AI deepfakes, token theft redefine cyber threats

The gist
Identity-based cyberattacks fueled by AI deepfakes and stolen tokens have exploded 850% in 2026, overwhelming defenses and forcing a radical cybersecurity rethink.
What to know
- Over half of all cyber incidents now involve identity attacks, with criminals exploiting SSL VPNs and RMM tools in 63% of cases to sidestep malware defenses.
- AI-powered deepfake scams make up 16% of breaches, doubling annual financial scam losses to $20 billion by automating millions of nearly undetectable phishing attempts.
- Breaches like Team PCP’s token thefts have spurred urgent adoption of zero trust and AI-proof identity verification, as attackers routinely bypass MFA with sophisticated phishing kits.
Identity Attacks Eclipse Malware
Cybercriminals now sidestep hardened malware defenses by hijacking credentials and session tokens, fueling an 850% surge in stealthy, identity-driven breaches.
By early 2026, cybercriminals have decisively shifted from traditional malware exploits to identity-centric attacks, with identity-based threats now accounting for more than half of confirmed cybersecurity incidents and exhibiting an 850% year-over-year increase, according to Red Canary. This pivot is driven by hardened malware defenses—such as Microsoft's blocking of macro-enabled attachments—that have pushed attackers to prioritize stealing credentials and session tokens, which offer stealthier and more direct access to cloud and SaaS environments. As Sophos highlights, 2022 marked the last year when non-identity related intrusions outnumbered identity-based ones, underscoring a fundamental reshaping of the threat landscape.
Attackers increasingly exploit legitimate credentials and trusted tools to gain initial access, with Blackpoint Cyber's 2026 Annual Threat Report revealing that 32.8% of incidents involved SSL VPN abuse and 30.3% involved Remote Monitoring and Management (RMM) tool exploitation—ScreenConnect being implicated in over 70% of rogue RMM cases. This reliance on routine, authorized access methods, combined with social engineering campaigns like fake CAPTCHA and ClickFix-style prompts that trick users into executing commands, enables attackers to bypass traditional malware detection and maintain persistence undetected.
Despite widespread adoption of multifactor authentication (MFA), attackers have adapted by deploying sophisticated MFA phishing kits such as the Tycoon 2FA phishing kit, enabling them to capture and reuse session tokens to bypass authentication without triggering alerts. Recent reports indicate that 67% of organizations suffered account takeovers, with 59% of those involving accounts protected by MFA, highlighting persistent vulnerabilities in authentication mechanisms and fueling a real-time, identity-driven arms race that demands urgent enhancements in threat detection and zero trust security models.
The Team PCP breach spree starkly illustrates the critical risks posed by identity and credential theft, where a single missed privileged access token enabled attackers to infiltrate cloud environments affecting high-profile targets like the European Commission. Researchers emphasize that Team PCP prioritizes rapid exploitation over stealth, reflecting a broader trend where attackers leverage stolen credentials and tokens at speed to overwhelm defenses. This breach underscores the urgent need for comprehensive credential lifecycle management, AI-governed security, and zero trust architectures to defend the new security perimeter defined by identity.
AI Deepfakes Break Trust
AI-powered deepfakes have made traditional ID checks obsolete, unleashing a wave of undetectable scams that double financial losses and erode confidence in digital interactions.
By early 2026, AI-driven deepfakes have evolved into a formidable tool for social engineering scams, capable of deceiving even vigilant users into authorizing fraudulent transactions or investing in fictitious projects. IBM data reveals that AI-enabled attacks now constitute 16% of all breaches, with phishing and deepfakes leading the charge. The challenge of spotting these scams is compounded by the sophistication of AI-generated content, which often lacks obvious glitches and uses urgent financial requests to manipulate victims, rendering traditional identity verification methods increasingly ineffective.
The automation and scale enabled by AI have revolutionized social engineering, allowing attackers to deploy millions of scam interactions simultaneously without human oversight. As one expert put it, "I can have a million agents working at my behest all night long," doubling the financial impact of scams from $10 billion to $20 billion within a year. This surge is fueled by AI’s ability to generate flawless English and multimodal content, erasing the telltale signs that once helped users detect phishing and deepfake attempts, thus demanding a radical rethink of cybersecurity defenses.
Cybersecurity leaders like Trusona emphasize that the era of document-based identity verification is over, as AI deepfakes render such methods obsolete. Instead, the focus must shift to verifying the true identity behind interactions, integrating real-world data and advanced fraud detection to counteract AI-enabled impersonation and VPN spoofing. Trusona’s customer-centric, demo-first approach aims to build trust through live trials, addressing skepticism and demonstrating that combating AI-driven fraud requires solutions beyond conventional ID checks and password hygiene.
The traditional trust infrastructure, designed for a time when impersonation was costly and slow, is collapsing under the weight of cheap, rapid, and credible AI-generated deepfakes. IBM estimates the cost to create a deepfake at just $1.33, with global fraud losses expected to reach $1 billion in 2024 alone. These scams exploit normal human work habits and trusted communication channels—such as urgent phone calls and voice biometrics—making social engineering attacks more effective and harder to detect, while also threatening broader organizational credibility across insurance, media, social platforms, and political campaigns.
Legit Tools Turn Rogue
Attackers weaponize trusted VPNs and RMM software, blending rogue access with authorized tools to slip past defenses and exploit overlooked credentials in sprawling cloud environments.
By early 2026, attackers have increasingly weaponized legitimate access tools such as SSL VPNs and Remote Monitoring and Management (RMM) software to infiltrate and persist within networks, with SSL VPN abuse accounting for 32.8% and RMM abuse for 30.3% of incidents. Environments deploying multiple remote access tools face heightened risks as rogue instances blend seamlessly with authorized software, complicating detection and enabling adversaries to operate under the radar.
Threat actors exploit valid but compromised credentials to establish VPN sessions that appear legitimate to security controls, facilitating rapid lateral movement toward high-value systems without triggering immediate alerts. This tactic extends to cloud environments where adversaries capture authenticated session tokens post-MFA via Man-in-the-Middle phishing—accounting for roughly 16% of cloud account disables—allowing them to bypass multi-factor protections and maintain stealthy access.
The Team PCP breach spree underscores the peril of overlooked credentials and privileged access tokens within complex CI/CD and cloud ecosystems; a single stolen GitHub Actions token enabled attackers to compromise multiple high-profile targets, including a European Commission cloud. Despite diligent credential rotation efforts, missed instances allowed persistent access, illustrating how the sheer volume and complexity of credentials challenge comprehensive protection and rapid response.
Supply chain compromises amplify these risks by propagating trust breaches from open source packages through enterprise applications to AI platforms, as seen in the Axios npm compromise impacting OpenAI. Attackers increasingly favor exploiting trusted workflows and third-party access over direct infrastructure hacks, exemplified by breaches at Booking.com, where internal system compromises enabled quiet, undetected data exfiltration. This shift reinforces the imperative that 'identity is the new perimeter,' demanding zero trust and AI-augmented identity verification to defend against these evolving vectors.
Zero Trust Goes Autonomous
Zero trust security now targets both humans and AI agents, demanding real-time identity verification and rapid credential revocation to outpace sophisticated token theft and deepfake impersonation.
The escalating sophistication of AI-driven identity exploits has propelled zero trust architectures and AI-augmented identity verification from optional best practices to essential defenses in 2026. As attackers increasingly target identity over malware—capturing an average of 87 credentials per infected device and exploiting perpetual tokens without device binding—organizations must adopt continuous, context-aware authentication and enforce least privilege access to contain breaches and prevent lateral movement. Trusona exemplifies this shift by pioneering AI-proof verification systems that leverage real-world data to detect identity impersonation beyond traditional document checks, addressing the new frontier where generative AI deepfakes render old ID verification obsolete.
Zero trust strategies in 2026 extend beyond human users to encompass autonomous AI agents, necessitating ephemeral, task-specific credentials and real-time anomaly detection to secure agentic environments. John Bruggeman of Absolute Security emphasizes that managing agent identity controls and infrastructure security within zero trust frameworks is critical to mitigating emerging risks from autonomous AI, while continuous monitoring and behavioral baselining remain vital to swiftly detect deviations indicative of compromise. This evolution underscores the complexity of modern identity governance, demanding cohesive, orchestrated security approaches rather than fragmented tool deployments.
Rapid incident response and credential management have become linchpins in minimizing damage from identity and token theft, especially as token stealing bypasses traditional password and MFA protections. Experts highlight that the first minutes following a compromise are critical, requiring immediate revocation of permissions and credential resets to curtail attacker persistence. Operational security must evolve continuously, incorporating regular permission reviews and adaptive transaction alerts to counter new phishing tactics and regulatory shifts, thereby reinforcing resilience against the dynamic threat landscape revealed in reports from Blackpoint Cyber and the Team PCP breach spree.
Trusona’s customer-centric, demo-first approach to AI-augmented identity verification not only outsmarts AI-driven deepfake fraud but also accelerates enterprise adoption by demonstrating real-world efficacy rather than theoretical promise. CEO Ori Eisen stresses the urgency for U.S. companies to adopt advanced identity defenses immediately, warning that ransom payments fuel further cybercrime. By enabling global partners with cutting-edge AI verification tools that integrate zero trust principles, Trusona reshapes cybersecurity and fraud prevention in the AI-infused cyber warfare landscape of 2026, setting a new standard for identity security.








