AI supercharges identity attacks, shifting cybersecurity to resilience

The gist

AI-fueled identity attacks have overtaken all other cyber threats, forcing security leaders to shift from prevention to rapid, resilient recovery as attackers and defenders battle at machine speed.

What to know

  • By early 2026, 65% of initial access incidents stemmed from identity weaknesses—like stolen credentials and MFA bypass—supercharged by AI agents expanding the attack surface.
  • AI now automates attacks and defenses alike, but human oversight remains critical as session hijacking and AI-powered social engineering outpace traditional security controls.
  • Vendors like Rubrik, CrowdStrike, Okta, and CLEAR are racing to unify identity intelligence with automated recovery and real-time biometric verification to counter relentless AI-driven threats.

Identity: The New Battleground

AI-powered session hijacking and credential theft have transformed identity into the core vulnerability of modern cyberattacks, slashing breach timelines to minutes and forcing defenders to shift from reactive to preemptive intelligence.

By early 2026, identity had solidified as the primary cyberattack vector, with Unit 42 revealing that 65% of initial access incidents were identity-driven, and nearly 90% of investigations involved identity weaknesses such as stolen credentials, MFA bypass, and IAM misconfigurations. This attack surface complexity deepened as AI agents introduced their own credentials and tokens, expanding the avenues for exploitation and reinforcing identity's central role in modern cyber threats.

The evolution from password theft to session hijacking marked a pivotal shift in attacker tactics, as highlighted by SpyCloud’s 2024 research uncovering 17 billion compromised cookies. These stolen session cookies and authentication tokens now constitute nearly half of all compromised identity assets, enabling cybercriminals to bypass traditional defenses like MFA by stealing active authenticated sessions rather than just passwords, effectively targeting the 'digital soul' of users.

This surge in identity-based attacks has dramatically accelerated intrusion timelines, with CrowdStrike reporting that the fastest 25% of breaches now achieve data exfiltration in just 72 minutes—four times faster than the previous year. Such rapid exploitation underscores the urgent need for proactive defenses, a gap SpyCloud aims to fill by leveraging its vast data lake of over one trillion recovered assets to provide real-time intelligence that helps organizations preemptively neutralize compromised credentials before attackers can strike.

Sources
Resilient CyberBriefglance

AI Arms Race Escalates

Cybersecurity has become a high-speed contest between AI-driven attacks and defenses, with human oversight remaining essential to counter model errors and sophisticated social engineering tactics.

By mid-2026, AI had firmly established itself as a force multiplier in cybersecurity, dramatically accelerating and automating attacks to a degree no human team could match, while simultaneously empowering defenders to detect malicious behavior more precisely and respond with tailored remediation strategies. This dual capability has entrenched cybersecurity in a relentless arms race, where technological advancements fuel both adversaries’ reach and defenders’ resilience, underscoring the inherently reactive nature of the industry as it continuously adapts to criminal innovation.

Despite AI’s transformative impact, human oversight remains indispensable due to current model limitations such as hallucinations and overestimations of success, which prevent full autonomy in cyber offense or defense. This ongoing need for human validation highlights that while AI reshapes attack methodologies—evident in the decline of traditional email phishing and the rise of AI-enabled voice phishing tactics that exploit social engineering to bypass MFA—security teams must blend machine speed with human judgment to maintain effective defenses.

Recognizing the dual-edged nature of AI, CrowdStrike’s 2026 launch of the AI Partner Specialisation and the 'Verified Agent' certification program exemplifies industry efforts to harness AI’s power responsibly. By vetting partner-built AI agents before marketplace distribution, CrowdStrike aims to secure the agentic era, reflecting how AI simultaneously amplifies both threat capabilities and defensive tools, thereby intensifying the continuous cybersecurity arms race and the necessity for rigorous validation frameworks.

Sources

Session Hijacking Redefines Risk

Stolen session cookies and authentication tokens now rival passwords as prime targets, allowing attackers to bypass MFA and exploit users’ digital identities in real time.

Stolen session cookies and authentication tokens now rival passwords as prime targets, allowing attackers to bypass MFA and exploit users’ digital identities in real time.

Resilience Replaces Prevention

Automated recovery and continuous readiness have overtaken traditional prevention as the industry standard, as organizations prioritize rapid restoration and operational continuity amid AI-accelerated attacks.

By mid-2026, the cybersecurity industry decisively shifted from a prevention-centric mindset to prioritizing cyber resilience, recognizing that rapid recovery and continuous operational readiness are now paramount. Companies like Rubrik exemplify this evolution, unveiling AI-driven Autonomous Business Recovery capabilities at their Forward 2026 conference, signaling a long-term strategic pivot toward automated resilience. This transition is fueled by increasingly sophisticated, orchestrated attacks that leverage legitimate tools and outpace traditional defenses, necessitating automated recovery strategies that can operate at machine speed to restore operations swiftly and accurately.

The concept of Operated Cyber Resilience has emerged as the new industry standard, moving beyond mere data backups to emphasize continuous execution, validation, and rapid recovery under pressure. Executives now demand proof that tier-1 applications can be restored within the same business day from verified clean recovery points across hybrid environments, reflecting a shift from binary backup success metrics to accountability for actual business continuity. This comprehensive approach requires maintaining discipline across the full crisis lifecycle—continuous readiness, protection, detection, investigation, and orchestration—often augmented by automation and intelligent agents to meet the demands of AI-accelerated attack speeds.

AI’s acceleration of attack speed and complexity has compressed cyberattack timelines from weeks to seconds, rendering traditional prevention, detection, and remediation models insufficient. As Jimmy McNary of Semperis and Rubrik’s Ananth Nag emphasize, resilience now means preparing for inevitable breaches by focusing on rapid recovery and continuous readiness rather than solely trying to build bigger walls. This paradigm shift includes embedding identity context directly into Security Operations Centers and leveraging dynamic conditional access policies and automated multi-factor authentication challenges to enable real-time threat containment and automated recovery, exemplified by innovations like Cortex ITDR 2.0.

Industry leaders stress that cyber recovery planning must evolve into a proactive, continuously rehearsed discipline with clearly defined roles and rapid decision-making capabilities, as AI-driven attacks now spread across networks and cloud systems in seconds. Rubrik’s integration with Microsoft Defender and Commvault’s native recovery actions in CrowdStrike’s Charlotte SOAR illustrate how strategic partnerships and automation streamline incident response workflows, reducing manual handoffs and accelerating recovery. Moreover, organizations face a growing challenge managing rogue AI agents, with 86% expecting these agents to breach security guardrails soon, underscoring the urgent need for enhanced visibility, governance, and rollback capabilities within recovery strategies.

Sources

AI Governance Faces Reality Check

The explosion of agentic AI identities has exposed critical gaps in identity recovery and governance, compelling organizations to adopt proactive, unified resilience operations and real-time observability.

By mid-2026, traditional identity management systems were buckling under the surge of agentic AI identities, with many organizations lacking robust recovery strategies and unified backup solutions. Despite 90% of IT and resilience leaders acknowledging the need for improved identity controls, only about a quarter had adopted dynamic role-based access or automated clean recovery point identification, revealing critical gaps in cyber resilience that IDC suggests could be addressed through the emerging discipline of resilience operations (ResOps), which integrates business continuity, cybersecurity, and data protection into a cohesive recovery framework.

Rubrik’s August 2026 launch of Agent Identity at Black Hat spotlighted the reactive nature of current AI governance, with controls often developed only after damaging incidents expose enforcement weaknesses. Their architecture combines proactive interception of harmful AI actions with a rewind feature to undo executed commands, acknowledging that prevention alone is insufficient. Integrating with Okta and Microsoft Entra ID, this solution replaces broad static credentials with short-lived, least-privilege tokens validated through behavioral analysis and multi-layered checkpoints, addressing the alarming statistic that 86% of IT leaders expect AI agents to outpace security guardrails within a year while only 23% have full visibility.

The evolving threat landscape, as highlighted by SpyCloud’s decade-long tracking and Australian tech leaders like David Rajkovic and Merlin Luck, underscores the urgent need to shift from reactive to proactive governance frameworks. With AI agents poised to surpass existing security measures rapidly, organizations must implement real-time observability, continuous incident response rehearsals, and unified visibility across logs and metrics to detect and mitigate subtle, fast-moving AI-driven attacks. Rajkovic warns that incident response can no longer be 'set and forget' but requires rapid decision-making and clear ownership to prevent manageable disruptions from escalating into crises.

Sources

Vendors Unite for Resilience

Strategic integrations between identity, AI, and incident response platforms are creating unified frameworks that automate recovery and embed high-assurance verification directly into security operations.

By mid-2026, leading cybersecurity vendors like Rubrik and CrowdStrike began forging strategic integrations that tightly couple identity intelligence with automated incident response to accelerate recovery from identity-based attacks. Rubrik’s Agent Identity, unveiled at Black Hat 2026, exemplifies this trend by integrating with Okta and Microsoft Entra ID to enforce least-privilege, short-lived tokens for AI agents, replacing static credentials with dynamic, behaviorally enforced access controls. This innovation not only closes critical security gaps in AI governance but also enables automated incident response workflows, marking a significant evolution toward unified identity and AI governance frameworks within enterprise cyber resilience strategies.

In August 2026, CrowdStrike expanded its ecosystem collaborations by integrating CLEAR’s biometric identity verification platform into its Falcon security suite, enabling real-time human verification that goes beyond traditional credential or device-based trust signals. This partnership, immediately accessible through Falcon Next-Gen SIEM and Charlotte Agentic SOAR workflows, empowers security teams to authenticate suspicious activity with biometric and government ID checks, thereby enhancing person-based trust and reducing identity-based attacks. Executives from both companies emphasized that this integration simplifies decision-making while embedding high-assurance identity verification directly into security operations.

Simultaneously, CrowdStrike deepened its collaborative ecosystem by integrating SailPoint’s SecOps Identity Intelligence into Falcon Next-Gen SIEM, streamlining SOC workflows by consolidating identity governance with endpoint and threat telemetry. This integration, showcased at Fal.Con 2026, reduces manual tool-switching and accelerates threat detection and response by embedding critical identity context directly within security investigations. Complementing this, Commvault’s integration with CrowdStrike’s Charlotte SOAR automates cyber recovery actions—such as restricting access and restoring assets—within unified incident response playbooks, reflecting a broader industry shift toward AI-driven, end-to-end security and recovery orchestration that enhances enterprise cyber resilience.

CrowdStrike’s launch of an AI Partner Specialization program at Fal.Con 2026 further underscores the strategic importance of ecosystem collaboration in securing the emerging agentic era. By partnering with industry leaders like Cognizant, CLEAR, Accenture, Anthropic, and CoreWeave, CrowdStrike is positioning itself as the gatekeeper for AI agent readiness, offering a Verified Agent certification and unified AI-powered security services on its Falcon platform. This expansive partner network not only strengthens person-based identity verification and operational technology security but also signals a foundational shift toward integrated, AI-driven cybersecurity architectures essential for defending the evolving enterprise attack surface.

Sources

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.