Recent cyberattacks have shown that sophisticated technical vulnerabilities are not always necessary for cybercriminals to succeed. In many cases, a compromised identity, a stolen password, or overly broad access rights can be enough to infiltrate systems. The case involving the alleged hacker group ZeroBytes highlights this point. French authorities are investigating attacks on the Direction générale des Finances publiques (DGFiP), the country’s tax authority. An 18-year-old man was placed under formal investigation and briefly detained, while a second suspect, under 16, was arrested but later released. According to the investigation, the attackers used compromised access rights belonging to state employees to carry out two intrusions in June and July, allegedly stealing data on 678,000 individuals and professionals. The key takeaway is that cybercriminals can exploit legitimate access points rather than breaking into systems directly. One of the main issues is how an identity—such as a username and password—can become a major point of entry. In the DGFiP case, the attackers used compromised credentials from state employees. Once inside, the real challenge is not just gaining access but moving further within the system. This depends on factors like the level of access privileges, the absence of multi-factor authentication (MFA), and the lack of proper monitoring. The problem extends beyond the initial breach to how identities and access rights are governed within an organization. Why do certain users have administrative privileges? Why do old accounts remain active after a project ends? These questions underscore the need for better identity governance and stricter access controls. The traditional reliance on passwords alone is no longer enough to protect digital assets. Cybercriminals have found ways to steal credentials from users through malicious software or by recording data entered on personal devices. A company may have strong protections on its work computers, but if employees use personal devices with weak security, that can become a vulnerability. To address this, stronger authentication methods like MFA are essential. While SMS-based codes are common, more secure options—like hardware tokens or biometric verification—are preferable. However, improving authentication is only part of the solution. Organizations must also consider the broader context of how data is accessed and protected. Another challenge is securing what are known as "non-human" identities—connected devices, printers, industrial equipment, and automated systems. These components, which are increasingly integrated into digital environments, can become entry points for attackers. In industrial settings, for example, a compromised device can bridge the gap between IT systems and operational systems, potentially causing physical damage or disruptions. Managing the access rights of these non-human identities is becoming a critical part of cybersecurity. As artificial intelligence and software agents gain more capabilities, the need to control their permissions and monitor their actions grows more urgent. The evolution of cyber threats also means that IT (information technology) and OT (operational technology) systems can no longer be treated separately. Many industrial systems were designed without cybersecurity in mind, and some are difficult to update. A single compromised device can become a strategic point for attackers, affecting not just digital systems but also physical operations. This has led to attacks with geopolitical implications, as critical infrastructure becomes a target. Cybersecurity is no longer just about protecting data—it’s also about ensuring national security and sovereignty. The ZeroBytes case also raises broader questions about how cybercriminals are formed. The young age of some suspects suggests that access to digital tools, communities, and knowledge is becoming more widespread and accessible at an early age. This challenges the idea that humans are the "weak link" in cybersecurity. Instead, it highlights the need to strengthen human elements by improving awareness and understanding of cyber threats. Training must go beyond occasional sessions and help employees recognize risks like phishing, identity theft, and social engineering. Finally, cybersecurity must move from a fear-based approach to one focused on mastery and control. Organizations need to understand where they are exposed, what access rights are necessary, and what data might be vulnerable. This includes monitoring weak signals from the cyber ecosystem, analyzing data from underground forums, and regularly testing defenses. The goal is not to prevent all breaches but to limit their impact. Future cybersecurity will depend less on the number of tools used and more on mastering identities, access rights, and overall exposure. This requires an organizational, human, and educational response, as the threat landscape continues to evolve.