An increasing number of cyberattacks are now being carried out using compromised user identities rather than through traditional system breaches. Data from Nordlo’s Security Operations Centre (SOC) shows that the number of incidents in Sweden has tripled in just eight months.
“We are seeing an entirely new pattern. It is significantly more difficult to defend against and affects both small and large businesses,” says Magnus Blomberg, CTO at Nordlo.

Magnus Blomberg, CTO at Nordlo.
Through its SOC service, which monitors and stops cyberattacks around the clock, Nordlo is seeing a new pattern emerge in Sweden. Instead of breaking through technical security measures, unauthorised actors are logging in with stolen credentials and operating as legitimate users.
Nordlo has observed a clear trend. Between October 2025 and May 2026, the number of incidents involving malicious activity that was detected and prevented tripled.
“The trend is linked to the fact that an increasing number of business systems and services are accessible via the internet. This means that the traditional security model, where the firewall, for example, provided a clear protective barrier, has largely become obsolete. Today, identity is the new attack surface.”
As a result, breaches are becoming considerably more difficult to detect. Because attackers use valid login credentials, their activity often appears to be normal user behaviour, meaning that traditional security tools do not always respond.
“What makes this type of attack so serious is that it blends in with normal behaviour. An attacker can remain undetected within an environment for a long time, gathering information or preparing for a larger attack,” says Magnus Blomberg.
At the same time, data from analyst firm Radar, commissioned by Nordlo, shows that three in four Swedish companies are prioritising increasing cybersecurity knowledge and awareness among their employees.
“This reflects a growing recognition that identity, and how it is used, is central to today’s threat landscape. It affects all types of organisations, regardless of size or sector.”
Nordlo’s SOC continuously analyses large volumes of data and can identify anomalous patterns in real time. This makes it possible to detect and stop breaches even when valid user credentials are being used. Many attacks also take place at night, at weekends and during public holidays, when organisations often have limited staffing.
“Employee awareness is an important part of cybersecurity, but it needs to be combined with technology and continuous monitoring. Only then can organisations achieve comprehensive protection,” says Magnus Blomberg.
For more information:
Magnus Blomberg, CTO Nordlo, +46 736 84 04 54, magnus.blomberg@nordlo.com
Caroline Peterson-Ullstrand, CMO & CCO Nordlo, +46 72 562 87 55 caroline.peterson-ullstrand@nordlo.com
Nordlo is one of the leading providers of cloud and infrastructure services in the Nordic region. The company offer scalable operational solutions, managed services and full outsourcing of IT and digitalisation services to companies and public sector organisations. Through close cooperation and sustainable choices of innovative technology, Nordlo helps customers to strengthen their competitiveness and drive digitalisation forward. Nordlo has a turnover of SEK 2.5 billion and approximately 1000 employees at locations throughout Sweden and large parts of Norway. https://nordlo.com/en
Tags: