Identity crisis: AI supercharges cyberattacks as trust becomes the new perimeter

Bleeping Computer

The gist

AI-powered identity attacks have exploded, pushing organizations to treat trust—not the network edge—as their last line of defense.

What to know

  • Identity-based cyberattacks surged 850% year-over-year by early 2026, with over 65 billion identity records exposed and AI-driven identity sprawl overwhelming 89% of IT leaders.
  • Adversaries now outsmart traditional defenses by abusing legitimate authentication flows (like Microsoft device code and OAuth tokens) and running AI-fueled social engineering campaigns such as Mutant Spider.
  • Over 90% of breaches still trace back to old-school failures—weak patching, poor privilege controls, and lapses in phishing-resistant MFA—spotlighting the urgent need for zero trust strategies and real-time trust validation.

Identity Becomes the Battlefield

Cybersecurity has shifted from firewalls to relentless identity monitoring, as attackers weaponize legitimate authentication and privilege sprawl to breach even the most modern environments.

By late 2025, the cybersecurity perimeter had decisively shifted from traditional network boundaries to an identity-centric model, driven by the need to counter sophisticated threats like Scattered Spider that exploit both human and non-human identities. Organizations now prioritize comprehensive discovery and continuous monitoring of all identities across environments—including IdPs, SaaS, cloud, and on-premises systems—to build a unified risk and access posture. This approach integrates identity threat detection with SaaS posture assessments and graph analytics, enabling prioritized remediation such as privilege reduction and configuration audits to harden identity posture and minimize credential compromise and insider threats.

The rise of financially motivated cybercrime throughout 2025 and early 2026 underscored how attackers increasingly leverage social engineering and credential theft to exploit trusted human identities. Distinct threat actor profiles emerged, from loosely organized West African BEC scammers to highly structured Eastern European groups conducting industrialized long-form social engineering like 'pig butchering.' Attackers also innovated by abusing legitimate authentication flows, such as Microsoft device code authentication, to bypass phishing defenses, illustrating that identity itself had become the new perimeter—one that traditional detection models struggle to protect.

By early 2026, identity-related threats had surged to dominate cybersecurity incidents, with reports from Sophos, Red Canary, and SpyCloud revealing identity-based attacks accounted for over half of confirmed threats and increased by 850% year-over-year. The explosion of exposed identity data—now exceeding 65 billion records—and the collection of hundreds of billions of compromised credentials by firms like Qel highlight how attackers prefer to infiltrate environments by masquerading as legitimate users rather than exploiting software vulnerabilities. Legacy systems such as Active Directory, plagued by sprawl and excessive privileges, remain prime targets for lateral movement and privilege escalation, emphasizing the critical need for just-in-time privilege elevation and phishing-resistant MFA like FIDO2 to shrink the attack surface.

The rapid proliferation of identities—including AI agents and unmanaged guest accounts—has overwhelmed IT leaders, with 89% reporting struggles to manage this sprawling footprint and 96% citing disconnected security tools as major gaps. This identity sprawl, coupled with inadequate real-time detection (72% of organizations fail to detect credential misuse promptly), creates fertile ground for attackers who exploit identity chains to move laterally and escalate privileges within hybrid environments. AI-driven automation further accelerates these attacks, enabling adversaries to rapidly identify and exploit dormant guest accounts and session tokens, making continuous identity governance, behavioral monitoring, and organization-wide MFA enforcement indispensable pillars of the modern identity-first security posture.

Sources
Software Analyst Cyber ResearchCyberWire DailyCISO Talk by James AzarN2K NetworksThreat Vector by Palo Alto NetworksPR Newswire - Consumer Technology

AI Arms Both Sides

AI-driven attacks now blend seamlessly into normal user activity, outpacing traditional detection and overwhelming defenders with machine-speed identity exploits and social engineering.

By early 2026, AI had become a force multiplier for identity-based cyberattacks, enabling adversaries to execute faster, more complex campaigns that exploit legitimate authentication flows and user trust. Platforms like Doppel introduced AI-native social engineering defenses, yet attackers countered with sophisticated tactics such as device code phishing and OAuth token abuse, exemplified by the Kali365 phishing-as-a-service kit that automates MFA bypass on Microsoft 365 accounts. These AI-driven methods circumvent traditional detection by leveraging real login portals and legitimate signed software, making it increasingly difficult for security tools to distinguish malicious activity from genuine user behavior.

AI-enabled social engineering has evolved beyond mere credential theft, with attackers now manipulating insiders through urgent impersonation and voice phishing to reset multifactor authentication and register attacker devices, as seen in the Mutant Spider campaigns targeting financial services. This shift underscores identity as the new cybersecurity perimeter, where compromised shared mailboxes and internal communications become launchpads for privilege escalation, rendering perimeter defenses ineffective. The Verizon 2026 Data Breach Investigations Report confirms credential theft as a declining vector, replaced by these sophisticated MFA bypass techniques that exploit human factors amplified by AI.

The rapid expansion of AI-driven identities—including non-human agents and machine accounts—has overwhelmed IT leaders, with 89% reporting difficulty managing identity sprawl and 96% citing disconnected security tools as a major vulnerability. This sprawling identity landscape creates exploitable gaps that hinder real-time detection of credential misuse, with only 38% of organizations confident in detecting and responding to such threats within 24 hours. As Keeper Security CEO Darren Guccione warns, 'every unmanaged identity is a prime target for attackers,' highlighting the urgent need for integrated identity governance and automated response capabilities in an AI-accelerated threat environment.

AI’s ability to operate at machine speed is outpacing traditional security monitoring, exploiting broken access controls and overpermissioned accounts to escalate attacks across hybrid environments. Companies like Portnox emphasize that perimeter-based defenses are increasingly obsolete, advocating for continuous, identity-level enforcement at both user and device layers as a cornerstone of zero-trust architectures. Additionally, the rise of shadow AI tools parallels historic shadow IT challenges, introducing new identity and access risks that demand automated management to prevent attackers from leveraging legacy service accounts and unsanctioned AI identities.

Sources
CyberWire DailyCISO Talk by James AzarCyberScoopCISO Talk by James AzarFast CompanyHacking Humans

Old Habits, New Consequences

Basic security failures—unpatched systems, weak privilege controls, and outdated MFA—remain the root cause of most breaches, proving that operational discipline is the real frontline.

By early 2026, cybersecurity experts repeatedly underscored that the vast majority of breaches—over 90% according to multiple analyses—stem not from novel exploits but from fundamental lapses in operational discipline. This includes failures in patch management, privilege reduction, and enforcing phishing-resistant MFA, as highlighted by Rob Allen and echoed across industry reports. The Step Finance $40 million crypto theft exemplifies this trend, where attackers bypassed blockchain security by compromising an executive’s device, spotlighting the persistent vulnerability of executive endpoints and the critical need for multi-sig hardware wallets and strict access controls.

Operational discipline extends beyond technology to encompass user behavior and governance, with finance teams urged to verify invoices solely through authenticated vendor portals to thwart urgent phishing scams, and organizations advised to restrict risky authentication flows such as OAuth device code to prevent sophisticated MFA bypasses. The Iron Mountain breach further illustrates how even minor data leaks can fuel brand impersonation attacks, necessitating proactive email security filters. These examples reinforce that consistent enforcement of basic security hygiene—user education, access restrictions, and continuous monitoring—is indispensable in the evolving threat landscape.

Despite the proliferation of advanced threats and AI-driven attack vectors, the cybersecurity battlefield remains dominated by preventable issues like unpatched vulnerabilities, misconfigurations, and stale credentials. Companies such as Reddit and Cisco have struggled with patching at scale, while exposed management interfaces and deprecated VPN protocols continue to invite exploitation. As James Azar bluntly states, the basics—default credentials, unauthenticated endpoints, and poorly scoped OAuth tokens—are the front lines, and failure to maintain rigorous patch velocity, asset inventory, and identity governance leaves organizations vulnerable to rapid, industrialized trust exploitation.

The challenge is not a lack of budget or talent but the consistent, scalable execution and monitoring of fundamental controls, which remain the linchpin of cybersecurity resilience. Geoff Belknap and other leaders emphasize that operational discipline—manifested in real-time asset inventories, default deny policies, zero trust principles, and behavioral detection—is what separates organizations that absorb attacks from those that become cautionary tales. This disciplined, often mundane approach to cybersecurity, akin to fitness through repetition and volume, is critical as the attack surface expands faster than policy and employee behavior can adapt.

Sources
CISO Talk by James AzarCISO Talk by James AzarVenture in SecuritySecurity Weekly - A CRA ResourceCISO Talk by James AzarSMB Tech & Cybersecurity Leadership Newsletter

Trust Exploited in the Supply Chain

Attackers now target the weakest links in SaaS and vendor ecosystems, using OAuth abuse and supplier impersonation to infiltrate hundreds of organizations through trusted channels.

By early 2026, attackers had industrialized the exploitation of trust within third-party and SaaS ecosystems, leveraging OAuth token phishing campaigns like those by ShinyHunters that targeted over 100 organizations, as well as exploiting compromised executive devices and vendor communications to bypass traditional defenses. The Klue supply chain breach exemplifies this trend, where a legacy credential allowed attackers to harvest OAuth tokens and access Salesforce environments across nearly 200 organizations, including major cybersecurity vendors such as Huntress and Recorded Future. This attack highlighted how threat actors increasingly abuse legitimate cloud APIs and trusted integrations rather than deploying malware, underscoring the critical need for continuous, real-time vendor risk oversight and trust validation to detect and mitigate such sophisticated lateral movements.

The expanding attack surface through complex supply chains and SaaS integrations has forced security leaders to broaden the definition of critical infrastructure beyond traditional assets to include SaaS platforms, supplier ecosystems, cloud identity services, and hardware trust anchors. Incidents like Russia’s Sandworm attacks on Polish energy facilities and vulnerabilities in widely trusted platforms such as PTC Windchill—central repositories for intellectual property—demonstrate how attackers exploit trusted vendor software and cloud-native development environments. As noted by industry experts, every vendor relationship and software dependency now demands governance equivalent to that of core infrastructure, with continuous trust validation and rapid patching becoming indispensable to defend against reconnaissance and exploitation attempts.

Misplaced trust in third-party communications and automation workflows has evolved into a significant operational risk, especially for industrial manufacturers where supplier impersonation fraud exploits automated invoice approvals and fragmented legacy systems. This form of fraud not only threatens cybersecurity but also disrupts supply chains and financial operations by redirecting payments or injecting fraudulent invoices, often bypassing traditional perimeter defenses. Experts emphasize that continuous trust validation, enhanced email authentication protocols like SPF, DKIM, and DMARC, and real-time monitoring of vendor communications are essential to mitigate these stealthy, trust-based attacks that blend seamlessly into normal operational traffic.

SaaS ecosystems face a profound identity and trust crisis, with unmanaged guest accounts constituting 69% of SaaS identities and persistent OAuth token sprawl granting attackers near-permanent access even after password resets. This vulnerability is exacerbated by low multi-factor authentication adoption—only 27% of SMBs enforce organization-wide MFA—leaving a vast attack surface open to credential theft and data exfiltration. As Kaseya’s Jim Lippie asserts, the most resilient organizations will be those embracing continuous monitoring, identity governance, and automated response, moving beyond static event tracking to behavioral detection that can flag anomalous activity within trusted accounts before breaches occur.

Sources
CISO Talk by James AzarCISO Talk by James AzarCISO Talk by James AzarRECISO Talk by James AzarPYMNTS

Zero Trust Goes All-In

Zero trust has evolved into a must-have, demanding continuous identity validation and dynamic privilege controls to stop attackers who blend in with legitimate users.

By early 2026, zero trust frameworks evolved from a recommended best practice to an indispensable security foundation, as attackers increasingly exploited legitimate user credentials to move laterally within networks undetected. Analysts emphasized that mere adoption of zero trust principles is insufficient unless implemented as a cohesive identity strategy that enforces least privilege, continuous authentication, and granular segmentation. This approach limits exposure by granting just-in-time, time-bound privileges and continuously verifying identity context, thereby disrupting attackers’ ability to pivot and escalate privileges unnoticed.

Conditional access policies emerged as critical enablers within zero trust architectures, defining strict allow lists based on user attributes, device health, location, and behavior to flag suspicious deviations. Solutions like Specops Device Trust and platforms integrating context-aware MFA and just-in-time privilege escalation automate continuous verification, instantly revoking access upon anomaly detection. This dynamic enforcement is vital against sophisticated threats such as MFA reset attacks and OAuth token theft, as highlighted by the FBI’s warnings on tools like Kali365 that bypass traditional multifactor protections.

The proliferation of identity sprawl, especially with AI-driven non-human identities and unmanaged guest accounts, has intensified the need for unified identity governance platforms that consolidate IGA, PAM, access management, and Active Directory controls. Keeper Security’s 2026 report revealed that 89% of IT leaders are overwhelmed by disconnected tools and sprawling identities, with 69% of SaaS accounts being unmanaged guests. Vendors like the one interviewed in June 2026 underscore that such integrated platforms reduce operational complexity and security blind spots, enabling continuous monitoring and automated privilege adjustments essential for regulated sectors and AI-intensive environments.

Industry experts caution that zero trust is not a silver bullet but a strategic posture that makes attacks more difficult and noisy, increasing detection likelihood and raising the bar for adversaries. The goal is to be harder to breach than competitors by enforcing least privilege, continuous identity-level enforcement at both user and device layers, and transitioning from static perimeter defenses to active, identity-first governance with automated behavioral monitoring. This holistic approach, championed by firms like Portnox and Kaseya, is crucial to counter AI-enhanced phishing, OAuth token misuse, and the growing complexity of identity-driven attack vectors.

Sources
N2K NetworksBleeping ComputerCyberWire DailyVenture BeatFast CompanyMB

SMBs and Sectors Under Siege

AI-powered threats now target SMBs, manufacturers, and universities at scale, exploiting resource gaps and fragmented vendor oversight to breach digital trust across industries.

By early 2026, SMBs found themselves squarely in the crosshairs of AI-driven cyber threats, facing over 5 million automated vulnerability scans weekly that eroded any advantage from 'security through obscurity.' As highlighted by the Sage-commissioned IDC survey, 80% of SMBs were unprepared for this new era of algorithmic precision attacks, which target small firms with the same rigor as Fortune 500 companies. Resource constraints and outdated cybersecurity infrastructures further compounded these vulnerabilities, leaving many SMBs reliant on legacy systems ill-equipped to defend against fast-evolving, AI-enabled threats, as VikingCloud research and Check Point’s disclosure of a critical VPN zero-day exploit underscore.

Manufacturing industries face a uniquely complex identity threat landscape driven by their sprawling supplier ecosystems and digitized operational workflows. Doppel’s 2026 analysis reveals that credential leaks dominate as the primary attack vector, enabling adversaries to infiltrate supplier portals, VPNs, and cloud systems, while sophisticated social engineering tactics like vishing and executive impersonation exploit trusted third-party relationships. The integration of robotics, ERP platforms, and automated procurement processes reduces human oversight, amplifying risks of AI-enabled supplier impersonation fraud that can disrupt production and financial operations. Effective defense demands continuous visibility into email authentication protocols such as SPF, DKIM, and DMARC across fragmented infrastructures to maintain digital trust and operational continuity.

Higher education institutions, much like SMBs, grapple with managing AI-driven identity risks amid deep reliance on third-party SaaS platforms critical to academic functions. As Palo Alto Networks’ Fadi Fadhil notes, many universities have secured their 'front door' while leaving the 'loading dock'—their vendor ecosystems—vulnerable, a gap starkly illustrated by the Canvas breach’s disruption of instruction and trust. Resource limitations and immature vendor risk management processes hinder comprehensive oversight, making scalable, AI-aware strategies that include continuous threat exposure management and up-to-date asset registries essential. Okta’s Jeremy Kirk emphasizes that understanding who has access to applications and API keys is now a foundational requirement in this AI age.

Across SMBs and sectors like manufacturing and education, the explosion of non-human identities—ranging from APIs to service accounts—has expanded attack surfaces exponentially, demanding unified identity security platforms that integrate governance, visibility, and control without adding operational burden. One Identity’s approach, combining IGA, PAM, access management, and Active Directory management, addresses these complexities, particularly in regulated industries. The rise of AI-driven impersonation and social engineering attacks has elevated identity to the modern security perimeter, with cyber insurers now mandating robust identity frameworks to mitigate financial risks. Additionally, third-party and supply chain risks remain acute, prompting specialized licensing models to monitor external contractor access and prevent attackers from bypassing primary defenses through administrative credential exploitation.

Sources

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.