Identity security is under growing strain. The passwords, multi-factor authentication (MFA) responses, IP reputation, geolocation and browser characteristics organizations have traditionally used to judge whether a login is legitimate are becoming easier for attackers to steal, imitate or work around.
AI is adding to that pressure, not by creating a completely new class of attack, but by making familiar identity attacks faster and more efficient. Meanwhile, rotating IP addresses and disposable browser profiles make malicious logins harder to distinguish from legitimate ones.
Against this rapidly evolving threat landscape, organizations need effective Zero Trust measures that protect against ‘legitimate’ logins from attacker-controlled infrastructure. It’s here that device trust helps, ensuring that valid credentials are insufficient without the device context they were meant to be used from.
The Industrialization of Account Takeover Attacks
AI has not created a fundamentally new form of account takeover. Attackers still rely on familiar techniques: phishing, credential theft, MFA abuse, session hijacking and social engineering. What has changed is the amount of manual work needed to run those attacks effectively.
Threat actors can create and send thousands of convincing phishing emails with little effort. If a more personalized message is needed, AI can pull public information from across the internet to build a detailed profile of the target.
Attackers can then adapt their message to match the target’s language and business context. A finance employee might receive a supplier-related request, while an administrator is approached with a cloud access issue.
None of this means AI is autonomously running the entire intrusion. In most cases, people still choose the targets, control the infrastructure and decide what to do with successful access.
The more accurate way to describe the change is that AI compresses the human work between acquiring information and acting on it. It lowers the cost of personalization and triage, allowing teams to run more campaigns and focus their effort on accounts with the highest expected value.
Verizon’s Data Breach Investigation Report found stolen credentials are involved in 44.7% of breaches.
Effortlessly secure Active Directory with compliant password policies, blocking 6+ billion compromised passwords, boosting security, and slashing support hassles!
Where Traditional Trust Signals Are Falling Short
Identity platforms often combine several signals to decide whether a login should be trusted. Each still has value, but attackers increasingly know how to steal, imitate or bypass the evidence these controls rely on.
Credentials
While passwordless options are becoming more popular, credentials are still required in most authentication flows. As such, phishing and credential-harvesting malware like infostealers form the first step in many account takeover attacks.
Attackers can also simply reuse credentials from previous breaches. In an incident earlier this year, IGN’s Twitch stream was hijacked by an unknown attacker, using Restream.io credentials that had sat in infostealers dumps for roughly a month before being exploited.
The attack highlights the importance of scanning for leaked credentials. Solutions such as Specops Password Auditor carry out a read-only scan of your Active Directory to identify leaked passwords and related vulnerabilities.
You’ll then receive an easy-to-understand report to help you prioritize fixes. Download Specops Password Auditor for free here.
MFA
MFA significantly improves security, but its strength depends on the method and the surrounding authentication flow.
One-time codes can be captured through phishing. Push notifications can be abused through repeated prompts or social engineering. Adversary-in-the-middle phishing can relay credentials and MFA responses to the legitimate service in real time.
Attackers may also steal session cookies after authentication and avoid the MFA challenge entirely.
IP Address and Geolocation
IP reputation can identify connections from known malicious infrastructure, while geolocation can flag activity from an unexpected region.
However, attackers can route traffic through residential proxies, mobile networks or compromised systems. They may choose an exit node close to the victim, making the login appear geographically plausible.
Legitimate activity is equally difficult to interpret. Remote work and corporate VPNs can produce unfamiliar locations. Stricter policies may block more attacks, but they also increase false positives and support work.
NIST’s Zero Trust Architecture guidance reflects this limitation. SP 800-207 states that organizations should not grant implicit trust based solely on physical or network location.
It treats user and device authentication as separate functions that should take place before access to an enterprise resource is established.
Device Binding Adds Another Trust Layer
Most identity controls still depend on credentials that can be presented from almost anywhere. This is why organizations need to extend trust decisions beyond traditional identity signals.
Solutions like Specops Device Trust limit an attacker’s ability to spoof legitimate login attempts and reduce the risk of account takeover by:
1. Tying Access to Approved Hardware
Organizations should be able to register and limit trusted devices, different policies to corporate, personal and third-party hardware.
If the login comes from an unknown device, the identity platform should treat that as a meaningful change in risk. Access shouldn’t be granted simply because the credentials and MFA succeeded.
2. Continuously Evaluating the User and the Device
A successful login should not create permanent trust for the rest of the session. Access should continue to depend on both the user’s identity and the health of their device.
If posture changes, such as through disabling endpoint protection or the device falling out of compliance, the level of access should change.
3. Matching Enforcement to the Level of Risk
Security teams are right to be cautious about adding friction, so device posture policies do not have to make every issue a blocking event.
Depending on the application and the severity of the problem, organizations can reduce privileges or give the user a short grace period to fix the device.
That approach keeps the control proportionate. A missing update should not always be treated in the same way as disabled endpoint protection or a rooted device.
4. Making it Easy for Users to Restore Trust
When access depends on device health, users need a clear way to resolve problems. Self-guided remediation allows employees to fix issues quickly, which reduces disruption while keeping the required security standard in place.
Mitigate the Risk of AI-Enabled Account Takeover with Specops
As AI improves the speed and personalization of account takeover, IT teams need solutions that blunt the effectiveness of those attacks.
While it may be a challenge to identify every malicious login from network signals alone, organizations can make valid credentials insufficient without the device context they were meant to be used from.
If you’re interested in seeing how Specops can help evolve your identity security strategy by bringing device trust into access decisions, contact us today.
Sponsored and written by Specops Software.


