AI doesn’t change singular importance of phishing-resistant authentication, Okta says
An article from Dive Brief The company presented new data about the prevalence of different forms of social-engineering attacks, saying...
An article from Dive Brief The company presented new data about the prevalence of different forms of social-engineering attacks, saying identity fundamentals still matter in the AI era. Published Oct. 7, 2026 Getty Images Dive Brief: Hackers may be using AI more frequently and in more ways, but their top priority is still subverting identity controls, the identity-security firm Okta said in a report published on Wednesday.
The report included data about the frequency of different kinds of account takeovers and a reality check to enterprises that AI shouldn’t fundamentally change their calculus when it comes to identity management. In a separate report also published on Wednesday, Okta detailed how hackers are trying to bypass strong authentication controls to sneak into accounts, underscoring the need for vigilance among both system administrators and regular employees.
Dive Insight: Okta’s main message to enterprises was that AI is augmenting, not replacing, existing strategies for breaking into targets’ online accounts . “AI is not the catalyst for identity attacks—it’s the accelerant,” researchers wrote. “Because the underlying conditions for initial access have not fundamentally changed, the architectural principles that secure organizations against human-led attacks remain just as effective against AI-augmented threats.” Okta analyzed roughly 6,000 social-engineering events to determine what kinds of attacks were the most common.
Continue reading
Watch a short ad to unlock the full article
The rest stays locked if you skip or close the ad early.
The company found that 87% of account takeovers involved attackers compromising passwords, with 58% also involving the compromise of authentication push notifications, 36% also involving the theft of app-based codes and 22% also involving the theft of SMS-based codes. The most common combination was stealing a password and subverting a push notification (47% of account takeovers occurred this way), followed by stealing a password and stealing an app-based code (27%).
Next, Okta evaluated each case based on how differently it would have gone with certain security controls in place. The company found that requiring users to use phishing-resistant account authentication would have stopped 88% of takeover attempts. Adding phishing resistance to third-party app sign-ins — an often-overlooked area of identity management — brought the number to 99.75%. (The tiny remaining fraction involved hackers compromising new enterprise accounts that were initially permissioned with weak authentication and then commandeering those accounts before the enterprise could apply stronger authentication.) As identity-management practices have become more sophisticated, hackers have tried to bypass them with a wide range of techniques .
Okta’s analysis of several campaigns described multiple forms of social-engineering lures. In one campaign, which began in August 2026, the attackers deployed a phishing kit that stole both passwords and one-time login codes. The malware presented a fake login window and invented a ruse to discourage the use of strong authentication tools.
“Since attackers know that they can’t defeat phishing-resistant authentication,” Okta researchers wrote, “they attempt to convince the target to use a one-time passcode instead by giving them a fake reason that their hardware key is not working.” After accessing the accounts, the attackers change their multifactor authentication enrollments to their own infrastructure in order to take control of them.
Okta also described two other campaigns. One in mid-2025 used Slack direct messages to direct victims to phishing sites, and another in 2023 began with text messages. Those campaigns were only successful because the victim organizations used authentication mechanisms that were susceptible to phishing .
“You can only prevent a skilled social engineer from achieving their objectives by denying them the ability to use weaker MFA factors to apps and data,” Okta said. “It’s vital that organizations not only mandate enrollment in phishing-resistant authenticators, but also enforce the use of phishing-resistant authenticators for access to protected resources as well as to add or remove new factors.”
Article text via FreeNewsAPI. Rights remain with Cybersecurity Dive.
Read on publisher site → Opens Cybersecurity Dive in a new tab