AI is making credential theft faster and easier to scale, according to analysis citing recent incidents and security reports.
On September 8, Google Threat Intelligence Group (GTIG) described a campaign in which an attacker compromised cloud infrastructure and deployed a multi-agent framework. The operation took less than six hours and compromised thousands of third-party credentials. AI handled parts of vulnerability scanning, troubleshooting and IP rotation with minimal human intervention.
Microsoft reported in April that the AI-assisted phishing campaigns it observed reached click-through rates as high as 54%, compared with around 12% for traditional campaigns. Verizon’s Data Breach Investigation Report found that stolen credentials were involved in 44.7% of breaches.
The source argues that AI does not need a new method of credential theft to increase risk. It can make established techniques more efficient by generating targeted messages in different languages and industries.
Identity weaknesses played a material role in 89% of investigations covered by Unit 42’s 2026 Global Incident Response Report. The analysis says valid passwords, MFA responses and sessions can satisfy authentication without proving that the requesting device is trusted.
It points to device-bound identity controls, including Specops Device Trust, as a way to require trust in both the user and the device. The source also mentions Specops Password Auditor, which performs a read-only scan of Active Directory.
Comments
0No comments yet. Be the first to comment.