The images in this article were generated with artificial intelligence. How we publish
Recent figures show that the theft of credentials has been triggered, with an increase in 160% in 2025 and that the committed credentials already participate in a significant part of the data leaks, according to reports such as Verizon's. These numbers are not a statistical curiosity: they are a clear symptom that the attackers have improved their tactics, integrating Artificial intelligence to automate their victim recognition, generate more convincing messages and evade traditional controls. For organizations this means that identity verification can no longer be a process; it must be a contextual, resilient and auditable process.
A key to reversing this trend is to rethink the role of passwords and authentication factors. The widespread use of static passwords, reuse between services and laxo incorporation processes create attack paths that malicious automation quickly exploits. Technical reports such as DBIR from Verizon and specialized journalistic analysis on the increase in the theft of credentials confirm that the exposure is widespread and that the defence must be multiple and coordinated.

First, priority must be given to phishing-resistant MFA instead of SMS-based solutions or push approvals susceptible to "prompt pumping" or SIM exchange. The adoption of standards such as FIDO2 and WebAuthn, hardware tokens, or passwords drastically reduces the likelihood of commitment because they eliminate the transmission of reusable secrets. This does not mean leaving the passwords overnight, but implementing a transition plan that provides for the safe recovery of accounts and provisional measures for users on non-compatible devices.
Technical support and support tables remain a preferred vector by attackers because they act as guardians of legitimate access under pressure. Implementation is essential strict verification procedures before resets or critical changes: verify identity with multiple factors (not just public information), record sensitive interactions, require additional authorisation for MFA changes and use tools that integrate automatic verification into the flow of the helpdesk. In addition, simulating social engineering attacks and performing specific exercises against deepfakes and voice supplanting helps to tighten human and technical responses.
Identity can no longer be assessed only by "what the user knows"; it must also be checked "from what" it is accessed. Incorporate device confidence access decisions - using MDM / EMM, EDR, device certificates, and patching status assessment - allow for differential policies: low-risk access with minimum controls and critical access with stepup authenization or blocking. This conditional access logic is the core of a Zero Trust model that reduces the surface usable by stolen credentials.
The passkeys and the passwordless are a promising alternative to reduce friction and operating windows, but they are not a panacea. Its adoption must be accompanied by robust recovery strategies, private key governance and user training to prevent fallback mechanisms (e.g. recovery mail) from becoming the new exploitable weakness. Design of device transfer flows, secure backups and administrative controls for privileged accounts is an essential part of any passkey deployment.
Biometry offers convenience and an additional barrier, but requires a design protection approach: never store unprocessed prints or faces, prefer local verification on the device, cipher biometric templates and limit their use to specific processes. For very high-security environments, privacy preservation technologies such as homomorphic encryption and protocols that allow comparison without exposing underlying data approach practical solutions; however, their complexity and cost require risk assessments and pilot tests before their mass deployment.

At the operational level, it is necessary to complement technical controls with detection and response: monitoring of abnormal login patterns, session and cookies protection, blocking of legal authentication, analysis of committed credentials and regular incident response exercises including IA-assisted supplanting scenarios. Continuous training of users and support equipment, together with regular audits of access policies, often offers the greatest return on risk reduction investment.
For security officials, the first practical step is to make an inventory of authentication vectors, map weak points (helpdesk, privileged accounts, recovery mechanisms) and prioritize risk mitigation measures with greater impact: deploy phishing-resistant MFA in critical accounts, apply device confidence for remote access and close unsafe channels such as SMS OTP. It is accompanied by real tests, key metric reports and a user communication plan that reduces friction and improves adoption.
The increase in the theft of credentials reminds us that the security of identities requires a multifaceted approach that combines technology, processes and human training. There is not a single miraculous solution, but a coherent strategy that combines Robust MFA, rigid control on the support, confidence in the device, well-governed passwordless and biometric data protection puts organizations in a position of advantage against the increasingly automated tactics of the attackers.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...