AI-powered attacks expose gaps in identity security

The gist
AI-powered attacks are outpacing defenses, driving up breach costs and exposing serious gaps in how organizations protect digital identities.
What to know
- AI-driven cyberattacks surged 56% by mid-2026, with one in four breaches now powered by automated AI tactics—and average costs hitting $6 million globally.
- Financial services face mounting risks as 58% cite public cloud as their top breach worry and 92% of firms hit by AI-related breaches lacked even basic AI access controls.
- Autonomous AI agents now outnumber humans 50:1, making identity governance a nightmare and fueling a spike in AI-enabled phishing and transfer fraud losses from 17.7% to over 85%.
AI Arms Race Escalates
Attackers now wield autonomous AI agents and deepfake-powered phishing at machine speed, overwhelming traditional defenses and exposing critical gaps in identity governance.
By mid-2026, AI-driven cyberattacks surged by 56%, dramatically accelerating traditional attack methods and pushing average breach costs to $6 million globally, with critical infrastructure and financial sectors hardest hit. IBM’s analysis revealed that one in four data breaches now involves AI, which enables threat actors to automate reconnaissance, generate persuasive phishing content, and rapidly test exploits at machine speed, significantly lowering the complexity and cost of sophisticated attacks. As Limor Kessem of IBM’s X-Force Cyber Crisis Management explains, this shift compels defenders to move from human-speed to machine-speed responses to keep pace with attackers.
AI-enhanced social engineering has emerged as a dominant tactic, accounting for 45% of AI-driven incidents, with deepfakes, voice, and SMS phishing contributing heavily to the rise in financial losses from these attacks. Resilience’s data shows that phishing, social engineering, and transfer fraud now comprise over 85% of incurred cyber losses, a steep increase from 17.7% in 2024, underscoring how AI amplifies human error exploitation rather than introducing entirely new attack vectors. Consequently, experts like Judson Dressler emphasize that rapid detection and containment are critical, as human judgment alone cannot keep pace with AI-generated threats.
The proliferation of autonomous AI agents introduces a staggering increase in non-human identities—estimated at a 50:1 ratio to human identities—complicating identity governance and privilege management. These ephemeral AI-driven entities can interact with enterprise systems, execute actions autonomously, and be exploited through prompt injection or compromised plugins, as noted by Kaspersky’s Sergey Lozhkin. This expanding attack surface demands automated, machine-speed controls to manage AI agent permissions effectively, especially given that 92% of organizations suffering AI-related breaches lacked basic AI access controls, highlighting a critical governance gap.
AI is not only accelerating the speed of attacks—evidenced by Horizon3’s autonomous AI compromising a real-world bank in just 77 seconds—but also enhancing the potency of ransomware and cryptographic attacks. While ransomware remains the costliest cyber threat, accounting for 73% of incurred losses despite low frequency, AI’s ability to break advanced cryptographic algorithms, such as Anthropic’s Claude Mythos cracking the HAWK post-quantum algorithm in 60 hours, signals a new frontier in cyber risk. This evolution underscores the urgent need for organizations to adopt layered defenses, immutable backups, and AI-aware security strategies to mitigate rapidly evolving AI-powered threats.
Visibility Crisis in Finance
Financial institutions are flying blind as fragmented AI ecosystems and outdated regulations obscure the true scale of AI-driven vulnerabilities and concentration risks.
The rapid integration of AI in financial services has introduced unprecedented systemic risks by accelerating the speed, scale, and interconnectedness of cyber and operational threats, yet no single firm or regulator currently possesses sufficient visibility to identify all ecosystem vulnerabilities or concentration risks. This lack of comprehensive insight undermines firm-level resilience controls and complicates coordinated responses, as highlighted in the 2026 analysis on AI’s impact in financial services which warns that increasing concentration risks weaken traditional defenses.
Existing governance and regulatory frameworks, such as the Consumer Duty and Senior Managers Regime, remain foundational but require urgent adaptation to keep pace with the fast-evolving AI landscape. Despite their flexibility, accountability continues to rest with regulated firms and senior management, who must grapple with the growing complexity of AI risks amid frameworks that often assume controlled environments—an assumption challenged by 80% of Asia Pacific IT leaders who find current AI security advice too theoretical to be practical.
Enterprises face a critical visibility gap into AI agents operating across fragmented environments, with Rubrik Zero Labs reporting that 80% of organizations in APAC lack full awareness of these autonomous entities. This obscurity hinders not only detection but also traceability, which is essential for understanding AI-driven actions and responding proactively to incidents. As Jon Oltsik emphasizes, "Visibility must come before any control layer can work," underscoring that governance efforts are futile without first knowing what agents exist and what systems they interact with.
The operational challenges of AI security extend beyond visibility to the need for continuous verification and dynamic governance, as autonomous AI systems like Mythos can identify and exploit unknown vulnerabilities faster than traditional defenses can respond. Attackers increasingly target trusted control planes—firewall managers, virtualization platforms, and AI infrastructure—to leverage access across thousands of systems, making static entitlements obsolete. Security experts like Krista Case and Jon Oltsik argue for deterministic architectural controls, strict network segmentation, and ongoing validation of AI behavior, while also emphasizing the indispensable role of human oversight to manage rogue AI actions and maintain operational resilience.
Systemic Threats Multiply
Shared AI models and unchecked 'Shadow AI' are amplifying operational risks, threatening to trigger synchronized failures and market volatility across the financial sector.
AI's rapid integration into financial services is amplifying systemic risks by accelerating the exploitation of existing vulnerabilities and creating correlated behaviors across institutions. As TMR highlights, AI doesn't just introduce new risks but makes existing flaws more dangerous and harder to contain, while synchronized decision-making driven by similar AI models in credit underwriting and investment recommendations could exacerbate market volatility and coordinated service withdrawals.
Financial institutions face significant operational resilience challenges due to their shared reliance on a limited number of AI model providers, which concentrates risk and raises the possibility of simultaneous outages or breaches across multiple firms. This concentration risk, coupled with the rise of autonomous AI agents and 'Shadow AI' operating without proper governance or IAM integration, creates visibility gaps and unchecked access that heighten vulnerability, as underscored by Forrester's designation of AI agent threats as the top CISO concern for 2026.
In response to escalating AI-driven cyber threats—including sophisticated attacks like automated vulnerability discovery and deepfake-enabled phishing—financial services are prioritizing the identification and protection of their most critical digital assets. Industry leaders emphasize that 'not everything is the Mona Lisa,' underscoring the need to focus security efforts on strategic assets within complex hybrid cloud environments, where 58% of firms view public clouds as their greatest breach risk, while 62% trust data lakes more for safeguarding critical data.
Regulatory frameworks such as the Consumer Duty and Senior Managers Regime remain foundational but must evolve to address the fast-moving AI landscape, placing accountability squarely on financial firms and senior management. Philip D. Harris stresses that deep observability and comprehensive visibility into encrypted traffic are now essential not only for security but also for governance and operational resilience, especially as 94% of financial leaders recognize these capabilities as critical to securing AI deployments and preparing for emerging threats like 'harvest now, decrypt later' attacks.
Identity Becomes the Battleground
Security teams are embedding identity intelligence into SOCs and automating threat containment, marking a decisive shift toward machine-speed defense against invisible AI-powered attacks.
By early 2026, enterprise security spending is increasingly focused on integrating identity intelligence directly into Security Operations Centers (SOCs) through advanced Identity Threat Detection and Response (ITDR) solutions like Cortex ITDR 2.0. This integration enables unified visibility and continuous posture management of identity infrastructures such as Active Directory, consolidating endpoint, network, cloud, and SaaS contexts into a single operational view that proactively uncovers misconfigurations and hidden attack paths. As one analysis notes, 'Identity has officially become the primary attack surface,' underscoring the critical need for identity context to live inside the SOC for effective defense against AI-driven, invisible identity-based attacks.
The shift toward automated, dynamic response mechanisms is transforming how enterprises contain identity-based threats, with technologies like Dynamic Conditional Access Policies (CAP) and step-up multi-factor authentication (MFA) triggered by real-time behavioral risk scores. These closed-loop workflows, exemplified by integrations such as Idira with Cortex, enable surgical, automated containment that neutralizes threats instantly without disrupting business operations. This evolution reflects a broader trend of consolidating cybersecurity tools to improve operational resilience against AI-accelerated threats by correlating identity telemetry with endpoint and network data.
In response to AI's growing complexity and risk, enterprises are consolidating their cybersecurity estates around a smaller number of strategic pillars—namely AI governance, identity, insider threat management, and secure gateways—to reduce operational complexity. According to Proofpoint's Bikramdeep Singh, organizations now prioritize visibility into all AI applications, including shadow IT, to ensure authorized data access and maintain forensic records. This strategic realignment also involves shifting from traditional rule-based detection to behavioral analysis, focusing on anomalous user activities to enhance operational visibility in AI-enabled environments.
Insider threat management has emerged as a critical investment area as enterprises deploy increasing numbers of AI agents capable of accessing sensitive corporate information across multiple systems, raising novel security challenges. Managed Security Service Providers (MSSPs) are adapting by adopting more consultative, engagement-driven roles, helping clients balance AI adoption with security and governance needs while minimizing operational disruption. Singh emphasizes that MSSPs must evaluate insider risks, assess data exposure, and recommend governance controls aligned with business objectives to navigate this evolving landscape effectively.




