Create a free Supply & Demand Chain Executive account to continue reading

AI Automation to Combat Rising Impersonation Threats: Study

Organizations are pivoting toward identity verification to bridge the "literacy-action gap" that has stalled traditional passwordless adoption.

Marina M Headshot
Adam121 Adobe Stock 315095274
adam121 AdobeStock_315095274

For the first time, Generative AI (53%) and Agentic AI (45%) have displaced stolen credentials as the primary identity security concern, according to HYPR’s sixth annual State of Passwordless Identity Assurance report, produced by 451 Research.

That’s because organizations are pivoting toward identity verification (IDV) to bridge the "literacy-action gap" that has stalled traditional passwordless adoption.

"Technical literacy is no longer the bottleneck; the challenge now lies in the mechanics of scaling across the enterprise,” says Bojan Simic, CEO and co-founder of HYPR. “In 2026, automated agents will leak more passwords than people, shifting identity risk from human-scale errors to industrial-scale machine automation. We must move past point-in-time security and make identity verification a permanent part of how we manage every employee, from onboarding to offboarding.”

Key takeaways:

  • The majority of organizations (87%) have encountered audio or video deepfakes in identity-based attacks.
  • Despite passkey literacy surging to 64%, enterprise-wide adoption remains stalled at 43%.
  • FIDO passkeys are the gold standard by 64% of leaders (up from 40%).
  • 65% of attacks are detected within hours, but AI automation allows data theft before manual intervention.
  • 65% of enterprises indicate using IDV, yet implementation remains siloed, with most deploying to less than a quarter of their workforce.
  • AI is re-arming existing threats like phishing (43%) and ransomware (37%) to automate fraud at volume. While defensive tools now detect 65% of identity-based attacks within hours, the "exfiltration window" is closing faster than human teams can react.
  • Nearly two-thirds (65%) of organizations cited personalized phishing as the dominant identity risk
  • Synthetic media is now a Top Tier enterprise threat, with close to half (45%) identifying prerecorded video deepfakes as a primary concern.
  • 40% reported AI voice cloning incidents involving manipulated audio clips targeting call centers.
  • Identity impersonation incidents surged by 35%, with candidate fraud (39%) emerging as the second most prevalent threat after credential misuse.
  • 59% of organizations incur a "hindsight tax," increasing budgets only after a breach, at which point 61% prioritize rapid IDV and MFA (57%) deployment.
  • 76% of organizations still rely on legacy passwords, though 71% are now moving toward passwordless adoption.
  • Three-quarters are likely to invest in passkeys or passwordless tools in 2026.
  • One-third have active passwordless pilots underway, the highest of any authentication method surveyed.
  • More than one-third (33%) have successfully scaled passwordless protection to over half of their total workforce.

 

Page 1 of 182
Next Page