AI Displaces Stolen Credentials as Top Identity Concern

New report highlights a shift toward industrial-scale automation as generative and agentic AI become primary threats to enterprise security.

Generative AI and agentic AI have officially overtaken stolen credentials as the leading identity security concern for global organizations, according to a new industry report.

The State of Passwordless Identity Assurance report, released Tuesday, indicates a significant shift in the threat landscape. For the first time, 53% of organizations cited generative AI and 45% cited agentic AI as their primary worries, signaling that the era of human-scale credential theft is being replaced by industrial-scale automated attacks.

This evolution has forced a strategic pivot toward identity verification. While technical literacy regarding modern authentication methods has reached record highs, enterprise-wide adoption continues to lag behind the velocity of AI-driven threats.

The Rise of Synthetic Media

The report found that 87% of organizations have encountered audio or video deepfakes during identity-based attacks. These synthetic media threats are no longer theoretical, with 45% of respondents identifying prerecorded video deepfakes as a top concern and 40% reporting incidents of AI voice cloning targeting call centers.

Identity impersonation incidents have increased by 35% over the past year. Candidate fraud, where attackers use AI to spoof identities during the hiring process, emerged as the second most prevalent threat behind credential misuse.

"In 2026, automated agents will leak more passwords than people," said Bojan Simic, CEO and co-founder of HYPR. "We must move past point-in-time security and make identity verification a permanent part of how we manage every employee, from onboarding to offboarding."

The Velocity Paradox

The speed of modern attacks is creating a "velocity paradox." While defensive tools currently detect 65% of identity-based attacks within hours, AI automation often allows for data exfiltration before security teams can intervene.

The report also highlighted a "hindsight tax" in cybersecurity budgeting. Approximately 59% of organizations only increase their security spend after a breach occurs. Following a compromise, 61% of those companies prioritize the immediate deployment of identity verification and 57% focus on multi-factor authentication.

Bridging the Implementation Gap

Despite the rising threats, a gap remains between awareness and action. Literacy regarding FIDO passkeys has reached 64%, and 64% of leaders now consider them the gold standard for authentication. However, enterprise-wide adoption remains stalled at 43%.

Current data suggests a market shift is imminent. Three-quarters of surveyed organizations plan to invest in passwordless tools this year, and 33% have successfully scaled passwordless protection to more than half of their workforce.

While 76% of organizations still rely on legacy passwords, the report indicates that one-third of enterprises have active passwordless pilots underway—the highest level of any authentication method currently tracked.

About the Author

Jesse Jacobs is assistant editor of SecurityToday.com.

Featured

New Products

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.