What Is an Attack Vector? Types, Examples & Prevention

An attack vector is the method or entry point an attacker uses to gain unauthorized access to a system, network, application, or account.
Published on
Monday, September 21, 2026
Updated on
September 20, 2026

What Is an Attack Vector in Cybersecurity?

An attack vector is the method or entry point an attacker uses to gain unauthorized access to a system, network, application, or account. A phishing email, a stolen password, an unpatched service, and a misconfigured cloud bucket are all attack vectors.

It answers one question: how did they get in? That is separate from the weakness being exploited and separate from the code used against it, and those three things get confused constantly.

How Attack Vectors Work

An attack vector carries an attacker from outside a system to inside it. The sequence rarely varies.

The attacker finds a weakness first: outdated software, a reused password, an exposed cloud service. A vector then delivers the attack against that weakness. Access widens from there through malware installation, data theft, or movement toward other systems.

Every vector targets a weakness in technology, in human judgement, or in configuration. A phishing message works on judgement. An unpatched flaw works on technology. An open storage bucket works on configuration, and no exploit is needed at all.

Passive and Active Attack Vectors

Vectors split into two categories based on whether the attacker changes anything.

Passive Vectors

They observe the target without altering anything on the system. Network traffic monitoring, packet capture, and collection of credentials from exposed data sources all fall here. Nothing changes, so the activity can run unnoticed for a long time.

Active Vectors

Active vectors interact with the target directly and leave a change behind. Phishing messages that install malware, exploitation of unpatched flaws, brute-force login attempts, and code injection against a web application all produce traces.

Common Types of Attack Vectors

Almost every documented intrusion uses one of ten recurring categories. Exploitation of vulnerabilities leads the current figures, recorded by Mandiant as the most common initial infection vector for the sixth consecutive year at 32 percent of intrusions where the vector could be established.

types of attack vectors

Phishing and Social Engineering

Deceptive messages persuade a user to reveal credentials or run a malicious file, most commonly by impersonating a trusted sender. Phishing covers email, spear phishing, voice, and SMS variants. CloudSEK's investigation into an APT36 campaign shows the current form: a phishing archive carrying a Linux shortcut disguised as a procurement document.

Compromised Credentials

Valid usernames and passwords obtained through reuse, credential stuffing, brute force, or infostealer malware. The attacker logs in as a legitimate user and triggers no failed login alert. CloudSEK's FortiBleed research documented an operator holding a database of validated credentials for internet-facing gateways, assembled entirely without exploiting any software flaw.

Malware

Malware delivered through attachments, trojanized applications, or compromised websites. Once it runs, it steals data, installs a backdoor, or hands over remote control of the host.

Vulnerability Exploitation

Unpatched flaws in applications, operating systems, and network devices give an attacker code execution or direct access. Internet-facing systems carry the highest risk here, because exploitation needs no user involvement and no credentials.

Misconfigured Systems

Exposed cloud storage, open services, default credentials, and permissive access settings create entry points that require no technical skill to use. Configuration errors produce more accessible openings than most vulnerability classes do.

Supply Chain Compromise

Attackers compromise a trusted software provider, library, or update mechanism, not the target itself. CloudSEK's investigation into the March 2026 LiteLLM compromise traced the entry point to a security scanner inside LiteLLM's own build pipeline. Malicious packages sat on PyPI for around 40 minutes and reached more than 2,500 organizations and roughly 434,000 CI/CD pipelines.

Insider Threats

Misuse of legitimate access by employees, contractors, or partners, whether deliberate or careless. Authorization is already in place, which makes this the hardest vector to separate from normal activity.

Web and API Attacks

Injection flaws, broken authentication, insecure object references, and abused API endpoints reach data and back-end systems directly. CloudSEK's investigation into public Postman workspaces found more than 30,000 of them leaking access tokens and API keys, which turns an application vector into a credential vector.

Cloud and Identity Attacks

Exposed storage buckets, over-broad IAM roles, stolen OAuth tokens, and session-token theft. A stolen session token skips authentication entirely, so multi-factor authentication does not stop this category once the token is in hand.

Physical Attack Vectors

Tailgating into a facility, plugging in a rogue USB device, or using an unlocked workstation. Digital-only security programs leave this category unaddressed, and it remains the route into environments with no internet exposure at all.

How Attack Vectors Chain Together

Single-vector intrusions turn out to be the exception rather than the norm. Real campaigns combine several, because each one solves a different problem for the attacker.

A common sequence runs like this. Phishing delivers an infostealer; the infostealer harvests saved browser credentials; those stolen credentials open a VPN portal, and an unpatched internal server then supplies the privilege escalation. Four vectors, one intrusion, and each stage leaves a different kind of evidence.

Chaining matters for defense because closing one vector rarely ends the exposure. Blocking the phishing message stops that route, and the harvested credentials remain valid until somebody revokes them. Treating each vector as an isolated finding is how organizations remediate an incident and get breached through the same campaign a month later.

Vector inventories understate risk for the same reason. A list records which doors exist. It says nothing about which doors open onto each other, and that second question is the one that decides remediation order.

Attack Vector vs Vulnerability, Exploit, Attack Surface, and Attack Path

These terms describe different parts of the same event, and practitioners use them interchangeably every day. Separating them matters, because each one answers a different question during an investigation.

Term What It Means Question It Answers
Attack Vector The method or path used to gain initial access How did they get in?
Vulnerability The underlying weakness in software, configuration, or process What was wrong?
Exploit The specific code or technique that turns a weakness into working access What did they use against it?
Attack Surface Every possible entry point across the environment Where else could they have got in?
Attack Path The route taken through the environment after initial access Where could they go next?

A worked example ties them together. An unpatched VPN appliance is the vulnerability. The code targeting that flaw is the exploit. The internet-facing appliance itself is the attack vector. Every other exposed service forms the attack surface, and the route from that appliance toward a domain controller is the attack path.

Real-World Attack Vector Examples

The same objective can be reached through completely different vectors, as these three incidents show.

WannaCry, 2017: Vulnerability Exploitation

Ransomware spread by exploiting the EternalBlue flaw in unpatched Windows systems. The vulnerability was the vector, and the campaign self-propagated across more than 200,000 systems in over 150 countries with no user action required.

SolarWinds, 2020: Supply Chain Compromise

Operators planted malicious code inside legitimate Orion platform updates. Roughly 18,000 customers installed the compromised build, which let the attacker in without a single phishing message or stolen password.

Twitter, 2020: Social Engineering

Attackers used phone-based social engineering against employees to reach internal administrative tools, then hijacked high-profile accounts for a cryptocurrency scam. Mature technical controls made no difference, because the vector bypassed all of them.

Emerging Attack Vectors in 2026

Cloud migration and AI adoption moved the entry points. These categories barely existed as vectors five years ago.

  • Exposed cloud services: storage buckets, databases, and management consoles left reachable from the internet with no authentication in front of them.
  • API abuse: attackers target APIs directly, not the applications built on top of them, and authorization checks are commonly weaker at that layer.
  • Session token theft: stealing an already-authenticated session bypasses both the login and the second factor, since the token records that authentication already happened.
  • SaaS and vendor compromise: a third-party platform becomes the stepping stone into every customer environment connected to it.
  • Leaked secrets in pipelines: API keys and tokens exposed in code repositories, CI/CD systems, and logs, which dark web monitoring catches only once they are traded.
  • AI application attacks: prompt injection and data exfiltration against AI-powered applications, which widen the AI attack surface well beyond traditional application risk.
  • MCP server exposure: unauthenticated Model Context Protocol servers expose internal tools to any caller. A CloudSEK case study traced one from an exposed server through SSRF and local file inclusion to live AWS credentials.

How Security Teams Identify Attack Vectors

Identification means finding the entry points before an attacker does. Four practices carry most of the work.

  • External attack surface discovery: continuous scanning of internet-facing assets finds the exposed services, forgotten subdomains, and expired certificates that never reached an inventory.
  • Vulnerability assessment: automated scans check software versions, configurations, and exposed services against known weaknesses, ranked by exploitability rather than raw count.
  • Penetration testing: controlled simulation confirms which vectors actually work against the environment, which is different from which flaws exist on paper.
  • Detection coverage mapping: aligning telemetry to the MITRE ATT&CK framework shows which initial access techniques the program would catch and which it would miss.

How to Prevent Attack Vectors

Prevention closes entry points and limits what any single one achieves. Sequence matters, because identity controls and patch velocity outperform everything else on current data.

strategies to prevent attack vectors
  • Patch internet-facing systems first: exploitation leads the initial access figures, which makes patch cadence on exposed systems a top-line metric instead of a background task.
  • Deploy phishing-resistant authentication: multi-factor authentication devalues stolen credentials, and hardware-backed methods survive the session-theft techniques that defeat one-time codes.
  • Harden configuration by default: close unnecessary ports, disable unused services, remove default credentials, and restrict public access on storage and applications.
  • Apply least privilege everywhere: scope access to role, so one compromised account reaches a fraction of the environment. Zero trust conditions extend this to every request rather than every login.
  • Verify the software supply chain: pin dependency versions, verify signatures, and monitor vendor posture continuously. Supply chain defense is where the LiteLLM class of incident gets caught.
  • Train against targeted deception: generic awareness training does little against a message built from real correspondence. Out-of-band verification for payment and access changes stops business email compromise where training alone fails.
  • Monitor and correlate telemetry: endpoint, identity, and network signals joined in one security operations workflow catch the vectors that individual alerts miss.

From Attack Vectors to Validated Attack Paths

Enumerating attack vectors turns out to be the easy half of the problem. The harder question is which of them actually connects to something worth protecting, because an exposed asset leading nowhere is a different priority from one reaching a domain controller in two steps. Nexus AI correlates initial access vectors across external exposure, dark web activity, AI infrastructure, and third-party ecosystems into validated attack graphs, which convert a queue of findings into a ranked list of paths worth breaking.

Attack Vector FAQs

What are the most common attack vectors?

Vulnerability exploitation, phishing and social engineering, compromised credentials, and malware. Exploitation of exposed systems currently leads the incident response data.

Is phishing an attack vector?

Yes. It delivers initial access by persuading a user to reveal credentials or run malicious code, which makes it one of the most common vectors.

What is the difference between an attack vector and a vulnerability?

A vulnerability is the weakness itself. The attack vector is the path used to reach and exploit it. One is the flaw; the other is the route.

What is an initial access vector?

The specific vector used for an attacker's first foothold. MITRE ATT&CK treats initial access as the opening tactic of an intrusion.

Can one attack use multiple attack vectors?

Yes. Operators chain them routinely, using phishing to steal credentials and then exploiting a flaw to widen access once inside.

Which attack vector is hardest to detect?

Insider misuse and stolen credentials, because both generate the same telemetry as legitimate activity and trigger no failed access attempts.

Related Posts
12 Common Cyber Attack Vectors You Should Know
Cyber attack vectors include phishing, compromised credentials, exposed software, API abuse, supply chain threats, and other paths attackers use for initial access.
What is Pastebin? Uses, Risks, and How It Works
Pastebin is a free site for sharing plain text and code via a link. How Pastebin works, its legitimate uses, security risks, and how attackers abuse it.
What is Personally Identifiable Information (PII)?
Personally identifiable information (PII) is any data that identifies a specific person. PII types, examples, exposure risks, and the laws that govern it.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.