Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

    August 10, 2026

    Bitcoin’s BIP-110 fork is back, but its backers want to replace the miners and change PoW

    August 10, 2026

    Lion Nebula Roars to Life With NASA’s Webb

    August 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
    • Bitcoin’s BIP-110 fork is back, but its backers want to replace the miners and change PoW
    • Lion Nebula Roars to Life With NASA’s Webb
    • State of the Climate: A Dimming, Overheated Planet, With Degraded Oceans
    • Boskalis’ vessel duo pulls off Brazil-to-Denmark tow of MODEC’s FPSO (Gallery)
    • How to feel optimistic in the face of crisis? Ask the kids fighting slug-like aliens | Alexander Hurst
    • Will Earth ‘lose gravity’ for 7 seconds on Aug. 12, 2026? NASA weighs in
    • How the US far-right weaponised ‘inshallah’ against Abdul El-Sayed | Islamophobia News
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 10
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    When Credentials Are No Longer Enough: Device Trust in the AI Era

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 10, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Identity security is under growing strain. The passwords, multi-factor authentication (MFA) responses, IP reputation, geolocation and browser characteristics organizations have traditionally used to judge whether a login is legitimate are becoming easier for attackers to steal, imitate or work around.

    AI is adding to that pressure, not by creating a completely new class of attack, but by making familiar identity attacks faster and more efficient. Meanwhile, rotating IP addresses and disposable browser profiles make malicious logins harder to distinguish from legitimate ones.

    Against this rapidly evolving threat landscape, organizations need effective Zero Trust measures that protect against ‘legitimate’ logins from attacker-controlled infrastructure. It’s here that device trust helps, ensuring that valid credentials are insufficient without the device context they were meant to be used from.

    The Industrialization of Account Takeover Attacks

    AI has not created a fundamentally new form of account takeover. Attackers still rely on familiar techniques: phishing, credential theft, MFA abuse, session hijacking and social engineering. What has changed is the amount of manual work needed to run those attacks effectively.

    Threat actors can create and send thousands of convincing phishing emails with little effort. If a more personalized message is needed, AI can pull public information from across the internet to build a detailed profile of the target.

    Attackers can then adapt their message to match the target’s language and business context. A finance employee might receive a supplier-related request, while an administrator is approached with a cloud access issue.

    None of this means AI is autonomously running the entire intrusion. In most cases, people still choose the targets, control the infrastructure and decide what to do with successful access.

    The more accurate way to describe the change is that AI compresses the human work between acquiring information and acting on it. It lowers the cost of personalization and triage, allowing teams to run more campaigns and focus their effort on accounts with the highest expected value.

    Verizon’s Data Breach Investigation Report found stolen credentials are involved in 44.7% of breaches. 

    Effortlessly secure Active Directory with compliant password policies, blocking 6+ billion compromised passwords, boosting security, and slashing support hassles!

    Try it for free

    Where Traditional Trust Signals Are Falling Short

    Identity platforms often combine several signals to decide whether a login should be trusted. Each still has value, but attackers increasingly know how to steal, imitate or bypass the evidence these controls rely on.

    Credentials

    While passwordless options are becoming more popular, credentials are still required in most authentication flows. As such, phishing and credential-harvesting malware like infostealers form the first step in many account takeover attacks.

    Attackers can also simply reuse credentials from previous breaches. In an incident earlier this year, IGN’s Twitch stream was hijacked by an unknown attacker, using Restream.io credentials that had sat in infostealers dumps for roughly a month before being exploited.

    The attack highlights the importance of scanning for leaked credentials. Solutions such as Specops Password Auditor carry out a read-only scan of your Active Directory to identify leaked passwords and related vulnerabilities.

    You’ll then receive an easy-to-understand report to help you prioritize fixes. Download Specops Password Auditor for free here.

    MFA

    MFA significantly improves security, but its strength depends on the method and the surrounding authentication flow.

    One-time codes can be captured through phishing. Push notifications can be abused through repeated prompts or social engineering. Adversary-in-the-middle phishing can relay credentials and MFA responses to the legitimate service in real time.

    Attackers may also steal session cookies after authentication and avoid the MFA challenge entirely.

    IP Address and Geolocation

    IP reputation can identify connections from known malicious infrastructure, while geolocation can flag activity from an unexpected region.

    However, attackers can route traffic through residential proxies, mobile networks or compromised systems. They may choose an exit node close to the victim, making the login appear geographically plausible.

    Legitimate activity is equally difficult to interpret. Remote work and corporate VPNs can produce unfamiliar locations. Stricter policies may block more attacks, but they also increase false positives and support work.

    NIST’s Zero Trust Architecture guidance reflects this limitation. SP 800-207 states that organizations should not grant implicit trust based solely on physical or network location.

    It treats user and device authentication as separate functions that should take place before access to an enterprise resource is established.

    Device Binding Adds Another Trust Layer

    Most identity controls still depend on credentials that can be presented from almost anywhere. This is why organizations need to extend trust decisions beyond traditional identity signals.

    Solutions like Specops Device Trust limit an attacker’s ability to spoof legitimate login attempts and reduce the risk of account takeover by:

    1. Tying Access to Approved Hardware

    Organizations should be able to register and limit trusted devices, different policies to corporate, personal and third-party hardware.

    If the login comes from an unknown device, the identity platform should treat that as a meaningful change in risk. Access shouldn’t be granted simply because the credentials and MFA succeeded.

    2. Continuously Evaluating the User and the Device

    A successful login should not create permanent trust for the rest of the session. Access should continue to depend on both the user’s identity and the health of their device.

    If posture changes, such as through disabling endpoint protection or the device falling out of compliance, the level of access should change.

    3. Matching Enforcement to the Level of Risk

    Security teams are right to be cautious about adding friction, so device posture policies do not have to make every issue a blocking event.

    Depending on the application and the severity of the problem, organizations can reduce privileges or give the user a short grace period to fix the device.

    That approach keeps the control proportionate. A missing update should not always be treated in the same way as disabled endpoint protection or a rooted device.

    4. Making it Easy for Users to Restore Trust

    When access depends on device health, users need a clear way to resolve problems. Self-guided remediation allows employees to fix issues quickly, which reduces disruption while keeping the required security standard in place.

    Mitigate the Risk of AI-Enabled Account Takeover with Specops

    As AI improves the speed and personalization of account takeover, IT teams need solutions that blunt the effectiveness of those attacks.

    While it may be a challenge to identify every malicious login from network signals alone, organizations can make valid credentials insufficient without the device context they were meant to be used from.

    If you’re interested in seeing how Specops can help evolve your identity security strategy by bringing device trust into access decisions, contact us today.

    Sponsored and written by Specops Software.

    Credentials Device Era longer trust
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

    Member of The Com sent to prison for blackmail, sextortion

    Valve notifies Steam hardware customers of a data breach

    How to detect OAuth client ID spoofing in Microsoft Entra ID before account takeover

    Critical Progress LoadMaster flaw now actively exploited in attacks

    OpenAI’s Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

    August 10, 2026

    Bitcoin’s BIP-110 fork is back, but its backers want to replace the miners and change PoW

    August 10, 2026

    Lion Nebula Roars to Life With NASA’s Webb

    August 10, 2026

    State of the Climate: A Dimming, Overheated Planet, With Degraded Oceans

    August 10, 2026
    Latest Posts

    Harbour Energy’s US arm advances repair plan after riser leak at Gulf of America oil & gas asset

    July 24, 2026

    Beavers restored a volcano-scarred river. Now it’s at risk again

    July 24, 2026

    China’s Tianwen-1 captures interstellar comet 3I/ATLAS near Mars

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

    August 10, 2026

    Bitcoin’s BIP-110 fork is back, but its backers want to replace the miners and change PoW

    August 10, 2026

    Lion Nebula Roars to Life With NASA’s Webb

    August 10, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.