CISA Wants Defenders to Deploy Fake Credentials and Systems to Catch Hackers
Brief
CISA has urged organizations to deploy fake credentials, systems, files, and data assets inside their environments to expose attackers after an initial compromise. The agency published its new guidance, Using Cyber Decoys to Strengthen Detection and Response, on September 16, 2026.
CISA said many attackers now avoid malware-heavy intrusion methods and instead abuse legitimate user accounts, built-in administrative tools, and living-off-the-land techniques .
These methods can help threat actors blend into normal network activity. At the same time, they perform discovery, move laterally, escalate privileges, and access sensitive information.
CISA Urges Fake Credentials to Catch Hackers
Cyber decoys are intentionally planted assets that appear real but have no legitimate business use.
