Identity security is under growing strain. The passwords, multi-factor authentication (MFA) responses, IP reputation, geolocation and browser characteristics organizations have traditionally used to judge whether a login is legitimate are becoming easier for attackers to steal, imitate or work around.

AI is adding to that pressure, not by creating a completely new class of attack, but by making familiar identity attacks faster and more efficient. Meanwhile, rotating IP addresses and disposable browser profiles make malicious logins harder to distinguish from legitimate ones.

Against this rapidly evolving threat landscape, organizations need effective Zero Trust measures that protect against ‘legitimate’ logins from attacker-controlled infrastructure. It’s here that device trust helps, ensuring that valid credentials are insufficient without the device context they were meant to be used from.

The Industrialization of Account Takeover Attacks

AI has not created a fundamentally new form of account takeover. Attackers still rely on familiar techniques: phishing, credential theft, MFA abuse, session hijacking and social engineering. What has changed is the amount of manual work needed to run those attacks effectively.