AI turns identity into cybercrime’s golden key: 90% of breaches now exploit trust, not malware

Intruvent Edge

The gist

AI-fueled identity attacks have shattered the old security playbook, with 90% of breaches now exploiting trust and credentials—leaving malware in the dust.

What to know

AI Supercharges Social Engineering

Attackers now deploy hyper-personalized, multi-channel phishing powered by deepfake voices and AI-crafted lures, making traditional detection tools and user intuition nearly obsolete.

By 2025, AI technologies had revolutionized identity-based social engineering attacks, dramatically increasing both their volume and sophistication. KnowBe4's 2025 Phishing Threat Trends Report highlighted a staggering 449% surge in AI-powered vishing attacks and a 67% rise in abuse of legitimate platforms, with attackers impersonating trusted brands like M&S and Harrods to bypass traditional defenses. These AI-driven campaigns leveraged seasonal timing and hyper-personalization, using company names and internal topics to drive 90% of user interactions, while sophisticated tactics such as branded landing pages and domain spoofing further enhanced their credibility.

AI has industrialized social engineering by enabling attackers to rapidly generate thousands of contextually aware, grammatically flawless phishing lures that mimic individual communication styles and internal company language. This evolution extends beyond email to multi-modal attacks including deepfake voice snippets for vishing, AI-generated executive videos, and interactive 'ChatOps Phishing' where AI-powered bots guide victims through MFA approvals or malicious app installations. Such attacks exploit multiple trusted channels like Slack, Teams, and calendar invites, rendering traditional phishing indicators obsolete and undermining human intuition and existing security measures.

By early 2026, attackers had further refined identity exploitation techniques, notably through OAuth consent phishing where malicious applications impersonate legitimate enterprise services like Adobe and DocuSign to bypass defenses. Despite the sophistication, successful account takeovers remained relatively low due to increased user vigilance and the quality of social engineering. However, the rise of MFA phishing demonstrated attackers’ adaptive strategies to circumvent widespread MFA adoption, signaling a clear shift from malware-based attacks to direct identity compromise.

AI voice cloning has supercharged traditional vishing attacks by removing instinctive red flags, as attackers pair spoofed emails with convincing voice calls that impersonate executives, such as CFOs. This 'lo-fi meeting high-tech' approach exploits humans’ inherent trust in voice communication, making these attacks harder to detect and necessitating policy-driven verification processes that empower employees to independently question and verify requests—even from senior leaders. As noted in 2026 analyses, defending against these AI-enhanced identity attacks requires moving beyond technical filtering to organizational culture shifts that support rigorous identity verification.

Sources
PR Newswire - Consumer TechnologyPR Newswire - Business TechnologyToxSec - AI and CybersecurityN2K NetworksSecurity IntelligenceIBM Technology

Identity Becomes the New Firewall

Cybercriminals exploit trust embedded in SSO, OAuth, and consent workflows to infiltrate organizations, turning a single compromised identity into unrestricted network access.

By early 2026, identity and trust have unequivocally emerged as the new security perimeter, supplanting traditional network boundaries. Attackers increasingly exploit consent moments—such as OAuth permissions, help desk resets, and API approvals—to bypass conventional defenses, as highlighted by the 'consent fix attack' that tricks users into manually surrendering OAuth tokens (Insights [1], [2], [3], [5]). This paradigm shift is underscored by high-profile incidents where adversaries leverage legitimate credentials and session tokens to infiltrate critical infrastructure and high-value targets, including China’s breach of UK Prime Ministers’ phones and Russia’s Sandworm attacks on Polish energy facilities (Insights [4], [6]).

The exploitation of Single Sign-On (SSO) platforms and session tokens exemplifies how attackers capitalize on trust embedded within identity systems to gain persistent, undetected access. The ShinyHunters’ targeted voice phishing campaign against Okta’s SSO service, employing nearly 150 custom domains to mimic legitimate help desks and MFA portals, demonstrates how compromising a single identity gateway can grant 'keys to the kingdom' for lateral movement and privilege escalation (Insights [8], [9], [10], [11]). Moreover, session hijacking through Adversary-in-the-Middle (AiTM) attacks captures real-time credentials and MFA codes, rendering password resets and MFA ineffective unless active sessions are revoked promptly (Insights [31], [32], [33]).

Attackers’ strategic shift from malware to identity exploitation reflects the increasing difficulty of traditional attack vectors and the lucrative potential of identity theft. As Microsoft and other vendors tightened malware defenses, adversaries pivoted to harvesting credentials, session tokens, and keys stored on compromised devices, with an average infected device containing 87 stolen credentials ranging from VPN keys to cloud admin tools (Insights [71], [72], [73], [74]). This shift aligns with ransomware’s evolution toward data theft and extortion models, where identity-based access is more valuable than system disruption, a trend confirmed by Sophos reporting that 67% of 2026 security incidents stem from identity-related attacks (Insights [75], [25], [77], [78]).

The weaponization of trust extends beyond technical exploits to sophisticated social engineering amplified by AI, blurring the line between insider and outsider threats. AI-enhanced voice cloning enables attackers to convincingly impersonate executives like CFOs, bypassing instinctive human skepticism and traditional defenses, necessitating policy-driven verification over mere technological filtering (Insights [35], [36], [37]). Additionally, attackers exploit shared mailboxes and internal help desks, as seen in healthcare payroll heists where social engineering combined with compromised credentials allowed attackers to reset MFA and passwords undetected within trusted environments (Insights [38], [39], [40], [41], [42], [43], [44]). This convergence of identity compromise and insider mimicry underscores that security must now focus on continuous identity verification and trust expiration to defend the new perimeter effectively (Insights [15], [16], [18]).

Sources
SANS Internet Storm CenterCISO Talk by James AzarN2K NetworksIntruvent EdgeHacking HumansGlobeNewswire - Industry News on Technology

Industrial-Scale Trust Exploitation

AI-empowered threat groups automate persona-building and cross-platform impersonation, bypassing technical defenses by mimicking insiders and manipulating users in real-time.

By late 2025, identity-centric cyberattacks had evolved into highly sophisticated, multi-vector campaigns exemplified by groups like Scattered Spider and ShinyHunters. Scattered Spider’s breaches of major retailers such as M&S and Harrods not only caused hundreds of millions in damages but also fueled extensive phishing campaigns leveraging the victims’ trusted brands, illustrating the industrialization of trust exploitation. Concurrently, attackers harnessed AI to automate intelligence gathering, constructing detailed 'persona graphs' from public data to mimic internal communication styles and deploy AI-forged content across multiple trusted platforms including Slack, Teams, and calendar invites. This multi-channel approach, combined with interactive 'ChatOps Phishing' tactics that guide victims through MFA approvals and malicious app installations in real time, underscores a new era where social engineering is amplified by AI to bypass traditional defenses.

Early 2026 saw attackers refining identity-centric techniques to target enterprise OAuth flows and single sign-on (SSO) systems, as demonstrated by the ConsentFix and ShinyHunters campaigns. ConsentFix manipulated victims into granting OAuth permissions and copying credential-bearing URLs, effectively circumventing protections against redirect URI manipulation by involving users directly in credential capture. Meanwhile, ShinyHunters registered approximately 150 custom domains to impersonate Okta MFA portals, enabling persistent network access through stolen SSO credentials and attacker-registered MFA devices. These attacks highlight the critical vulnerability of SSO as a single point of failure, where compromising one identity can grant broad access across corporate environments.

Case studies from early 2026 reveal how attackers exploit internal trust and shared mailboxes to execute complex social engineering payroll heists without deploying malware. Attackers leveraged compromised shared mailbox credentials to impersonate insiders, using phone calls to help desks to reset passwords and MFA, thereby gaining legitimate access that evaded detection by security tools which perceived the activity as normal internal behavior. This approach underscores a paradigm shift where identity itself becomes the new security perimeter, rendering traditional perimeter defenses ineffective against threats that mimic insider access and privileges.

By mid-2026, identity exploitation had firmly surpassed traditional malware as the primary attack vector, with identity-related root causes accounting for over 90% of breaches investigated. Attackers increasingly favored stealing credentials, session tokens, and leveraging AI to accelerate intrusions, achieving data exfiltration in as little as an hour. Vulnerabilities in common authentication methods such as SMS-based MFA and push notifications were routinely exploited through SIM swapping and social engineering. Furthermore, attackers capitalized on the interconnectedness of identity fabrics like Active Directory and Azure Connect to move laterally across environments, amplifying breach impacts. As Red Canary reported an 850% year-over-year increase in identity threat detections, it became clear that identity is now the new security perimeter, with attackers preferring to 'just log in as that person' rather than exploit traditional vulnerabilities.

Sources
PR Newswire - Consumer TechnologyToxSec - AI and CybersecurityN2K NetworksSANS Internet Storm CenterN2K NetworksN2K Networks

Layered Defenses for Identity Wars

Static security is dead—organizations must unite dynamic identity governance, behavioral analytics, and zero trust policies to thwart AI-driven identity attacks.

By late 2025, cybersecurity experts underscored the necessity of a layered defense framework that integrates people, processes, and technology to combat AI-driven phishing and identity-centric attacks. This approach combines Just-in-Time Micro-Drills and clear policies to fortify the human firewall, out-of-band verification for sensitive transactions, and advanced technological controls such as phish-resistant MFA (notably FIDO2 and passkeys), hardened mail gateways, OAuth lockdowns, and behavioral anomaly detection focusing on impossible travel and unusual access patterns. As articulated in multiple sources, including the November 2025 How-To guides, static signature-based defenses have become obsolete against AI’s infinite variations, demanding dynamic, process-focused security postures that emphasize continuous identity governance and real-time anomaly detection.

By November 2025, the rise of sophisticated identity threats like the Scattered Spider group accelerated adoption of zero trust principles, emphasizing continuous identity posture hardening through configuration audits, privilege reduction, and threat-informed risk modeling. Organizations were urged to achieve comprehensive identity visibility across human, machine, API, and vendor identities spanning cloud, SaaS, and on-premises environments, stitching these into a unified risk and access profile. Behavioral baselining and runtime anomaly detection, supported by extensive telemetry correlation and advanced detection rules (e.g., Permiso’s 1,500+ research-driven rules), became critical to detect subtle identity-based attacks, marking a shift from perimeter defenses toward integrated identity and SaaS posture assessments that also validate voice and video interactions.

Entering 2026, the cybersecurity narrative pivoted to address the limitations of MFA and session security amid rising adversary-in-the-middle (AiTM) and session hijacking attacks. While hardware security keys and passkeys remain vital due to their domain-bound cryptographic protections, attackers increasingly exploit session tokens and legacy authentication protocols like NTLM and Kerberos to bypass MFA, as highlighted by Microsoft’s warnings that password resets are ineffective against such threats. Consequently, continuous identity governance practices—including revoking active sessions, hunting for attacker-created inbox rules, and enforcing token expiration and replay protections—became indispensable. Experts like Steve emphasize that zero trust and conditional access policies, combined with segmentation and least privilege access, are no longer optional but essential to prevent lateral movement and credential abuse within modern enterprises.

The evolving threat landscape in early 2026 also revealed that layered defenses must extend beyond technology to incorporate strict policy-driven verification processes, especially as attackers blend AI voice cloning with traditional social engineering tactics like vishing. Organizations are encouraged to empower employees to question and verify identities—even when it involves challenging executives—to counteract sophisticated impersonation attacks. This human-centric governance complements technical controls such as conditional access allow lists, session token rotation, and behavioral monitoring, forming a resilient defense posture that acknowledges trust as a controlled, expiring commodity rather than a static state. As John Bugamman and others at RSAC 2026 emphasize, zero trust readiness with minimal business disruption hinges on continuous identity verification, default-deny execution policies (e.g., Threat Locker), and real-time detection and response capabilities that adapt to industrialized trust exploitation.

Sources
ToxSec - AI and CybersecuritySoftware Analyst Cyber ResearchIntruvent EdgeIntruvent EdgeThe Hacker NewsSecurity Now (Audio)

Insurers Demand Identity Maturity

Cyber insurance and regulators now scrutinize identity hygiene, privilege management, and audit practices, as legacy authentication gaps and AI agents expose new risks.

By early 2026, the cybersecurity insurance landscape had evolved to prioritize identity posture as a critical metric, with insurers and regulators emphasizing password hygiene, privileged access management, and multi-factor authentication (MFA) coverage to assess risk and set premiums. However, evidence of active risk management—such as regular audits of credential exposure—proved more valuable than mere technical controls, reflecting a shift toward maturity and intent in identity security practices. This focus arises from the fact that credential compromise remains a primary attack vector, responsible for one in three cyber-attacks, underscoring the necessity of robust identity controls to prevent widespread disruption and support sustainable underwriting.

Despite advances in identity controls, legacy authentication protocols like NTLM and Kerberos ticket abuse continue to undermine MFA protections, allowing attackers to bypass security measures through pass-the-hash and forged ticket attacks. Windows environments remain particularly vulnerable as many logons rely solely on Active Directory paths that do not trigger MFA, while direct RDP sessions and interactive logons further expose critical authentication routes. Tools such as Specops Secure Access have emerged as essential solutions to extend MFA enforcement across these vectors, including offline logins, highlighting the complex technical challenges in securing hybrid identity environments.

The rapid proliferation of AI agents and non-human identities has introduced unprecedented governance gaps and visibility challenges, with 90% of organizations admitting pressure to loosen identity controls for AI, leading to persistent standing access and fragmented management. Keeper Security’s 2026 research revealed that nearly half of AI-powered tools hold privileged access without centralized monitoring, exacerbating risks of excessive privileges and security incidents. Addressing these challenges requires unified privileged access management platforms that integrate password, secrets, and privileged access controls to secure both human and automated identities within modern enterprises.

Human factors remain the weakest link in identity security, as attackers increasingly exploit social engineering to bypass even the strongest technical defenses like end-to-end encryption on messaging apps. The lack of vetted support systems around secure communication tools places undue responsibility on individuals, creating a governance gap that attackers leverage by targeting 'zero days in the human psyche' rather than software vulnerabilities. Effective identity management must therefore incorporate clear recovery and response procedures to mitigate risks when human identities are compromised, emphasizing that cyber hygiene and user awareness are as critical as technological safeguards.

Sources
The Hacker NewsThe Hacker NewsGlobeNewswire - Industry News on TechnologyPR Newswire - Business TechnologyCybersecurity Headlines

Zero Trust: No More Excuses

Security leaders must abandon convenience for continuous verification and segmentation, as weak authentication and AI-driven impersonation fuel the majority of modern breaches.

By early 2026, security leaders are urged to fundamentally rethink identity security by enforcing phishing-resistant multi-factor authentication and resetting reused passwords, as these remain critical vulnerabilities exploited in 67% of incidents per the Sophos Active Adversary Report. The persistent reliance on weak authentication methods like SMS-based MFA and push notifications, which attackers bypass through SIM swapping and social engineering, underscores the urgent need for stronger identity controls. Kavitha Mariapan of Rubrik highlights that 90% of security leaders recognize identity-based attacks as their biggest threat, a sentiment echoed by breach investigations revealing identity weaknesses played a material role in 90% of cases, emphasizing that closing these gaps could prevent the majority of breaches.

Integrating AI-aware security controls has become indispensable as attackers exploit AI-driven impersonation and sophisticated social engineering. Platforms like Doppel demonstrate how AI-native defense can dismantle cross-channel attacks, while operational measures such as locking browser extensions to approved allowlists, rotating API keys for large language model endpoints, and treating session token leaks as immediate compromises are critical to maintaining security integrity. Real-time detection and threat hunting must evolve to monitor post-patch integrity and virtual environment anomalies, with training focused on recognizing AI-generated phishing that mimics human grammar and context, reflecting a strategic shift towards proactive, AI-informed defense.

Security leadership must embrace a paradigm shift from traditional fortress mentalities to zero trust architectures that assume authentication is inherently weak and internal users can be compromised through social engineering. This approach involves designing systems that fail safely and recover quickly, emphasizing segmentation and isolation before compromise, and continuous identity verification with controlled friction replacing convenience. John Bugamman stresses zero trust readiness as essential against agentic AI threats, while practical tools like Threat Locker enforce strict execution policies to maintain operational scalability and cleanliness, aligning security operations with business resilience and national stability.

Aligning cybersecurity efforts with broader business resilience requires translating technical risks into business language and recognizing that every security failure is fundamentally a consent failure—whether through help desk resets, Office macros, or browser extension approvals. Security leaders must extend their focus beyond technology controls to include auditing vendor and law enforcement cooperation channels and monitoring international payments for mule account indicators. As US National Cyber Director Shawn Cairncross notes, resilience is not merely absorbing attacks but proactively raising adversary costs and shaping their behavior, a strategic imperative underscored by the reputational risks business leaders increasingly acknowledge.

Sources
CISO Talk by James AzarCyberWire DailyGlobeNewswire - Industry News on TechnologyCyberWire DailyCISO Talk by James AzarCISO Talk by James Azar

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.