What Recent AI-Powered Attacks Mean for Your Identity Security

Cybercrime just got a whole lot more efficient, thanks to AI-powered attacks that are changing the game for identity security.

In a disturbing demonstration of what’s possible with artificial intelligence, Google Threat Intelligence Group (GTIG) recently revealed several attacks that showcase the speed and scalability of cybercrime. One such attack saw a threat actor compromise an organization’s cloud infrastructure in under six hours, harvesting thousands of third-party credentials in the process. The AI even took care of some of the heavy lifting, automating parts of the vulnerability-scanning pipeline and rotating IP addresses with minimal human intervention.

The problem is that these same capabilities that make organizations more productive can also be used by threat actors to make attacks faster and easier to scale. And it’s not just about the speed – AI-assisted phishing campaigns have been shown to achieve click-through rates as high as 54%, compared to around 12% for traditional campaigns. This is because attackers can now generate targeted messages more quickly, adapt them for different languages or industries, and create variations without writing each one from scratch.

The economics of phishing are shifting in favor of the attacker, making it easier to steal credentials at scale. And with stolen credentials involved in over 44% of breaches, according to Verizon’s Data Breach Investigation Report, this is a worrying trend for organizations. It’s not about introducing new ways to steal credentials – AI simply makes established techniques more efficient.

But here’s the thing: attackers still rely on familiar weaknesses such as weak and reused passwords. This means that visibility is a crucial first step in reducing credential exposure. Before security teams can address these issues, they need to know where the weaknesses are in their own environment.

Specops Password Auditor is one tool that can help with this. By performing a read-only scan of your Active Directory, it identifies password-related vulnerabilities and highlights issues with users and password policies. The resulting report gives security teams a clearer view of where credential risk exists today, so they can prioritize what needs attention.

However, successful authentication isn’t necessarily trustworthy. When attackers use stolen credentials to gain access, they may not even need to exploit a vulnerability or use an obviously malicious login mechanism. They can simply abuse valid identities, using the same authentication processes employees use every day. This changes what malicious activity looks like to defenders, making it harder to spot.

The key issue for security teams is that, wherever credentials are stolen from, they provide valuable access that an organization’s authentication system is designed to accept. This is where the distinction between authentication and trust starts to matter – a correct password or login doesn’t necessarily mean that the intent behind it is legitimate.

So what can organizations do? For starters, they need to ensure their current authentication processes are robust enough to confidently establish that users and devices connecting to internal networks are trustworthy. This means prioritizing visibility, addressing weaknesses such as weak and reused passwords, and keeping up with the latest threats – including those enabled by AI. By doing so, they can reduce credential exposure and stay one step ahead of the attackers.


Source: Bleeping Computer — 2026-09-17