AI-Powered Identity Attacks: Why Identity Governance Is Your Best Defense

AI has not changed what attackers want. They still want credentials, access, and data. What AI has changed is how fast and how convincingly they get them. CrowdStrike’s 2026 Global Threat Report recorded an 89% increase in attacks by AI-enabled adversaries. Deepfake fraud losses hit $1.65 billion in a single year. 82% of CrowdStrike’s 2025 detections were malware-free – attackers logging in, not breaking in.

The security industry has responded with better endpoint detection, smarter email filters, and AI-powered threat intelligence. These are necessary. But none of them address the core problem: once an attacker has valid credentials – stolen, phished, or deepfaked past your verification – your perimeter defenses have already lost.

That is where identity governance picks up. Not as a replacement for detection, but as the control layer that limits what stolen credentials can actually reach.

The numbers behind the shift

The scale of AI-assisted identity attacks in 2025-2026 is not incremental. It is a category change.

Phishing has become AI-native. The FBI’s 2025 IC3 report recorded a 37% rise in AI-assisted business email compromise. Hoxhunt’s Phishing Trends Report found that 40% of BEC emails in Q2 2025 were AI-generated. Vishing – voice phishing – grew 442% between the first and second half of 2024, according to CrowdStrike and Pindrop.

Deepfakes have moved from novelty to operational weapon. Surfshark’s 2026 research tracked $2.19 billion in global deepfake fraud losses from January 2019 to March 2026, with $1.65 billion of that concentrated in 2025 alone. Pindrop recorded a 1,300% year-over-year rise in deepfake fraud attempts in contact centers. 62% of organizations surveyed by Gartner in September 2025 reported experiencing at least one deepfake attack in the prior twelve months.

Credential abuse remains the dominant breach vector. The Verizon 2026 DBIR found credential abuse present in 39% of full breach chains – the single most pervasive technique. IBM’s 2025 Cost of a Data Breach report measured breaches via compromised credentials at $4.67 million average cost, taking 246 days to identify and contain. CrowdStrike’s 2026 Global Threat Report noted an 89% increase in attacks by AI-enabled adversaries.

The speed has changed. CrowdStrike recorded the fastest eCrime breakout time at 27 seconds. Average breakout speed increased 65% year-over-year. When an attacker moves from initial access to lateral movement in under a minute, manual response processes are irrelevant.

Why better authentication is not enough

The instinctive response to credential-based attacks is stronger authentication: phishing-resistant MFA, passkeys, biometric verification. These are necessary. They are not sufficient.

Authentication answers one question: “Is this person who they claim to be at the moment of login?” It does not answer the questions that matter after authentication succeeds:

  • Should this person still have access to this system?
  • Does this access make sense given their current role?
  • Has anyone reviewed whether these privileges are still appropriate?
  • Is this combination of access rights creating a segregation-of-duties violation?
  • Would revoking this access, right now, take minutes or weeks?

These are identity governance questions. And for most organizations, the honest answer to each of them is “we don’t know” or “it depends on someone remembering to check.”

The real incidents tell the same story

The pattern in recent AI-assisted breaches is remarkably consistent. The attacker does not need a zero-day. They need a credential that nobody governs.

Arup, February 2024. A finance worker in Hong Kong joined a video call with colleagues including the company CFO. Every other participant on the call was an AI-generated deepfake. The worker authorized $25 million in transfers before the fraud was discovered.

Microsoft / Midnight Blizzard, January 2024. The Russian state-sponsored group password-sprayed into a legacy test account that had been left with elevated standing privileges to Microsoft’s corporate environment. They accessed email accounts of senior leadership and the cybersecurity team. The test account had no business need for those privileges. Nobody had reviewed it.

Snowflake customers, May 2024. Attackers used credentials stolen by infostealer malware to access approximately 165 customer tenants. No backdoors, no exploits. The accounts lacked MFA and had persistent standing access. Ticketmaster, Santander, and dozens more were affected.

Rakuten Mobile, February 2025. Three teenagers with no coding background used ChatGPT to build an attack tool that hit systems approximately 220,000 times. The barrier to entry for identity-based attacks has collapsed.

In every case, the governance gap was the same: credentials existed with excessive privileges, nobody was reviewing whether the access was still appropriate, and revocation processes were too slow to matter.

What identity governance actually defends

Identity governance does not stop phishing emails from arriving. It does not detect deepfakes. What it does is ensure that when an attacker succeeds in stealing or faking a credential, the damage they can do is constrained, detectable, and reversible.

Least privilege enforcement

The most direct defense against credential compromise is ensuring that every identity – human or machine – has only the access it currently needs. Not the access it needed six months ago. Not the access its predecessor in the role had. The access required by its current job function, right now.

midPoint enforces least privilege through automated role assignment based on HR data. When someone changes departments, their old access is revoked and new access is granted automatically. There is no accumulation of stale privileges, no “just in case” access lingering from a previous project.

Continuous access certification

Periodic access reviews catch the privileges that automated rules miss. midPoint runs access certification campaigns where managers and application owners verify that each identity’s access is still appropriate. Unreviewed items escalate automatically. Rejected access is revoked through automated provisioning, not a ticket queue.

This directly addresses the Snowflake and Microsoft breach patterns. Those dormant accounts with excessive privileges would have been flagged and revoked in the next certification cycle – or immediately, if event-triggered certification was configured for high-risk access.

Segregation of duties enforcement

AI-powered social engineering often targets finance and administrative functions where a single compromised identity can authorize transactions. midPoint’s SoD engine prevents toxic role combinations in real time. A user cannot simultaneously hold “create payment” and “approve payment” entitlements. An identity that acquires both – through any mechanism – triggers an automatic policy violation.

Outlier detection

When an attacker uses compromised credentials to request additional access or move laterally, their behavior creates anomalies in the identity data. midPoint’s outlier detection flags identities whose role assignments deviate from peers in the same organizational unit, job function, or archetype. An account that suddenly holds access to systems outside its normal scope surfaces as an outlier – even if every individual access grant was technically approved.

Rapid deprovisioning

When a breach is detected, the speed of access revocation determines the blast radius. Organizations using midPoint can revoke all access for a compromised identity across every connected system within minutes, not the days or weeks that manual processes require. IBM’s research shows that breaches involving compromised credentials take an average of 246 days to identify and contain. Automated deprovisioning compresses the “contain” portion to near zero.

Non-human identity governance

AI agents, service accounts, and API keys are increasingly targeted because they typically have broader access and weaker governance than human users. midPoint governs non-human identities with the same lifecycle controls as human identities. For a deep dive on this topic, see our article on Non-Human Identity Governance in midPoint.

The governance gap is measurable

IBM’s 2025 Cost of a Data Breach report found that organizations using extensive security AI and automation saved $1.9 million per breach compared to those that did not. But the report also found that 97% of organizations that experienced AI-related security incidents lacked proper AI access controls, and 63% lacked AI governance policies entirely.

The gap is not a technology gap. It is a governance gap. The controls exist. They are not deployed.

Gartner’s 2026 cybersecurity predictions explicitly recommend fortifying identities – both human and machine – with strong lifecycle controls as a top defense priority. Not as a nice-to-have compliance exercise, but as the primary control against credential-based attacks that now dominate the threat landscape.

What this means for your IGA program

If your identity governance program was designed primarily for compliance – annual access reviews, basic role assignments, audit log generation – it is not configured for an AI-powered threat environment. The difference between a compliance-oriented IGA deployment and a security-oriented one is:

Certification frequency. Annual reviews miss too much. High-risk access should be certified quarterly or on every change. midPoint supports both scheduled and event-triggered certification campaigns.

Scope. If your certifications cover human users but not service accounts, API keys, and AI agents, you are certifying the minority of your identity population. midPoint governs all identity types through the same framework.

Automation depth. If access revocation requires a helpdesk ticket, you cannot respond to a breach in the timeframe that matters. midPoint’s provisioning engine executes revocation automatically on certification decisions, policy violations, and lifecycle events.

SoD coverage. If segregation-of-duties checks only run at request time but not continuously, privilege accumulation creates exploitable gaps. midPoint evaluates SoD policies continuously across all role assignments.

Outlier visibility. If you cannot identify which identities hold access that deviates from their peers, you cannot detect lateral movement through compromised credentials. midPoint’s outlier detection makes this visible without manual analysis.

Start closing the governance gap

AI has made credential-based attacks faster, cheaper, and more convincing. The organizations that will weather this shift are not the ones with the best email filters. They are the ones where a stolen credential grants the minimum access required, where that access is reviewed regularly, where anomalies are detected automatically, and where revocation happens in minutes.

WeKnowIdentity helps organizations configure midPoint’s governance engine for security, not just compliance. That includes least-privilege role modeling, continuous certification campaigns, SoD policy design, outlier detection activation, and non-human identity governance. If your IGA program was built for auditors but not for attackers, that is the gap we close.

Book a free governance assessment

Related Resources

Sources

Planning an IAM modernization or migration?

Our midPoint specialists help enterprises implement, migrate, and operate identity governance platforms. Whether you are replacing MIM, SAP IDM, or another legacy system — we can help you plan a structured, low-risk transition.

Discuss Your Project

Free: midPoint Migration Readiness Checklist

50+ point checklist covering discovery, architecture planning, data migration, parallel operation, cutover, and post-migration validation. Used by our team on every enterprise deployment.

Get the Free Checklist →
JM

Ján Minárčiný

Founder & Lead midPoint Consultant | 4x Evolveum Certified

Ján is the founder of WeKnowIdentity, a boutique IAM consulting firm specializing in Evolveum midPoint. He holds four midPoint certifications (Professional, Advanced, Deployment Specialist, Group Synchronization), plus IDPro BoK and GitOps (CGOA) certifications. With 10+ enterprise midPoint deployments across Europe, he writes about IAM strategy, midPoint best practices, and identity governance.

Comments are closed.