Sixty three percent of the logins Cloudflare observed across its network in the past quarter carried credentials already stolen somewhere else, and 94 percent of all login attempts now originate from bots, not people. Those two numbers, buried in the company's first Cloudforce One threat report, say more about where 2026 security budgets belong than the report's headline claim about a record 31.4 terabit-per-second distributed denial of service attack.
Cloudforce One built the report around a metric it calls Measure of Effectiveness, the ratio of attacker effort to operational payoff. A stolen session token clears that bar more reliably than a custom exploit. A reputable cloud platform hosting a payload clears it more reliably than a rented server. The report's argument is that attackers have stopped optimizing for sophistication and started optimizing for throughput, and identity is the cheapest lever available.
The Front Door Was Never the Weak Point
Multi-factor authentication was supposed to close the credential-theft problem. The report shows why it has not. Infostealer malware such as LummaC2 harvests active session tokens after a user has already authenticated, which means the attacker walks past MFA entirely instead of trying to defeat it. The theft happens post-login, so the control that was built to stop unauthorized logins never gets triggered.
That single mechanic explains the 94 percent bot-traffic figure. Credential stuffing at that volume is not a targeted campaign against one company. It is infrastructure, running continuously against every login page a botnet can reach, because the marginal cost of one more attempt rounds to zero.
Read Access Was Never the Problem. Write Access Is.
Every vendor risk conversation I sit in treats SaaS integration itself as the exposure. The report argues something narrower and more useful: the exposure is the scope of the permission, not the existence of the connection. A read-only integration can leak data. A write-enabled one can act on your behalf, and that is the distinction that turned one compromised Salesloft token into incidents at hundreds of companies that had no direct relationship to Salesloft. The API could write, so the blast radius was every downstream system trusting that write.
Procurement teams that ask vendors "do you integrate with our stack" are asking the wrong question. The one that matters is narrower: what can this integration write, and to how many systems.
The Calendar Invite Is Not Hiding a Payload. It Is the Server.
Attackers stashing malicious links in calendar invites is old news. What Cloudforce One describes is a different animal. One tracked group writes encrypted commands into calendar event descriptions and reads them back later, using the calendar as the command-and-control channel itself rather than a delivery wrapper around one. The event is not bait. It is infrastructure, indistinguishable in your logs from a colleague scheduling a meeting.
That reclassification matters for defenders. A tool built to catch malicious links in invites will miss this entirely, because there is no link and no attachment, only a scheduling app quietly running a command loop nobody provisioned it for.
Email carries a version of the same gap. Nearly half of the messages Cloudforce One analyzed, 46 percent, failed DMARC, the protocol built to confirm a sender is who it claims to be. Phishing-as-a-service operators are pricing that gap into their calculations now.
A write-enabled integration between two approved tools now carries more risk than the firewall in front of either one.
Biometrics Splits Into Two Different Budget Lines
The report treats identity verification as one trend. It is two, and they answer to different buyers. Behavioral biometrics, typing rhythm, mouse movement, session cadence, sits with the security team and answers a narrow question: is the person using this session the same one who logged in an hour ago. Physical identity verification, liveness checks in a video interview, sits with HR and answers a different question entirely: is the candidate on this call a real, single, consistent person.
Deepfaked hiring interviews made the second question urgent on its own terms, independent of anything happening inside the network. A CIO evaluating vendors here is not buying one capability twice. They are buying two, from teams that may never have compared notes before this report gave them a reason to.
Cloudflare Is Grading Its Own Homework
Cloudflare's own coverage of RSAC this spring described a company absorbing security categories one product line at a time, from AI endpoint discovery to bot management. This threat report reads as the evidence base for that expansion. Every finding in it, credential theft, SaaS-tooling abuse, bot-driven logins, points toward products Cloudflare already sells: Turnstile and its newer agent-verification layer Precursor for the login problem, Zero Trust for the SaaS-to-SaaS exposure, and the bot management tier for the 94 percent figure.
That overlap does not make the data wrong. Cloudflare's network carries roughly a fifth of global web traffic, and that vantage point is real. It does mean the report should be read as market research with a genuine methodology attached, not as a neutral academic study, and procurement teams citing these numbers in a board deck should know whose product roadmap the numbers were gathered to support.
If 63 percent of the logins hitting your network already carry stolen credentials, what percentage of your security budget still assumes the front door is the point of failure, and who owns the decision to move that money to identity infrastructure this fiscal year?
