For years, many organizations have been conditioned to think of cyberattacks as obvious events: a sudden spike in failed logins, a phishing campaign hitting hundreds of employees at once, a suspicious domain lighting up security tools, or a flood of alerts that makes it clear something is wrong. Those attacks still happen, but increasingly, some of the more interesting campaigns are designed to do the opposite.
They stay quiet. Activity is spread across accounts, infrastructure and time so that no individual event appears especially alarming. An attacker may test whether a credential works, whether a person will click, whether an authentication flow can be manipulated, or whether there is a path to a valuable account without ever creating the kind of obvious spike defenders are trained to look for.
The internet is already noisy
Every organization operates against a constant background of suspicious activity. Employees receive phishing emails, automated systems test exposed credentials, attackers scan login pages, lookalike domains appear, and passwords leaked in previous breaches get reused against unrelated services. Security teams see versions of this every day, and much of it becomes part of the ambient noise of operating online.
Attackers understand that environment too. If defenders expect a credential attack to generate hundreds or thousands of obvious login failures, the logical response is to avoid generating hundreds or thousands of obvious login failures. Instead, a campaign can move slowly, distributing attempts across different users, IP addresses, locations and time periods so that each event looks ordinary in isolation.
One failed login might not be meaningful. A second attempt against another employee several hours later may not raise alarms either. Add a convincing phishing message, a familiar-looking login page, or a link that appears legitimate at first glance, and the individual pieces can still look relatively harmless. The danger emerges when those pieces are connected.
Low volume can be a feature, not a limitation
Security systems naturally rely on thresholds because thresholds work. When something happens often enough, quickly enough or suspiciously enough, a control can trigger an alert and give defenders something concrete to investigate.
But thresholds also create something attackers can design around. A distributed, low-volume campaign can trade speed for stealth, gathering information and testing defenses over days or weeks rather than trying to compromise an organization in a burst of activity. The attacker does not need to win immediately if remaining unnoticed provides a better chance of success later.
Public information makes this easier. Job titles, leadership teams, company announcements and reporting structures are often readily available online, which means an attacker can begin building a list of valuable targets without needing privileged access to anything. Executives, finance teams, IT administrators and employees with access to sensitive systems can all be identified with surprising ease.
That changes the nature of the campaign. Instead of looking like mass phishing, it can resemble ordinary internet noise directed at exactly the right people.
MFA changed credential attacks. It did not end them.
Multi-factor authentication remains one of the most important security controls an organization can deploy because it dramatically raises the bar for an attacker who has obtained a username and password. But raising the bar does not make the problem disappear.
Attackers have adapted by broadening the question they are trying to answer. Instead of asking only whether they can steal a password, they can ask whether they can convince a user to authenticate to a fake site, proxy a legitimate authentication session, steal a session after authentication, trick someone into approving an OAuth application, or create an impersonation convincing enough that the user completes the next step on their behalf.
This is why credential security and user interaction can no longer be treated as separate problems. An attacker may not need to defeat MFA technically if they can create an experience that causes a legitimate user to authenticate in the wrong place or grant access they did not intend to grant.
The attack eventually reaches a person
Modern organizations can deploy email security, endpoint protection, identity controls, DNS filtering, SIEM platforms, threat intelligence and numerous other defensive technologies. All of them matter, and all of them can stop meaningful parts of an attack chain.
Yet many attacks still converge on a very simple moment: a person is looking at something in a browser and deciding whether to trust it. Is this really Microsoft? Is this actually my bank? Is this the correct login page? Did this message really come from someone I know? Should I grant this application access? Is this domain legitimate?
That moment matters because it is where much of the attacker’s preparation becomes actionable. Reconnaissance, credential testing, impersonation and phishing infrastructure are often designed to influence a decision that takes only a few seconds to make.
Increasingly, that decision happens in the browser.
Another challenge is that many security tools are optimized to identify individual events. They can flag a failed authentication, a suspicious URL, a new domain, an unusual login, a browser extension or an OAuth request. Each of those signals has value, but attackers are not thinking in individual events. They are thinking about the campaign as a whole.
The meaning often emerges from the relationship between signals rather than from any single signal by itself. One failed login may be meaningless, and one visit to a newly created domain may be meaningless. A strange authentication prompt or a convincing impersonation attempt might also be difficult to interpret in isolation.
When several of those things begin happening around the same users, services or organizations, the context changes. The better question is no longer simply, “Is this individual event malicious?” It becomes, “What is happening around this person right now, and do these signals belong to the same story?”
That is a harder security problem, but it is also an increasingly important one.
The browser is becoming a security control point
At Haven, we believe the browser deserves a much larger role in modern security, not because it replaces identity protection, endpoint security or email defenses, but because it sits unusually close to the point where the user interacts with the attack itself.
The browser can provide context about the domain a user is visiting, whether a site appears legitimate, whether a link looks suspicious, and whether an interaction carries characteristics commonly associated with impersonation or phishing. More importantly, it can provide that context while the user is making the decision, rather than after the fact.
That timing matters. Traditional security awareness asks people to remember what they learned days, weeks or months earlier and correctly apply it during a convincing or stressful interaction. Contextual protection has the opportunity to help in the moment, when the user is actually deciding whether to click, authenticate, enter information or continue.
That is a fundamentally different model from relying on awareness alone.
Awareness still matters, but it cannot carry the entire load
People should understand how phishing works, why MFA matters, and why unexpected login requests deserve scrutiny. Good security education still reduces risk and remains an important part of any security program.
The problem is that attackers spend enormous amounts of time making malicious activity look normal. Asking every employee to correctly identify every convincing impersonation attempt, fake login page or carefully timed message is not a realistic security strategy by itself.
The better model is one in which technology helps people make better decisions by giving them context at the moment they need it. For many modern attacks, that means getting closer to the browser and closer to the user rather than relying only on controls that operate before or after the interaction.
The attacks that matter may be the ones we barely notice
The security industry has become very good at detecting explosions: huge phishing campaigns, massive credential attacks, malware outbreaks and sudden spikes in suspicious activity. Those events are visible because they create volume.
The next challenge is recognizing attacks deliberately designed never to create that kind of volume. A few login attempts, a small number of carefully selected targets, a believable domain, a convincing authentication flow and a message delivered at exactly the right moment can all appear unremarkable on their own.
Taken together, however, they may represent something far more deliberate.
The future of security will depend less on asking whether a single event looks dangerous and more on understanding the context surrounding the person experiencing it. Because the next serious credential attack may not arrive as an obvious incident.
It may simply look normal.