As AI-enhanced attacks become increasingly sophisticated, traditional identity security measures are struggling to keep pace. The days of relying solely on passwords and multi-factor authentication (MFA) responses to secure online accounts are numbered, as attackers find new ways to bypass and exploit these controls.
The rise of artificial intelligence has not introduced a fundamentally new type of attack, but rather amplified familiar techniques such as phishing, credential theft, MFA abuse, session hijacking, and social engineering. With AI’s help, threat actors can now automate the process of creating convincing phishing emails, adapting their message to match the target’s language and business context. This not only speeds up the attack but also makes it more effective.
The Verizon Data Breach Investigation Report found that stolen credentials are involved in 44.7% of breaches, highlighting the vulnerability of traditional identity security measures. Even MFA, which is considered a robust authentication method, can be compromised through techniques such as phishing, social engineering, or adversary-in-the-middle attacks.
Device trust has emerged as an essential component in securing online accounts. By verifying the device context from which valid credentials are used, organizations can ensure that even legitimate logins from attacker-controlled infrastructure are detected and prevented. This is particularly important in today’s threat landscape where rotating IP addresses, disposable browser profiles, and other evasion techniques make it increasingly difficult to distinguish between malicious and legitimate activity.
The use of AI has accelerated the pace at which attackers can launch identity attacks. Rather than relying on manual effort, AI enables teams to automate the process of creating phishing campaigns, adapting messages, and identifying potential targets. This not only increases the speed but also the scale of attacks, making it even more challenging for organizations to keep up.
To protect against these evolving threats, organizations need to adopt effective Zero Trust measures that prioritize device trust as a key component. By combining traditional identity security controls with device verification, organizations can significantly reduce the risk of unauthorized access and minimize the impact of successful breaches.
Ultimately, the increasing reliance on AI-enhanced attacks underscores the importance of adopting a more proactive approach to identity security. This requires a combination of technical measures, such as implementing robust authentication protocols and device trust solutions, as well as non-technical strategies, like employee education and awareness programs. By taking a comprehensive approach to identity security, organizations can stay ahead of the evolving threat landscape and protect their users from increasingly sophisticated attacks.
For individuals and organizations looking to strengthen their password policies and block compromised passwords, tools like Specops Password Auditor can help identify leaked credentials and related vulnerabilities. This not only improves overall security but also reduces the administrative burden associated with managing complex authentication flows.
Source: Bleeping Computer — 2026-08-10