Security pros still use passwords amid AI phishing
Yubico and Okta found 43% of security professionals still use work passwords, while sources differ on survey size and how AI phishing was measured.
Yubico and Okta’s 2026 authentication research found that many security and technology professionals still sign in with passwords even as AI-driven phishing is widely reported. Infosecurity Magazine said the survey covered 2,000 cybersecurity professionals, while Help Net Security said it covered 1,890 technology and security professionals across nine countries. Both sources said 43% still use a username and password for work; Infosecurity also reported 48% do so for personal accounts, that only 25% use hardware-backed passkeys at work, that 23% of organizations do not mandate MFA everywhere, and that 76% see fragmented authentication. Help Net Security added that 87% said they knew passkeys, 52% were issued a password at onboarding, and only 36% correctly told a human-written HR email from an AI-generated one. Both reported that 44% said their organization had at least one AI-driven phishing incident in the past year, though Help Net Security described those incidents as successful and self-reported rather than a measured breach rate. Infosecurity separately said 70% reported more phishing and 43% reported deepfake voice, video, or phone impersonation.
- Sources disagree on sample size: Infosecurity Magazine said 2,000 cybersecurity professionals; Help Net Security said 1,890 technology and security professionals across nine countries in a 2026 authentication report.
- Both said 43% still use a username and password for work accounts; Infosecurity also said 48% do so for personal accounts, ranking passwords among the least secure methods.
- Infosecurity: only 25% use hardware-backed passkeys at work, 23% said organizations do not mandate MFA everywhere, and 76% reported fragmented authentication across internal apps.
- Help Net Security: 87% said they knew passkeys, and 52% were issued a password at onboarding.
- Both said 44% reported at least one AI-driven phishing attack in the past year; Help Net Security called the figure successful and self-reported, not a measured breach rate.
- Infosecurity: 70% reported more phishing, and 43% reported deepfake voice, video, or phone impersonation.
- Help Net Security: only 36% correctly distinguished a human-written HR email from an AI-generated one.
Coverage timelineoldest first · each row is one article
- · 1d agoHalf of Cybersecurity Pros Still Rely on Passwords Despite Security Concerns
Infosecurity Magazine· 48
Yubico and Okta found nearly half of security professionals still use passwords while AI-driven phishing rises.
- · 20h agoThe people who know passkeys best are still typing passwords
Help Net Security· 41
Yubico and Okta found 43% of security professionals still sign in with passwords despite knowing passkeys.