Credentials theft is fired in 2025: IA, MFA phishing-resistant and Zero Trust to protect your identities

Author: Published 4 min de lectura 138 reading

The images in this article were generated with artificial intelligence. How we publish

Recent figures show that the theft of credentials has been triggered, with an increase in 160% in 2025 and that the committed credentials already participate in a significant part of the data leaks, according to reports such as Verizon's. These numbers are not a statistical curiosity: they are a clear symptom that the attackers have improved their tactics, integrating Artificial intelligence to automate their victim recognition, generate more convincing messages and evade traditional controls. For organizations this means that identity verification can no longer be a process; it must be a contextual, resilient and auditable process.

A key to reversing this trend is to rethink the role of passwords and authentication factors. The widespread use of static passwords, reuse between services and laxo incorporation processes create attack paths that malicious automation quickly exploits. Technical reports such as DBIR from Verizon and specialized journalistic analysis on the increase in the theft of credentials confirm that the exposure is widespread and that the defence must be multiple and coordinated.

Credentials theft is fired in 2025: IA, MFA phishing-resistant and Zero Trust to protect your identities
Image generated with IA.

First, priority must be given to phishing-resistant MFA instead of SMS-based solutions or push approvals susceptible to "prompt pumping" or SIM exchange. The adoption of standards such as FIDO2 and WebAuthn, hardware tokens, or passwords drastically reduces the likelihood of commitment because they eliminate the transmission of reusable secrets. This does not mean leaving the passwords overnight, but implementing a transition plan that provides for the safe recovery of accounts and provisional measures for users on non-compatible devices.

Technical support and support tables remain a preferred vector by attackers because they act as guardians of legitimate access under pressure. Implementation is essential strict verification procedures before resets or critical changes: verify identity with multiple factors (not just public information), record sensitive interactions, require additional authorisation for MFA changes and use tools that integrate automatic verification into the flow of the helpdesk. In addition, simulating social engineering attacks and performing specific exercises against deepfakes and voice supplanting helps to tighten human and technical responses.

Identity can no longer be assessed only by "what the user knows"; it must also be checked "from what" it is accessed. Incorporate device confidence access decisions - using MDM / EMM, EDR, device certificates, and patching status assessment - allow for differential policies: low-risk access with minimum controls and critical access with stepup authenization or blocking. This conditional access logic is the core of a Zero Trust model that reduces the surface usable by stolen credentials.

The passkeys and the passwordless are a promising alternative to reduce friction and operating windows, but they are not a panacea. Its adoption must be accompanied by robust recovery strategies, private key governance and user training to prevent fallback mechanisms (e.g. recovery mail) from becoming the new exploitable weakness. Design of device transfer flows, secure backups and administrative controls for privileged accounts is an essential part of any passkey deployment.

Biometry offers convenience and an additional barrier, but requires a design protection approach: never store unprocessed prints or faces, prefer local verification on the device, cipher biometric templates and limit their use to specific processes. For very high-security environments, privacy preservation technologies such as homomorphic encryption and protocols that allow comparison without exposing underlying data approach practical solutions; however, their complexity and cost require risk assessments and pilot tests before their mass deployment.

Credentials theft is fired in 2025: IA, MFA phishing-resistant and Zero Trust to protect your identities
Image generated with IA.

At the operational level, it is necessary to complement technical controls with detection and response: monitoring of abnormal login patterns, session and cookies protection, blocking of legal authentication, analysis of committed credentials and regular incident response exercises including IA-assisted supplanting scenarios. Continuous training of users and support equipment, together with regular audits of access policies, often offers the greatest return on risk reduction investment.

For security officials, the first practical step is to make an inventory of authentication vectors, map weak points (helpdesk, privileged accounts, recovery mechanisms) and prioritize risk mitigation measures with greater impact: deploy phishing-resistant MFA in critical accounts, apply device confidence for remote access and close unsafe channels such as SMS OTP. It is accompanied by real tests, key metric reports and a user communication plan that reduces friction and improves adoption.

The increase in the theft of credentials reminds us that the security of identities requires a multifaceted approach that combines technology, processes and human training. There is not a single miraculous solution, but a coherent strategy that combines Robust MFA, rigid control on the support, confidence in the device, well-governed passwordless and biometric data protection puts organizations in a position of advantage against the increasingly automated tactics of the attackers.

Coverage

Related

More news on the same subject.