AI has not changed what attackers want. They still want credentials, access, and data. What AI has changed is how fast and how convincingly they get them. CrowdStrike’s 2026 Global Threat Report recorded an 89% increase in attacks by AI-enabled adversaries. Deepfake fraud losses hit $1.65 billion in a single year. 82% of CrowdStrike’s 2025 detections were malware-free – attackers logging in, not breaking in.
The security industry has responded with better endpoint detection, smarter email filters, and AI-powered threat intelligence. These are necessary. But none of them address the core problem: once an attacker has valid credentials – stolen, phished, or deepfaked past your verification – your perimeter defenses have already lost.
That is where identity governance picks up. Not as a replacement for detection, but as the control layer that limits what stolen credentials can actually reach.
The numbers behind the shift
The scale of AI-assisted identity attacks in 2025-2026 is not incremental. It is a category change.
Phishing has become AI-native. The FBI’s 2025 IC3 report recorded a 37% rise in AI-assisted business email compromise. Hoxhunt’s Phishing Trends Report found that 40% of BEC emails in Q2 2025 were AI-generated. Vishing – voice phishing – grew 442% between the first and second half of 2024, according to CrowdStrike and Pindrop.
Deepfakes have moved from novelty to operational weapon. Surfshark’s 2026 research tracked $2.19 billion in global deepfake fraud losses from January 2019 to March 2026, with $1.65 billion of that concentrated in 2025 alone. Pindrop recorded a 1,300% year-over-year rise in deepfake fraud attempts in contact centers. 62% of organizations surveyed by Gartner in September 2025 reported experiencing at least one deepfake attack in the prior twelve months.
Credential abuse remains the dominant breach vector. The Verizon 2026 DBIR found credential abuse present in 39% of full breach chains – the single most pervasive technique. IBM’s 2025 Cost of a Data Breach report measured breaches via compromised credentials at $4.67 million average cost, taking 246 days to identify and contain. CrowdStrike’s 2026 Global Threat Report noted an 89% increase in attacks by AI-enabled adversaries.
The speed has changed. CrowdStrike recorded the fastest eCrime breakout time at 27 seconds. Average breakout speed increased 65% year-over-year. When an attacker moves from initial access to lateral movement in under a minute, manual response processes are irrelevant.
Why better authentication is not enough
The instinctive response to credential-based attacks is stronger authentication: phishing-resistant MFA, passkeys, biometric verification. These are necessary. They are not sufficient.
Authentication answers one question: “Is this person who they claim to be at the moment of login?” It does not answer the questions that matter after authentication succeeds:
- Should this person still have access to this system?
- Does this access make sense given their current role?
- Has anyone reviewed whether these privileges are still appropriate?
- Is this combination of access rights creating a segregation-of-duties violation?
- Would revoking this access, right now, take minutes or weeks?
These are identity governance questions. And for most organizations, the honest answer to each of them is “we don’t know” or “it depends on someone remembering to check.”
The real incidents tell the same story
The pattern in recent AI-assisted breaches is remarkably consistent. The attacker does not need a zero-day. They need a credential that nobody governs.
Arup, February 2024. A finance worker in Hong Kong joined a video call with colleagues including the company CFO. Every other participant on the call was an AI-generated deepfake. The worker authorized $25 million in transfers before the fraud was discovered.
Microsoft / Midnight Blizzard, January 2024. The Russian state-sponsored group password-sprayed into a legacy test account that had been left with elevated standing privileges to Microsoft’s corporate environment. They accessed email accounts of senior leadership and the cybersecurity team. The test account had no business need for those privileges. Nobody had reviewed it.
Snowflake customers, May 2024. Attackers used credentials stolen by infostealer malware to access approximately 165 customer tenants. No backdoors, no exploits. The accounts lacked MFA and had persistent standing access. Ticketmaster, Santander, and dozens more were affected.
Rakuten Mobile, February 2025. Three teenagers with no coding background used ChatGPT to build an attack tool that hit systems approximately 220,000 times. The barrier to entry for identity-based attacks has collapsed.
In every case, the governance gap was the same: credentials existed with excessive privileges, nobody was reviewing whether the access was still appropriate, and revocation processes were too slow to matter.
What identity governance actually defends
Identity governance does not stop phishing emails from arriving. It does not detect deepfakes. What it does is ensure that when an attacker succeeds in stealing or faking a credential, the damage they can do is constrained, detectable, and reversible.
Least privilege enforcement
The most direct defense against credential compromise is ensuring that every identity – human or machine – has only the access it currently needs. Not the access it needed six months ago. Not the access its predecessor in the role had. The access required by its current job function, right now.
midPoint enforces least privilege through automated role assignment based on HR data. When someone changes departments, their old access is revoked and new access is granted automatically. There is no accumulation of stale privileges, no “just in case” access lingering from a previous project.
Continuous access certification
Periodic access reviews catch the privileges that automated rules miss. midPoint runs access certification campaigns where managers and application owners verify that each identity’s access is still appropriate. Unreviewed items escalate automatically. Rejected access is revoked through automated provisioning, not a ticket queue.
This directly addresses the Snowflake and Microsoft breach patterns. Those dormant accounts with excessive privileges would have been flagged and revoked in the next certification cycle – or immediately, if event-triggered certification was configured for high-risk access.
Segregation of duties enforcement
AI-powered social engineering often targets finance and administrative functions where a single compromised identity can authorize transactions. midPoint’s SoD engine prevents toxic role combinations in real time. A user cannot simultaneously hold “create payment” and “approve payment” entitlements. An identity that acquires both – through any mechanism – triggers an automatic policy violation.
Outlier detection
When an attacker uses compromised credentials to request additional access or move laterally, their behavior creates anomalies in the identity data. midPoint’s outlier detection flags identities whose role assignments deviate from peers in the same organizational unit, job function, or archetype. An account that suddenly holds access to systems outside its normal scope surfaces as an outlier – even if every individual access grant was technically approved.
Rapid deprovisioning
When a breach is detected, the speed of access revocation determines the blast radius. Organizations using midPoint can revoke all access for a compromised identity across every connected system within minutes, not the days or weeks that manual processes require. IBM’s research shows that breaches involving compromised credentials take an average of 246 days to identify and contain. Automated deprovisioning compresses the “contain” portion to near zero.
Non-human identity governance
AI agents, service accounts, and API keys are increasingly targeted because they typically have broader access and weaker governance than human users. midPoint governs non-human identities with the same lifecycle controls as human identities. For a deep dive on this topic, see our article on Non-Human Identity Governance in midPoint.
The governance gap is measurable
IBM’s 2025 Cost of a Data Breach report found that organizations using extensive security AI and automation saved $1.9 million per breach compared to those that did not. But the report also found that 97% of organizations that experienced AI-related security incidents lacked proper AI access controls, and 63% lacked AI governance policies entirely.
The gap is not a technology gap. It is a governance gap. The controls exist. They are not deployed.
Gartner’s 2026 cybersecurity predictions explicitly recommend fortifying identities – both human and machine – with strong lifecycle controls as a top defense priority. Not as a nice-to-have compliance exercise, but as the primary control against credential-based attacks that now dominate the threat landscape.
What this means for your IGA program
If your identity governance program was designed primarily for compliance – annual access reviews, basic role assignments, audit log generation – it is not configured for an AI-powered threat environment. The difference between a compliance-oriented IGA deployment and a security-oriented one is:
Certification frequency. Annual reviews miss too much. High-risk access should be certified quarterly or on every change. midPoint supports both scheduled and event-triggered certification campaigns.
Scope. If your certifications cover human users but not service accounts, API keys, and AI agents, you are certifying the minority of your identity population. midPoint governs all identity types through the same framework.
Automation depth. If access revocation requires a helpdesk ticket, you cannot respond to a breach in the timeframe that matters. midPoint’s provisioning engine executes revocation automatically on certification decisions, policy violations, and lifecycle events.
SoD coverage. If segregation-of-duties checks only run at request time but not continuously, privilege accumulation creates exploitable gaps. midPoint evaluates SoD policies continuously across all role assignments.
Outlier visibility. If you cannot identify which identities hold access that deviates from their peers, you cannot detect lateral movement through compromised credentials. midPoint’s outlier detection makes this visible without manual analysis.
Start closing the governance gap
AI has made credential-based attacks faster, cheaper, and more convincing. The organizations that will weather this shift are not the ones with the best email filters. They are the ones where a stolen credential grants the minimum access required, where that access is reviewed regularly, where anomalies are detected automatically, and where revocation happens in minutes.
WeKnowIdentity helps organizations configure midPoint’s governance engine for security, not just compliance. That includes least-privilege role modeling, continuous certification campaigns, SoD policy design, outlier detection activation, and non-human identity governance. If your IGA program was built for auditors but not for attackers, that is the gap we close.
Book a free governance assessment
Related Resources
- Non-Human Identity Governance in midPoint: Closing the 109-to-1 Gap
- NIS2 Directive: How midPoint Helps You Meet Identity Security Requirements
- DORA Compliance: How midPoint Meets Identity Governance Requirements
- GDPR Compliance with midPoint: Automated Access Certification and Audit Reporting
Sources
- CrowdStrike 2026 Global Threat Report. 89% increase in AI-enabled adversary attacks, 82% malware-free detections, 27-second breakout time.
- Verizon 2026 Data Breach Investigations Report. Credential abuse in 39% of breach chains, 15 AI-bolstered attack techniques.
- IBM Cost of a Data Breach Report 2025. $4.67M credential breach cost, 246-day identification time, $1.9M savings with security AI.
- Surfshark Deepfake Fraud Research 2026. $2.19B global losses, $1.65B in 2025.
- Gartner, September 2025 Survey. 62% of organizations experienced deepfake attacks.
- Pindrop 2025 Voice Intelligence Report. 1,300% YoY rise in deepfake fraud attempts.
- FBI IC3 Report 2025. 37% rise in AI-assisted BEC.
- Hoxhunt Phishing Trends Report. 40% of BEC emails AI-generated in Q2 2025.
- CrowdStrike / Pindrop 2025. 442% vishing growth H1 to H2 2024.
- Gartner Cybersecurity Predictions 2026. Identity fortification as top priority.
Planning an IAM modernization or migration?
Our midPoint specialists help enterprises implement, migrate, and operate identity governance platforms. Whether you are replacing MIM, SAP IDM, or another legacy system — we can help you plan a structured, low-risk transition.
Discuss Your ProjectJán Minárčiný
Founder & Lead midPoint Consultant | 4x Evolveum Certified
Ján is the founder of WeKnowIdentity, a boutique IAM consulting firm specializing in Evolveum midPoint. He holds four midPoint certifications (Professional, Advanced, Deployment Specialist, Group Synchronization), plus IDPro BoK and GitOps (CGOA) certifications. With 10+ enterprise midPoint deployments across Europe, he writes about IAM strategy, midPoint best practices, and identity governance.

