed. This type of vulnerability is commonplace. It is also largely neglected. Audits focus on infrastructure, while applications accumulate blind spots.
A blind spot that the figures confirm
According to the barometer CESIN 2026, Data theft remains the primary consequence of attacks. Information remains the most coveted asset, and web applications are the main gateway. The number of data breaches notified to the CNIL reached 6,167 over the whole of 2025, up almost 10% compared to 2024. The trend is not slowing down, it is accelerating. And behind each notification, there is an insufficiently protected application, an uncontrolled session, an access key whose lifespan was too long.
A response that must evolve
The good news is that the fundamentals exist. Reduce the length of sessions. Control digital access keys. Audit application access. Apply the principle of least privilege. Reduce exposure, harden identity, remove unnecessary access, monitor continuously: these actions work, provided they are applied seriously.
The bad news… is that these actions require looking at applications for what they really are: the new security perimeter. Not a secondary layer. Not a technical detail. The heart of the problem.
Now the question is no longer whether a company will be targeted. It’s knowing which door the attacker will enter through. Most often, this door is application and it is open.