AI Displaces Stolen Credentials as Top Identity Concern

New report highlights a shift toward industrial-scale automation as generative and agentic AI become primary threats to enterprise security.

Generative AI and agentic AI have officially overtaken stolen credentials as the leading identity security concern for global organizations, according to a new industry report.

The State of Passwordless Identity Assurance report, released Tuesday, indicates a significant shift in the threat landscape. For the first time, 53% of organizations cited generative AI and 45% cited agentic AI as their primary worries, signaling that the era of human-scale credential theft is being replaced by industrial-scale automated attacks.

This evolution has forced a strategic pivot toward identity verification. While technical literacy regarding modern authentication methods has reached record highs, enterprise-wide adoption continues to lag behind the velocity of AI-driven threats.

The Rise of Synthetic Media

The report found that 87% of organizations have encountered audio or video deepfakes during identity-based attacks. These synthetic media threats are no longer theoretical, with 45% of respondents identifying prerecorded video deepfakes as a top concern and 40% reporting incidents of AI voice cloning targeting call centers.

Identity impersonation incidents have increased by 35% over the past year. Candidate fraud, where attackers use AI to spoof identities during the hiring process, emerged as the second most prevalent threat behind credential misuse.

"In 2026, automated agents will leak more passwords than people," said Bojan Simic, CEO and co-founder of HYPR. "We must move past point-in-time security and make identity verification a permanent part of how we manage every employee, from onboarding to offboarding."

The Velocity Paradox

The speed of modern attacks is creating a "velocity paradox." While defensive tools currently detect 65% of identity-based attacks within hours, AI automation often allows for data exfiltration before security teams can intervene.

The report also highlighted a "hindsight tax" in cybersecurity budgeting. Approximately 59% of organizations only increase their security spend after a breach occurs. Following a compromise, 61% of those companies prioritize the immediate deployment of identity verification and 57% focus on multi-factor authentication.

Bridging the Implementation Gap

Despite the rising threats, a gap remains between awareness and action. Literacy regarding FIDO passkeys has reached 64%, and 64% of leaders now consider them the gold standard for authentication. However, enterprise-wide adoption remains stalled at 43%.

Current data suggests a market shift is imminent. Three-quarters of surveyed organizations plan to invest in passwordless tools this year, and 33% have successfully scaled passwordless protection to more than half of their workforce.

While 76% of organizations still rely on legacy passwords, the report indicates that one-third of enterprises have active passwordless pilots underway—the highest level of any authentication method currently tracked.

About the Author

Jesse Jacobs is assistant editor of SecurityToday.com.

Featured

New Products

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.