Identity

Q1 2026 Complete: Credential Attacks, a Fuel Crisis, and Why Identity Infrastructure Can No Longer Wait

Return-to-office mandates were the headline going into 2026. By the end of March, governments were telling people to stay home, identity-based attacks were hitting critical sectors across the country, and regulators started handing down penalties for inadequate identity controls.

Three very different stories. One common thread. Here's how they connect.

What happened

The ongoing conflict in the Middle East shut down the Strait of Hormuz, taking 20% of global oil supply with it. The flow-on to Australia was immediate. Fuel prices surged to record levels, and all the post-pandemic push to get people back into the office shifted from "return to your seat" to "this is no longer a reasonable request."

Identity-based attacks dominated the quarter. A major breach in the Victorian education sector impacted 1,700 government schools (Information Age / ACS). And confirmation that stolen credentials remained the most common way attackers break into organisations globally, for the third year running (Verizon DBIR).

Regulatory penalties for cyber security control failures became real, with Australia's first civil penalties for inadequate identity and access controls handed down this quarter (Global Compliance News / Baker McKenzie).

The common thread

These look like separate headlines. They are not. Identity-based attacks succeeded because basic controls were not consistently enforced: multi-factor authentication, password policies, and making sure former employees lose access when they leave. Similar to the pandemic, the fuel crisis exposed organisations that cannot securely support remote access. Regulatory penalties confirmed that identity security is now a compliance obligation. The thread running through all of it is identity infrastructure that was not built for how organisations need to operate today.

Where IAM is heading

The global market for identity and access management grew 24% year-on-year in January (CSO Online / Context). Here's what's driving it:

  • AI tools are starting to act on behalf of employees. That means organisations need to control not just who has access, but what software is acting on whose authority, and for how long.
  • Security is moving from "check once at the door" to continuous verification. Modern frameworks now monitor identity, device, and behaviour throughout an entire session, adjusting access in real time based on risk.
  • Admin and privileged access is being brought under tighter control. Elevated permissions are now granted only when needed and revoked automatically afterwards, with AI monitoring for unusual activity.
  • Passwords are on the way out. Passkeys, biometrics, and hardware keys are replacing traditional logins at enterprise scale, cutting one of the biggest security risks and reducing help desk workload at the same time.

What Q2 should be about

Getting the foundations right. Who has access to what. Making sure that access is appropriate, up to date, and works from anywhere. Ensuring that when someone joins, changes roles, or leaves, their access updates automatically. And building systems where security does not depend on being in a specific building.

We have seen what this looks like at scale. Our team is currently delivering one of the largest identity transformations in the Australian higher education sector, spanning hundreds of thousands of identities across students, staff, researchers, and external partners, with complex access requirements across cloud and legacy environments. IAM is not theoretical for us. It's operational.

The foundational work can start within weeks. The returns are: reduced IT overhead, faster onboarding, stronger security posture, and the kind of compliance readiness that keeps you on the right side of the penalties we saw this quarter.

Q2 is the window. Build the identity infrastructure that makes the next disruption irrelevant.

At Move FWD, IAM transformation is our expertise. If Q1 highlighted areas you want to get ahead of, reach out to our team via hello@movefwd.agency or 1300 683 393.