When Credentials Are No Longer Enough: Device Trust in the AI Era

Identity Security Under Siege as AI-Powered Attacks Gain Momentum

The traditional arsenal of identity security measures is facing a perfect storm of challenges. Passwords, multi-factor authentication (MFA) responses, IP reputation, geolocation, and browser characteristics that once provided a robust defense against login attempts are now increasingly vulnerable to exploitation by attackers.

Artificial intelligence (AI) has not created a new class of attack, but it has significantly amplified the efficiency and speed of familiar identity attacks. This shift is being driven by the growing availability of stolen credentials, disposable browser profiles, and rotating IP addresses that make malicious logins harder to distinguish from legitimate ones.

As organizations grapple with this evolving threat landscape, they need a more effective approach to security – one that prioritizes device trust alongside traditional authentication methods. Device trust ensures that valid login credentials are insufficient without the context of the device being used to access the system. This additional layer of protection is critical in identifying and blocking “legitimate” logins from attacker-controlled infrastructure.

The Industrialization of Account Takeover Attacks

AI has not fundamentally changed the nature of account takeover attacks, but it has significantly streamlined the process. Attackers continue to rely on techniques such as phishing, credential theft, MFA abuse, session hijacking, and social engineering. However, AI-powered tools have made these attacks faster and more efficient by automating tasks that were previously labor-intensive.

Threat actors can now create and send thousands of convincing phishing emails with minimal effort, making it easier to trick victims into revealing sensitive information. Moreover, AI can help attackers personalize their messages based on the target’s language and business context, increasing the likelihood of a successful attack.

While AI is often portrayed as an autonomous force driving cyberattacks, in most cases, human decision-making still plays a crucial role. People choose targets, control infrastructure, and decide how to act once access is gained. The more accurate description of AI’s impact is that it compresses the time between acquiring information and acting on it, allowing attackers to execute multiple campaigns with greater ease.

The need for effective identity security measures has never been clearer. Verizon’s Data Breach Investigation Report found that stolen credentials are involved in 44.7% of breaches, highlighting the importance of securing active directory passwords.

Where Traditional Trust Signals Are Falling Short

Traditional trust signals, including credentials, MFA responses, IP reputation, geolocation, and browser characteristics, are increasingly vulnerable to exploitation. Attackers can steal, imitate, or bypass these controls with ease, making it essential for organizations to adopt more robust security measures.

Credentials remain a crucial factor in many authentication flows, but they can be easily compromised through phishing or stolen from previous breaches. In fact, the recent hijacking of IGN’s Twitch stream using Restream.io credentials highlights the importance of scanning for leaked credentials and implementing password policies that prevent such incidents.

MFA, while effective, is not foolproof. One-time codes can be captured through phishing, push notifications can be abused through repeated prompts or social engineering, and adversary-in-the-middle phishing can relay credentials and MFA responses in real time. Similarly, IP address and geolocation-based controls can be evaded using residential proxies, mobile networks, or compromised systems.

In light of these challenges, organizations must adopt a more comprehensive approach to identity security that prioritizes device trust alongside traditional measures. This includes implementing effective Zero Trust policies, regularly scanning for leaked credentials, and adopting robust password policies that prevent the exploitation of stolen credentials. By taking these steps, organizations can significantly reduce their risk exposure and protect against even the most sophisticated AI-powered attacks.


Source: Bleeping Computer — 2026-08-10