What Recent AI-Powered Attacks Mean for Your Identity Security
Commentary on AI-accelerated credential theft cites Google's report of a six-hour multi-agent cloud attack and urges device trust and zero-trust identity controls.
The piece recounts Google Threat Intelligence Group's September 8 report of a credential-harvesting operation where an AI-built multi-agent framework compromised cloud infrastructure and thousands of third-party credentials in under six hours, including automated vulnerability scanning and IP rotation. It also cites Microsoft's April finding that AI-assisted phishing achieved 54% click-through rates versus roughly 12% for traditional campaigns, and Unit 42 data that identity weaknesses featured in 89% of investigated incidents. The article, which promotes Specops Password Auditor and Device Trust, argues successful authentication does not establish device trust and recommends binding identities to approved devices.