Kasey Cromer, Netlok | September 8, 2026
Executive Summary
Wall Street has always been a target. But the nature of the threat has fundamentally changed. In August 2026, a coordinated wave of AI-powered voice phishing attacks hit several of the largest hedge funds and asset managers in the United States, including Two Sigma Investments and Point72 Asset Management. Attackers used AI voice cloning to impersonate trusted executives and colleagues, pressuring employees into surrendering login credentials or granting system access. Two Sigma confirmed it detected and stopped the attempted breach with no impact to its data or systems. Point72 told investors its initial review found no client information had been stolen.
These incidents are not isolated. Mandiant’s M-Trends 2026 report, drawn from more than 500,000 hours of incident response investigations in 2025, found that voice phishing surged to 11% of all confirmed entry points, making it the second most common way attackers first get in after software exploits at 32%. Email phishing declined to just 6%. The calls are outperforming the clicks.
The strategic question is no longer whether voice phishing is a real threat. The August 2026 incidents settled that. The question is what an attacker can obtain when a convincing call gets through. Photolok by Netlok addresses that question at the identity layer.
Why Financial Services Firms Are the Primary Target
Financial services firms offer something no other sector can match: direct, scalable access to liquid capital, combined with time pressure that makes verification feel inconvenient. Hedge funds, asset managers, private equity firms, investment banks, and broker-dealers execute high-value transactions at speed, manage market-moving information, and operate through tightly interconnected systems, each representing a potential access point.
Mandiant’s M-Trends 2026 data shows financial services accounted for 14.6% of all incidents Mandiant investigated in 2025, the second most frequently targeted industry. The FBI’s 2025 Internet Crime Report registered more than 191,000 phishing and spoofing complaints, the most frequently reported cybercrime category for the third consecutive year, with business email compromise accounting for $3.046 billion in reported losses.
FS-ISAC’s Navigating Cyber 2025 report, drawing on intelligence from more than 5,000 financial firm members across 75 countries, identified AI-enabled fraud and impersonation attacks, including deepfakes targeting executives, as a central and growing threat to the sector. Economic instability amplifies all of this. When markets are volatile, urgent out-of-hours requests for capital reallocation or system access become routine. Attackers exploit that operational rhythm. Financial sector employees are conditioned to move quickly when authority commands it. AI voice cloning turns that conditioning into a vulnerability.
How AI Has Changed the Voice Phishing Threat
FINRA’s investor guidance, published in 2025, states that fraudsters need only three seconds of audio to create a credible-sounding voice clone. For financial executives, that source material is everywhere: earnings calls, conference presentations, media interviews, and internal videos are all publicly accessible and sufficient to build a working model. Once built, the clone can be deployed with scripts personalized using publicly available information about the target’s role, relationships, and current business context.
Federal Reserve Board Governor Michael Barr addressed this directly in an April 2025 speech at the Federal Reserve Bank of New York, warning that generative AI has given criminals the ability to replicate a person’s voice, phrase patterns, tone, and inflection from a short audio sample. He described this as the potential to “supercharge identity fraud” and stated that voice biometrics used for authentication are effectively defeated by current AI capabilities.
Voice phishing accounted for 23% of confirmed entry points in cloud-related incidents in Mandiant’s M-Trends 2026 report, making it the single most common way attackers got into cloud environments. CrowdStrike’s 2026 Threat Hunting Report documents that voice phishing increased 134% from 2024 to 2025, and the first half of 2026 has already matched the full volume of the second half of 2025. The threat is still accelerating.
The Identity Layer Is the Target
Every AI voice phishing call in the financial sector is designed around one objective. Attackers want to obtain a credential, trigger an authentication, gain a session, or reset access. The attacker may impersonate a managing director, a chief risk officer, or an IT help desk analyst. The voice and urgency vary. The end state is always the same. Convert a convincing call into account access.
Password-based authentication creates a structural vulnerability that awareness training cannot fully close. A well-constructed voice phishing call is designed to override skepticism by exploiting legitimate authority relationships. When someone who sounds exactly like the CIO calls an IT administrator to request an urgent password reset, the pressure to comply is real and the time to verify is short. If the authentication architecture leaves a reusable password in the transaction, the attacker has everything they came for.
The FINRA 2025 Annual Regulatory Oversight Report warns member firms to consider whether their cybersecurity programs address the use of generative AI to increase the credibility and severity of attacks, including deepfake audio, linking AI-enabled fraud specifically to account takeovers, fraudulent wire transfers, and unauthorized system access. The SEC Division of Examinations has similarly reinforced identity validation as a core regulatory priority, noting in its 2026 Examination Priorities that registered investment advisers and financial institutions must demonstrate resilient controls capable of mitigating sophisticated AI-generated audio and video attacks and manipulation-based fraud.
Why Traditional Defenses Are Not Enough
Financial firms have invested heavily in email security, security software on individual devices, and security awareness training. These controls matter, but they were built for a different threat model. Email filtering cannot stop a phone call. Caller ID cannot establish who is speaking. Awareness training asks employees to detect fraud by recognizing signs of deception, but AI voice cloning removes those signs. The voice is correct. The context is correct. The urgency is calibrated. There may be nothing to detect.
Mandiant’s M-Trends 2026 data shows email phishing has declined to just 6% of confirmed entry points. Attackers are moving away from channels where defenses are strongest and toward voice, cloud access, and direct human manipulation, where employee judgment is the last line of defense. Asking employees to be the final detection layer against real-time AI voice cloning in a high-pressure financial environment is not a security strategy. Employees have always been in the line of defense. What has changed is the vehicle attackers use to reach them.
The structural problem is that as long as passwords exist in the authentication workflow, a successful impersonation attempt has a clear payoff. A password can be read aloud, entered into a portal while an attacker watches, or reset through a help desk workflow. Once obtained, it can be reused or combined with further manipulation to reach higher-value systems.
How Photolok by Netlok Addresses the Gap
Photolok by Netlok operates at the identity layer and integrates with platforms such as Okta Workforce. It replaces password-based credentials specifically and does not claim to eliminate every form of credential or every security risk. Its value in a voice phishing scenario is direct: when there is no password for an employee to surrender or enter after being deceived, the attacker cannot convert a convincing phone call into account access.
Photo-based authentication. Users identify images from a photo panel rather than entering a password. What makes this more than a visual password is what happens behind the scenes: each photo carries an encrypted code that changes with every login, is tied to the user’s registered device, and requires a server-side access code to validate. Even if an attacker captures or records a session, they cannot use it because the encryption and device binding lock them out. A voice phishing call that ends with the employee cooperating with a credential request returns nothing of value, because even if the photos were obtained, the encryption and device binding make them unusable without the registered device and server-side access code.
1 Time Photo. Users can configure up to five single-use photos for authentication. Once used, that photo is no longer available. Even if an attacker intercepts a login or records a session, the encrypted codes tied to that photo have already expired and there is nothing to capture that can be reused to break in again. For financial firms where session hijacking and help desk resets are common attack objectives, this removes a persistent category of risk.
Duress Photo. Users can configure up to two Duress Photos, randomly selected for display during login. Duress photos are silent alarms. If an employee is pressured by someone impersonating an executive, colleague, or IT staff member into authenticating under coercion, selecting a Duress Photo triggers a real-time alert to security teams the moment it is chosen, while the login appears normal to the attacker. In a financial sector environment where employees may face significant authority pressure to comply with an urgent-sounding request, this gives the organization a way to detect and respond to coerced authentication without requiring the employee to openly challenge the caller, a capability that passwords, passkeys, and biometrics do not provide.
For financial services CISOs, the strategic case is straightforward: the August 2026 incidents demonstrated that even well-resourced firms with strong security programs are targeted by AI voice phishing. The question is not whether the calls will come. It is what the attacker can obtain when one succeeds. Photolok changes that answer at the identity layer, without requiring changes to the trading platforms, portfolio systems, or core infrastructure behind the login.
The Bottom Line
The August 2026 AI voice phishing campaign against Wall Street’s largest hedge funds is a marker, not an outlier. Voice phishing is now the second most common way attackers gain entry to enterprise systems globally, making the financial sector’s combination of liquid assets, interconnected systems, authority-driven culture, and market urgency an ideal target for a threat that exploits trust.
FINRA and the SEC have both issued guidance making clear that AI-generated audio and video attacks are regulatory concerns, not just security concerns. Firms that rely solely on awareness training, email filtering, and caller verification to defend against AI voice cloning are betting that their employees can reliably detect deception that is designed to be undetectable.
The more durable defense is to remove what the attacker is calling to collect. Photolok removes passwords from the identity layer, replacing them with a credential type that cannot be handed over in a phone call or captured and reused, and gives security teams a real-time signal when someone is authenticating under duress.
The call will come. What the attacker walks away with is the question Photolok answers.
Request Your Personalized Demo
About the Author
Kasey Cromer is Director of Customer Experience at Netlok.
Sources
[1] Mandiant. ‘M-Trends 2026.’ March 2026. cloud.google.com/blog/topics/threat-intelligence/m-trends-2026
[2] FBI Internet Crime Complaint Center. ‘2025 Internet Crime Report.’ 2026. ic3.gov
[3] FS-ISAC. ‘Navigating Cyber 2025.’ May 2025. fsisac.com
[4] FINRA. ‘Protecting Your Investment Accounts From GenAI Fraud.’ 2025. finra.org
[5] FINRA. ‘2025 Annual Regulatory Oversight Report.’ January 2025. finra.org
[6] Federal Reserve Board. ‘Deepfakes and the AI Arms Race in Bank Cybersecurity.’ April 2025. federalreserve.gov
[7] CrowdStrike. ‘2026 Threat Hunting Report.’ August 2026. crowdstrike.com
[8] SEC Division of Examinations. ‘2026 Examination Priorities.’ 2026. sec.gov
[9] Public reporting on the August 2026 AI voice phishing campaign targeting Wall Street investment firms, including confirmed statements from Two Sigma and Point72.
[10] Netlok. ‘How Photolok Works.’ netlok.com
Kasey Cromer, Netlok | August 24, 2026
Executive Summary
Targeted impersonation is no longer an edge case. According to Outtake’s 2026 State of Digital Risk Report, based on a survey of more than 900 enterprise security, fraud, and risk leaders, 53% of organizations had an executive or employee impersonated in the past year. A separate Outtake report — the 2026 State of Executive Impersonation, drawn from 40,000 impersonation alerts across approximately 300 monitored executives — found that 47% of organizations had already encountered confirmed or suspected AI-generated impersonation of an executive or brand representative. AI has made these attacks faster to produce, harder to detect, and easier to execute across every channel an organization uses — email, voice, text, video, and collaboration tools.
The objective behind every impersonation attempt is consistent: persuade a trusted person to reveal a password, enter it into a login page while the attacker watches, approve an authentication request, or grant access under false pretenses. That makes impersonation fundamentally an identity security problem. Filters and training help, but they cannot guarantee that every employee will recognize every convincing fraud. Password-based authentication gives attackers a transferable prize. Removing password-based credentials at the identity layer changes the payoff entirely: even when the deception gets through, there is no password to hand over.
Photolok by Netlok does not prevent every impersonation attempt from reaching an employee. But it removes what the attacker is trying to obtain when one does.
Impersonation Has Reached Enterprise Scale
The evidence shows an environment where impersonation and fraud are now pervasive across organizations of every size and sector. Outtake’s 2026 Report found that 84% of organizations experienced material digital risk incidents in the past year, yet only 7% describe their program as leading — meaning the vast majority are dealing with active threats while operating programs they themselves consider underdeveloped. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 77% of respondents reported an increase in fraud and impersonation-driven attacks in 2025, and that 73% said they or someone in their network had been personally affected.
At the transaction level, the Anti-Phishing Working Group (APWG) recorded 971,181 phishing attacks in the first quarter of 2026, rising from 853,244 in Q4 2025 — a 13.8% increase in a single quarter, directly reported in APWG’s Q1 2026 Phishing Activity Trends Report. The FBI’s 2025 Internet Crime Report registered phishing and spoofing as the most frequently reported cybercrime category for the third consecutive year, with more than 191,000 complaints filed. Business email compromise — fraud in which an attacker poses as a trusted executive, supplier, or colleague to redirect payments or access — accounted for $3.046 billion in reported losses in 2025 across 24,768 tracked incidents. These are directly reported complaint and loss totals; a per-incident average of approximately $123,000 is a figure calculated from those totals, not a number directly reported by the FBI.
The pattern behind these numbers is consistent. Verizon’s 2025 Data Breach Investigations Report found that the human element was involved in 60% of breaches, and that creating a false story to manipulate someone into taking an action — a tactic known as pretexting — overtook phishing as the most common manipulation-based attack for the first time. Impersonation is not peripheral to modern breach activity. It is central to it.
AI Has Changed the Economics of Deception
Generative AI has removed the skill barrier that once limited high-quality impersonation to sophisticated and well-resourced attackers. Targeted, convincing content that previously took hours to develop and produce can now be generated in minutes. Messages can be personalized to a specific person’s role, relationships, and communication style. Rewriting tools eliminate the awkward phrasing that awareness training traditionally teaches employees to spot.
CrowdStrike’s 2026 Threat Hunting Report shows that voice phishing — attacks conducted by fraudulent phone call to pressure someone into sharing information or taking an access-related action — increased 134% from 2024 to 2025, and the first half of 2026 has already matched the volume recorded in the entire second half of 2025. The threat is not just prevalent. It is still accelerating. An attacker does not need a sophisticated setup: AI tools can produce a convincing voice clone from a short audio sample scraped from a public recording.
Video has introduced similar risks to visual verification. iProov’s 2026 Threat Intelligence Report, drawn from real-world data across iProov’s global security operations, found that AI-generated attacks targeting iOS devices surged 741% in 2025 alone, and that deepfake impersonation has expanded beyond identity verification systems into everyday corporate video calls and workflows. The Ponemon Institute found that 41% of organizations have already experienced deepfake attacks targeting executives. Seeing someone on a video call is no longer reliable proof that the person is who they appear to be.
Mobile devices amplify the problem further. Zimperium’s 2026 Global Mobile Threat Report found that mobile phishing events detected on employee devices grew 380% since January 2025, and that the number of devices where employees clicked a malicious link grew 110% in 2025 compared to the prior year. Text messages reach employees outside managed inboxes, on smaller screens where differences in sender addresses are harder to notice, in environments where security cues are limited.
Every Channel Is Now an Impersonation Channel
The channel no longer defines the attack. The false identity does. A credible email can establish context. A text message can create urgency. A voice call can push toward action. A video can provide false reassurance. A message in a workplace collaboration tool can appear to come from an internal colleague or IT support representative. An impersonation campaign can move across channels, using each interaction to build the trust needed to trigger an authentication event.
Microsoft documented a 2026 campaign in which an attacker impersonated IT support through persistent voice phishing in a collaboration environment, targeting multiple employees across a sustained period. The campaign illustrates the shift: the support workflow itself becomes the lure when an attacker can convincingly play the role of the people employees expect to trust.
Verizon’s 2026 Data Breach Investigations Report found that mobile-centric attacks involving fake texts and voice calls achieved a success rate 40% higher than traditional email phishing — a directly reported finding. Security programs cannot treat email filtering as the primary boundary between employees and impersonation. Any channel employees use to communicate and verify identity is a channel attackers will use to deceive.
Why Traditional Defenses Are Falling Behind
Email filtering can block known malicious infrastructure and suspicious attachments, but it has little to work with when a message is well written, contextually accurate, sent from a compromised legitimate account, or followed up by a voice call. Caller verification helps only when the directory and device used for verification are trustworthy — which cannot be assumed when caller identity can be faked. Video confirmation is no longer a reliable trust signal when video can be synthesized in real time.
Awareness training is necessary but cannot carry the full weight of defense. Asking employees to serve as the final detection layer against real-time AI voice cloning and AI-generated video in a high-pressure executive impersonation scenario sets up an unreliable defense. CrowdStrike’s 2026 Threat Hunting Report found that 79% of attacks to gain initial access were carried out without using malicious software — relying instead on manipulating people and abusing valid access.
The structural problem is that password-based authentication gives a successful impersonation attempt a transferable prize. A password can be revealed in a phone call, entered into a login page while the attacker watches, or surrendered under pressure. Once obtained, it can be reused, used to initiate account recovery, or combined with further manipulation to bypass additional controls. Controls built on recognition — seeing, hearing, or reading something that seems familiar — increasingly confuse familiarity with assurance.
How Photolok by Netlok Changes the Payoff
Photolok by Netlok operates at the identity layer and integrates with platforms such as Okta Workforce. It replaces password-based credentials specifically — it does not claim to eliminate every form of credential or every security risk. Its value in an impersonation scenario is direct: when there is no password for an employee to disclose or enter after being deceived, the attacker’s ability to convert a convincing interaction into account access is materially constrained.
Photo-based authentication. Users identify images from a photo panel rather than entering a password. What makes this more than a visual password is what happens behind the scenes: each photo carries an encrypted code that changes with every login, is tied to the user’s registered device, and requires a server-side access code to validate. Even if an attacker captures or steals the photos, they cannot use them — the encryption and device binding lock them out. An attacker cannot walk away from a convincing phone call or a login page with a reusable password, because there is no password to capture.
1 Time Photo. Users can configure up to five single-use photos for authentication. Once used, that photo is no longer available. Even if an attacker intercepts a login or records a session, the encrypted codes tied to that photo have already expired — there is nothing to capture that can be reused to break in again. This directly addresses the problem that makes stolen credentials so valuable: a credential that cannot be reused has no value once captured.
Duress Photo. Users can configure up to two Duress Photos, randomly selected for display during login. If an employee is pressured or tricked into authenticating by someone impersonating a colleague, executive, or IT staff member, selecting a Duress Photo triggers a real-time alert to security teams the moment it is chosen. The security operations center receives a real-time distress signal while the person doing the coercing sees a normal login. This matters because the employee may not always be in a position to safely challenge or refuse the person on the other end of the call, meeting, or message. Security architecture should account for that reality — and this is a capability that passwords, passkeys, and biometrics do not provide.
For CISOs, the strategic shift is this: stop asking whether every employee can detect every convincing impersonation, and start asking what an attacker obtains when one gets through. If the answer is a reusable password, the architecture still rewards deception. Photolok removes that reward.
The Bottom Line
AI has industrialized impersonation. It has made fraudulent requests sound more natural, arrive through more channels, and adapt faster than static controls can track. The prevalence data now reflects that reality: the majority of large organizations encounter executive impersonation, phishing and fraud are the most reported cybercrime category, and $3 billion in losses flow through business email compromise every year.
The answer is not to assume every impersonation can be detected before an employee encounters it. It is to ensure a convincing impersonation cannot be converted into access. Photolok removes passwords from the identity layer, replacing them with a credential type that cannot be handed over in a phone call, entered into a fraudulent login page, or captured and reused — and gives security teams a real-time signal when someone is authenticating under duress.
Deepfakes don’t need your password. But as long as passwords exist, they are one convincing phone call away from being handed over.
Request Your Personalized Demo
About the Author
Kasey Cromer is Director of Customer Experience at Netlok.
Sources
[1] Outtake. ‘2026 State of Digital Risk Report.’ June 2026. outtake.ai
[2] Outtake. ‘2026 State of Executive Impersonation.’ July 2026. outtake.ai
[3] World Economic Forum. ‘Global Cybersecurity Outlook 2026.’ January 2026. weforum.org
[4] Anti-Phishing Working Group. ‘Phishing Activity Trends Report Q1 2026.’ May 2026. apwg.org
[5] FBI Internet Crime Complaint Center. ‘2025 Internet Crime Report.’ 2026. ic3.gov
[6] Verizon. ‘2025 Data Breach Investigations Report.’ May 2025. verizon.com/business/resources/reports/dbir
[7] Verizon. ‘2026 Data Breach Investigations Report.’ May 2026. verizon.com/business/resources/reports/dbir
[8] CrowdStrike. ‘2026 Threat Hunting Report.’ August 2026. crowdstrike.com
[9] iProov. ‘Threat Intelligence Report 2026.’ April 2026. iproov.com
[10] Ponemon Institute. ‘Deepfake Attacks Targeting Executives.’ 2026. ponemon.org
[11] Zimperium. ‘2026 Global Mobile Threat Report.’ July 2026. zimperium.com
[12] Microsoft. ‘Help on the line: How a Microsoft Teams support call led to compromise.’ March 2026. microsoft.com
[13] Netlok. ‘How Photolok Works.’ netlok.com
Kasey Cromer, Netlok | August 4, 2026
Executive Summary
For years, enterprise security programs have been built around protecting human logins. The assumption was straightforward: secure the accounts your employees use, and you secure the organization. That assumption is now dangerously out of date. Non-human identities — the API keys, service accounts, AI agents, bots, and automation credentials that connect every system, integration, and workflow in a modern enterprise — now outnumber human identities by ratios as high as 144 to 1 in cloud-native environments, according to Entro Labs’ NHI & Secrets Risk Report H1 2025. They grew 44% in total number year over year, while the ratio of machine identities to human identities increased by 56% — reflecting that human identity growth did not keep pace. And unlike human identities, non-human identities are largely under-governed.
The gap between how many machine identities exist and how well they are managed has become one of the most consequential blind spots in enterprise security. Attackers have noticed. When a stolen API key can grant persistent, silent access to cloud infrastructure, data stores, and downstream systems — without triggering the alerts that a compromised human account would — machine identity compromise offers something passwords never could: long-term, invisible access that looks exactly like normal operations.
Photolok by Netlok does not manage machine identities directly. But it addresses the most common door attackers use to reach them: the human login. By eliminating passwords at the identity layer, Photolok removes the starting point most sophisticated attackers use to move into the machine identity environment.
The Scale of the Problem
Most CISOs know that non-human identities exist in their environment. Few know how many there actually are. Entro Labs’ NHI & Secrets Risk Report H1 2025 found that in cloud-native environments — organizations built primarily around cloud infrastructure — non-human identities outnumber human identities at a ratio of 144 to 1, up from 92 to 1 just one year earlier. Across the broader enterprise, specialized identity research from the NHI Management Group — an independent industry body unaffiliated with Entro Labs — estimates the ratio at 25 to 1 to 50 to 1, with variation driven by cloud adoption, the number of cloud software subscriptions, and how aggressively organizations have deployed automation.
A significant portion of those identities are invisible to security teams. Orchid Security’s Identity Gap 2026 Snapshot, based on data from enterprise environments across North America and Europe, found that 67% of non-human identities are created directly within applications by developers, vendors, or automated systems — outside of any central identity provider, and without formal onboarding or assigned ownership.
Every new cloud software subscription, cloud service, automation workflow, and AI agent adds more machine credentials. According to GitGuardian’s State of Secrets Sprawl 2026 report, 28.65 million new passwords, API keys, and tokens written directly into code were added to public GitHub repositories — online storage systems where developers keep code — in 2025 alone, a 34% year-over-year increase and the largest single-year jump ever recorded. Internal repositories, the same report found, are roughly six times more likely to contain these embedded credentials than public ones, meaning the total exposure across any organization is considerably larger than what appears in public data.
Why Machine Identities Stay Vulnerable
Human identity programs have mature playbooks: onboard through HR, assign a manager, conduct access reviews, offboard when an employee leaves. Non-human identities were never designed to fit that model. They are created by developers to make an integration work, by operations teams to run an automated task, by vendors during implementation. They rarely have an accountable owner, are almost never included in termination workflows, and do not expire with employee turnover.
The practical consequence is a growing backlog of forgotten, ownerless, and over-privileged accounts. Some are temporary connections that outlived their original purpose. Others are permanent integrations that were never properly scoped or maintained. In either case, the access they carry has never been reviewed, reduced, or reassigned — leaving organizations with a population of active accounts that no one is watching.
The governance gap is compounded by the fact that non-human identities frequently bypass the controls that protect human accounts. They do not have multi-factor authentication (MFA) — the step that requires a second form of verification beyond a password. They are not bound to a specific device. They operate continuously, often with permissions that would immediately raise flags if a human account held the same level of access. Specialized identity research from the NHI Management Group’s 2026 Infrastructure Identity Survey found that 70% of organizations grant AI systems more access than they would give a human employee performing the exact same job.
How Embedded Credentials Fuel Machine Identity Compromise
The primary way attackers gain access to non-human identities is through the uncontrolled spread of passwords, API keys, and tokens written directly into code and shared across collaboration tools — what the industry calls secrets sprawl. When a developer writes an API key directly into a script or shares a service account token in a Slack channel, that credential can persist indefinitely, valid and exploitable long after the original need has passed.
GitGuardian’s State of Secrets Sprawl 2026 report makes the scale concrete. Of secrets confirmed as valid in 2022, 64% were still valid and exploitable as of January 2026 — meaning credentials have been sitting in public code for four years without being rotated or revoked. That persistence is what makes secrets sprawl strategically valuable to attackers. A credential does not need to be fresh to be useful. It needs to be valid.
The problem extends beyond source code. The same report found that about 28% of credential leak incidents originate entirely outside repositories, in collaboration and productivity tools such as Slack, Jira, and Confluence. The reason this happens is rarely deliberate. Developers work in tools built for speed and collaboration, not security review. There is no automatic warning when a password is pasted into a Slack message or a key is written into a script. By the time the exposure is discovered — if it is discovered at all — the credential has often been sitting in plain sight for months or years.
From Human Login to Machine Identity: How Attackers Move
While machine identities are a compelling target on their own, most sophisticated attackers begin with a human account and then move into machine identity space. Compromising a human account gives an attacker the ability to discover machine credentials — finding API keys in code repositories the employee has access to, extracting tokens from settings files, or creating new service accounts using administrative privileges. Once they control a machine identity, they can operate silently, because their activity looks like authorized automation rather than a human intruder.
Verizon’s 2025 Data Breach Investigations Report found that credential abuse was the leading initial access method, present in 22% of analyzed breaches. CrowdStrike’s 2024 Threat Hunting Report documented how adversaries exploit legitimate human credentials to reach cloud environments, then abuse connections between different systems to access additional infrastructure. The pattern is consistent: a human login is compromised, and machine identities are what attackers reach for next.
The reason is straightforward. A compromised machine identity often offers more value than a compromised human account. Machine identities run continuously. They hold system-level permissions across services, data stores, and infrastructure layers. They rarely trigger alerts because their activity does not look anomalous. And when their credentials persist for years without being updated, a single exposed API key can provide access long after the original breach has been forgotten.
AI Agents Are Accelerating the Problem
The rise of agentic AI in 2025 and 2026 has multiplied the non-human identity surface significantly. Every AI agent deployed in an enterprise is another machine identity — one that authenticates using credentials, accesses data and systems, and often operates with more access than necessary. Microsoft Copilot Studio users have collectively created more than one million AI agents, yet only 44% of organizations have implemented any oversight rules for them, according to the 2026 Infrastructure Identity Survey. GitGuardian’s 2026 data shows AI-service credentials as one of the fastest-growing leak categories, up 81% year over year. When AI agents share keys across multiple applications, a single exposed credential can grant access across an entire agent fleet.
How Photolok by Netlok Addresses the Gap
Photolok by Netlok operates at the identity layer and focuses on the human side of this problem. It does not manage API keys, service accounts, or machine tokens directly. Instead, it hardens the human login so attackers cannot use compromised credentials as a bridge to machine identities.
Photo-based authentication. Users identify images from a photo panel rather than entering a password. What makes this more than a visual password is what happens behind the scenes: each photo carries an encrypted code that changes with every login, is tied to the user’s registered device, and requires a server-side access code to validate. Even if an attacker captures or steals the photos, they cannot use them — the encryption and device binding lock them out. There is no static secret to phish, no password database to raid, and no captured image that can be reused to break in.
1 Time Photo. Users can configure up to five single-use photos for authentication. Once used, that photo is no longer available. Even if an attacker intercepts a login or records a session, the encrypted codes tied to that photo have already expired — there is nothing to capture that can be reused to break in again. This directly addresses the persistence problem that makes stolen credentials so valuable: a credential that cannot be reused has no value in the markets where stolen secrets are traded.
Duress Photo. Users can configure up to two Duress Photos, randomly selected for display during login. If an employee with access to critical systems is pressured into authenticating under coercion, selecting a Duress Photo triggers a real-time alert to security teams the moment it is chosen. The security operations center receives a real-time distress signal while the person doing the coercing sees a normal login — a capability that passwords, passkeys, and biometrics do not provide.
For CISOs working to reduce non-human identity risk, the most immediate leverage point is the human login. When attackers cannot easily compromise human credentials, their ability to discover and weaponize machine identities is substantially reduced. Photolok offers a way to harden that layer at the identity level, without requiring any change to the cloud platforms, AI systems, or machine identity infrastructure running behind it.
The Bottom Line
The gap between how many non-human identities exist and how well they are governed is one of the fastest-growing attack surfaces in 2026. Machine identities outnumber human identities at 144 to 1 in cloud-based environments, up from 92 to 1 just one year earlier, and at 25 to 1 to 50 to 1 across the broader enterprise. 64% of credentials confirmed valid in 2022 are still exploitable today. AI agents are multiplying this surface faster than oversight programs can absorb. And 67% of non-human identities were never visible to security teams in the first place.
Attackers do not need to invent a new technique to exploit this. They need a valid human login, and the path to machine identities is often wide open. Photolok closes that first door — eliminating the password most attackers use as their starting point — and gives security teams a real-time signal when someone is authenticating under duress.
The identities you cannot see are the ones attackers are counting on you to ignore.
Request Your Personalized Demo
About the Author
Kasey Cromer is Director of Customer Experience at Netlok.
Sources
[1] Entro Labs. ‘NHI & Secrets Risk Report H1 2025.’ July 2025. entro.security
[2] NHI Management Group. ‘How Many NHIs Does a Typical Enterprise Have?’ May 2026. nhimg.org
[3] NHI Management Group / Teleport. ‘2026 Infrastructure Identity Survey.’ 2026. nhimg.org
[4] Orchid Security. ‘Identity Gap: 2026 Snapshot.’ May 2026. globenewswire.com
[5] GitGuardian. ‘State of Secrets Sprawl 2026.’ March 2026. gitguardian.com
[6] GitGuardian. ‘State of Secrets Sprawl 2025.’ March 2025. gitguardian.com
[7] Verizon. ‘2025 Data Breach Investigations Report.’ May 2025. verizon.com/business/resources/reports/dbir
[8] CrowdStrike. ‘2024 Threat Hunting Report.’ 2024. crowdstrike.com
[9] Netlok. ‘How Photolok Works.’ netlok.com
Kasey Cromer, Netlok | July 15, 2026
In 2026, the most consequential cyberattacks are not breaking down digital walls. They are walking through digital doors left open by a single compromised login. IBM’s X-Force Threat Intelligence Index 2025 (IBM X-Force) found that critical infrastructure organizations accounted for 70% of all attacks IBM X-Force responded to in 2024. The systems that keep hospitals running, payments clearing, and power flowing are not peripheral targets anymore. They are the primary ones.
What connects nearly every one of these incidents is not a sophisticated exploit. It is a login. Attackers may use many different technical paths to reach a critical system, but they almost always need a working login to turn access into real-world impact. For security leaders across healthcare, finance, energy, public services, and logistics, that makes login security the place where infrastructure risk concentrates. Photolok by Netlok is built to remove the credential type attackers rely on most to make that move.
The reason stolen login information leads the way is straightforward: it is the easiest path. Attackers do not need to find a software flaw or engineer an elaborate deception. They use credentials that are already available — bought, stolen, or guessed — and walk in through the front door.
AI is speeding up every stage of an attack, from the first scouting of a target to breaking in to maintaining long-term access. It is helping attackers find and exploit the weaknesses organizations already have, particularly around weak logins and unpatched systems.
The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 87% of organizations identify AI-related vulnerabilities among their fastest-growing cyber risks. IBM X-Force found that login theft occurred in roughly 30% of analyzed incidents in 2024, driven by a surge in phishing campaigns that deliver malware designed to steal saved passwords. Together, these findings show AI speeding up a pattern that already existed, rather than introducing something entirely new.
For critical infrastructure operators, this means the same AI tools used to generate convincing phishing against a finance team or a hospital’s billing department can just as easily target the administrators and engineers who control access to grid consoles, claims systems, or logistics platforms. The business process differs by sector. The underlying tactic does not: steal the login, and the rest of the access follows.
Critical infrastructure is no longer a secondary concern. It is the focus. IBM X-Force reports that critical infrastructure organizations accounted for 70% of all attacks IBM X-Force responded to in 2024 — most of the real-world incidents IBM’s responders handled that year were directed at organizations whose services underpin health, finance, energy, logistics, or public administration.
This concentration of attacks is not limited to one type of adversary. Financially motivated groups and state-aligned actors both recognize that disrupting or extorting critical infrastructure produces an outsized payoff for the effort it takes. When a hospital’s clinical systems, a payment clearing engine, or an energy scheduling platform goes down, the organization’s tolerance for downtime is extremely low — and that low tolerance is exactly what makes these environments so attractive to attackers, regardless of who is behind them.
Across regulated industries, the systems that matter most tend to be the oldest and hardest to change — core banking platforms, electronic health record systems, grid backends, and public-sector case management systems were often built for reliability long before AI-accelerated threats became the norm.
TXOne Networks’ 2024 Annual Industrial Cybersecurity Report, based on a Frost & Sullivan survey of 150 C-suite executives, shows how this plays out in the systems that run physical equipment, such as power plants and water treatment facilities. Two findings stand out. First, 85% of organizations do not conduct regular software updates on these systems, with most updating quarterly or less often. Separately, 85% say outdated systems limit their ability to apply timely security updates at all — and within that group, one-third have no security software protecting these devices, only 22% know exactly what devices are connected to their network, and 41% still use factory-set passwords that were never changed.
The connection between office networks and plant systems compounds this exposure. The TXOne Networks’ report found that 94% of organizations encountered at least one security incident involving their industrial systems in the past 12 months, and office network breaches played a role in 98% of those cases — 68% through direct penetration and 30% through collateral damage, where an office-side incident spilled over into plant operations, usually with a login acting as the bridge.
This research is framed around industrial systems, but the structural pattern holds across regulated sectors broadly: outdated platforms, infrequent updates, and login boundaries that are easier to cross than they should be.
As network defenses have improved, attackers have rationally shifted toward stealing logins as the easiest, most scalable way to reach high-impact systems. Instead of battering down firewalls, they log in using valid credentials, tokens, and administrator-level access that already belong to people the organization trusts.
Verizon’s 2025 Data Breach Investigations Report confirms this shift directly. Across all types of breaches analyzed, stolen login information was the most common way attackers first got in, present in 22% of cases — ahead of exploiting software flaws at 20% and phishing at 16%. When looking specifically at attacks targeting websites and web-based systems, the figure is even starker: 88% of those breaches involved stolen passwords. The 22% reflects the full picture across all attack types; the 88% reflects how dominant stolen credentials are within that specific category.
IBM X-Force findings point in the same direction: roughly 30% of the incidents IBM responders analyzed in 2024 involved attackers going after someone’s login directly rather than hunting for a software flaw first, because that route was simpler and more reliable. For regulated organizations whose operations depend on logging in securely — claims adjudication, payment approvals, clinical orders, grid operations, case management — this makes the login the main point of control. The system behind that login may be cloud-based or decades old. Once a valid login is compromised, the sophistication of the technology behind it matters far less than the breadth of access that login carries.
AI is changing not just how attackers find systems, but how they steal the logins that guard access to those systems. AI tools make it straightforward to craft highly tailored phishing emails that impersonate executives, internal systems, or trusted vendors, at a level of personalization static templates never achieved.
IBM X-Force ties the rise in login theft directly to a surge in phishing emails that deliver malware designed to steal saved passwords. This malware quietly harvests browser-stored passwords and other saved login information, which is then sold or reused to log into business systems and admin dashboards.
Remote identity checks are under similar pressure. iProov’s Threat Intelligence Report 2025 documents a sharp increase in AI-generated video and image attacks and face-swap attempts during 2024, driven by widely available AI tools. Attackers no longer need custom-built tools — they can combine off-the-shelf deepfake tools and virtual cameras to fool identity checks at scale, directly relevant wherever remote contractors are granted high-level access based on identity checks performed at a distance.
The net effect is that the traditional pillars of authentication — something you know, something you have, something you are — are all being eroded by AI’s ability to simulate, steal, or bypass them.
Modern critical infrastructure runs on ecosystems, not single organizations. Cloud platforms, software providers, and equipment vendors all play a role in keeping these systems running, and every one of those relationships introduces outside logins with access to internal systems.
Verizon’s 2025 DBIR shows how much this is amplifying breach impact. The share of breaches involving a third party rose from 15% in the prior year to 30% in the 2025 dataset — nearly one in three breaches now involves a third party somewhere in the chain. The risk an organization faces is no longer limited to its own systems. It includes every login in the extended ecosystem that can reach critical services, from a vendor admin account to a service provider’s remote access credential.
Photolok by Netlok operates at the identity layer. It does not claim specialized industrial system integrations or control over the equipment behind those systems. Instead, Photolok focuses on the human side of critical infrastructure: the people who log in to access high-value systems, whether those systems are core banking platforms, clinical applications, energy scheduling portals, or public-sector case management tools.
Photo-based authentication. Users identify images from a photo panel rather than entering a password. What makes this more than a visual password is what happens behind the scenes: each photo carries an encrypted code that changes with every login, is tied to the user’s registered device, and requires a server-side access code to validate. Even if an attacker somehow captures or steals the photos, they cannot use them — the encryption and device binding lock them out. There is no static secret to phish, no password database to raid, and no captured image that can be reused to break in.
1 Time Photo. Users can configure up to five single-use photos for authentication. Once used, that photo is no longer available. Even if an attacker intercepts a login or records a session, the encrypted codes tied to that photo have already expired — there is nothing to capture that can be reused to break in again.
Duress Photo. Users can configure up to two Duress Photos, randomly selected for display during login. If an employee with high-level access to a critical system is pressured into authenticating under coercion, selecting a Duress Photo triggers a real-time alert to security teams the moment it is chosen. The security operations center receives a real-time distress signal while the person doing the coercing sees a normal login — a capability that passwords, passkeys, and biometrics do not provide.
For organizations managing critical infrastructure, the strategic question is not whether login security matters. The research from IBM, Verizon, WEF, and TXOne makes that clear. The real question is how much residual risk is still tied to passwords sitting in front of the systems that matter most. Photolok offers a way to reduce that risk at the identity layer, without requiring any change to the industrial systems, core banking, clinical, or public-sector platforms behind it.
The pattern across this research is consistent. AI is not inventing new ways to attack critical infrastructure. It is making an old and reliable tactic — stealing login information — faster, more convenient, and easier to scale. Critical infrastructure organizations accounted for 70% of the attacks IBM’s responders handled in 2024. Stolen login information remains the top way attackers get in, according to Verizon’s 2025 DBIR. And outdated systems across nearly every regulated sector share the same structural weaknesses: hard to update, closely connected to broader office networks, and reachable through logins that span multiple systems.
When the system that fails is a power grid, a hospital network, or a payment platform, the consequences are not abstract. They are operational and immediate. Photolok removes passwords from the login process, replacing them with a credential type that is inherently resistant to phishing, reuse, and large-scale password theft, and gives security teams a real-time signal when someone is authenticating under duress.
Critical infrastructure does not get breached by a sophisticated exploit nearly as often as it gets logged into by someone who should never have had access in the first place.
Request Your Personalized Demo
About the Author
Kasey Cromer is Director of Customer Experience at Netlok.
Sources
[1] IBM. ‘X-Force Threat Intelligence Index 2025.’ April 2025. ibm.com
[2] World Economic Forum. ‘Global Cybersecurity Outlook 2026.’ January 2026. weforum.org
[3] TXOne Networks. ‘2024 Annual OT/ICS Cybersecurity Report.’ March 2025. txone.com
[4] Verizon. ‘2025 Data Breach Investigations Report.’ May 2025. verizon.com/business/resources/reports/dbir
[5] iProov. ‘Threat Intelligence Report 2025: Remote Identity Under Attack.’ 2025. iproov.com
[6] IBM. ‘Cost of a Data Breach Report 2024.’ July 2024. ibm.com/reports/data-breach
[7] Netlok. ‘How Photolok Works.’ netlok.com
Kasey Cromer, Netlok | June 16, 2026
In 2026, phishing is no longer a numbers game. For years, attackers relied on volume — sending millions of generic emails and hoping enough would land. AI has changed the economics entirely. Attackers can now generate convincing, role-specific, context-aware phishing campaigns in minutes, personalize them at industrial scale, and execute credential theft before most security teams have time to respond. According to Microsoft’s 2025 Digital Defense Report, AI-generated phishing emails achieve a 54% click-through rate compared to 12% for traditionally written messages — a 4.5x increase that is a direct ratio of those two reported figures, not a separate metric. That is not a marginal improvement. It is a fundamental shift in the threat landscape.
For security leaders, the question is no longer just how to stop every malicious message from reaching a user. It is what an attacker gains if one gets through. If the answer is a reusable credential, the organization has left the most valuable thing attackers are after fully exposed. Photolok by Netlok is built to eliminate that exposure at the identity layer — removing the password from the equation entirely so the phishing threat changes fundamentally.
Phishing has always been an identity problem disguised as a messaging problem. The email is the vehicle. The credential is the prize. AI has dramatically improved how the attack is delivered, but the underlying objective has not changed: gain access to an environment by stealing, reusing, or manipulating identity.
For years, the quality of a phishing attack depended on attacker investment. A generic mass campaign was cheap but unconvincing. A well-crafted spear phishing email — one that targets a specific person using their role, language, and business context — required significant research and skill. AI collapses that tradeoff. An attacker can now use publicly available data from LinkedIn, company websites, and prior breach exposure to build credible, personalized lures at scale. A fake invoice referencing a real vendor. A message from the apparent CFO in the correct internal tone. A support request timed to coincide with a system outage. These are no longer exclusive to sophisticated nation-state actors. They are accessible to any attacker willing to use the tools now widely available.
Microsoft’s 2025 Digital Defense Report described AI-assisted phishing as “the most significant change in phishing over the last year.” The 54% click-through rate on AI-generated messages, compared to 12% for traditional campaigns, reflects a difference in precision rather than volume. AI enables attackers to localize content, match a recipient’s role and communication style, and reduce the friction that causes users to pause and question whether a message is legitimate.
KnowBe4’s 2025 Phishing Threat Trends Report adds important context. The report found that the vast majority of polymorphic phishing attacks — campaigns designed to vary their content across messages to evade pattern-based detection — utilize AI. This means attackers are not simply writing better messages. They are using AI to ensure that filters and security teams see each message as something new, preventing signature-based detection from catching the wave before it reaches users.
Verizon’s 2026 Data Breach Investigations Report analyzed more than 22,000 confirmed breaches across 145 countries. Across those breaches, 62% involved a human element, credential abuse appeared in 39% — not just as the way attackers first get in, but as a recurring factor at every stage of the breach — and social engineering was the primary pattern in 16% of cases. These figures overlap; a single breach can be counted in more than one category.
IBM’s 2025 Cost of a Data Breach Report found that phishing was the most common way attackers gained initial access, responsible for 16% of breaches studied, and that phishing-related breaches carried an average cost of $4.8 million. That number belongs in the boardroom. Phishing is not a threat an organization can afford to treat as routine. It is a financial risk with direct relevance to cyber insurance, business interruption, and regulatory exposure.
Microsoft’s 2025 Digital Defense Report offers a telling data point on where the money goes when identity is compromised. Looking specifically at incident response investigations where outcomes were clearly identified, business email compromise — fraud in which attackers impersonate a trusted executive, supplier, or finance contact to manipulate payments or access — appeared more often than ransomware, at 21% (business email compromise) versus 16% (ransomware). Identity is now the primary path to financial fraud, not just operational disruption. These figures come from Microsoft’s own investigation data and are separate from the Verizon DBIR findings cited above.
What connects these findings is a consistent underlying pattern. Whether the entry point is a phishing email, a voice call, or a credential purchased from a prior breach, the outcome attackers are working toward is the same: a valid identity signal that lets them move through an environment looking like a legitimate user. The way attackers get in is evolving. What they are after is not.
What makes AI-powered phishing especially dangerous in 2026 is not only improved message quality. It is speed. The window between a phishing message landing and a successful credential capture has compressed to the point where traditional detection and response assumptions no longer hold.
As email-based phishing defenses have matured, attackers have adapted. Verizon’s 2026 DBIR measured mobile-centric phishing — attacks delivered via voice calls and text messages — for the first time at scale and found a 40% higher median click rate on phone-based attacks compared to email-based phishing simulations. This is not simply a channel shift. It is the next evolution in how attackers pursue the same objective. As organizations build stronger defenses around one technique, attackers move to the environments where users are least guarded, and enterprise controls have the least reach. An employee who would scrutinize a suspicious email may respond instinctively to a text message or voice call without the same level of skepticism.
What follows a successful credential capture is no longer slow. Mandiant’s M-Trends 2026, based on more than 500,000 hours of incident response investigations, found that the median time between initial access and handoff to a ransomware group has collapsed to just 22 seconds. Once phishing delivers a working identity signal, what comes next moves at machine speed. The old security model assumed that detection quality could compensate for occasional prevention failures. In an AI-accelerated phishing environment, that assumption is no longer valid. The time between a prevention failure and attacker action is now measured in seconds.
Most enterprise phishing controls were designed to block malicious content at the edge, then rely on user awareness to catch what slips through. That architecture still matters, but it is under pressure from three directions simultaneously.
First, AI improves message quality enough to defeat many content-based controls. The grammar errors, generic greetings, and off-brand formatting that users were trained to spot are disappearing from AI-generated campaigns. Second, AI increases variation enough to undermine static detection signatures. Filters that block yesterday’s campaign have no reliable signal for today’s. Third, AI reduces attacker cost enough to make high-quality personalization economically viable at scale. The economic barrier that once separated mass phishing from targeted spear phishing no longer exists in any meaningful way.
Microsoft’s data reinforces the severity of the shift. Identity-based attacks rose 32% in the first half of 2025 alone, and the report notes that more than 97% of those attacks were password-based — spray attacks, brute force attempts, and credential stuffing. That figure is important because it reveals the structural weakness that AI-powered phishing is designed to exploit. Passwords exist across every enterprise environment, they are reused, they are exposed in prior breaches, and they are exactly what a convincing phishing email is designed to capture.
Security awareness training remains necessary but is no longer sufficient on its own. Training users to recognize suspicious content is less effective when the content is well-written, context-specific, and timed to match a real business event. AI-generated messages do not ask users to overcome obvious red flags. They ask them to override familiarity. That is a fundamentally harder ask, and no training program was designed to absorb click-through rates of 54%.
The most effective response to AI-powered phishing is not to get better at stopping every malicious message. No organization can guarantee that outcome. The stronger question is what an attacker gains when a message gets through. Photolok by Netlok is a passwordless identity provider that replaces vulnerable, text-based credentials — passwords that can be stolen, guessed, or phished — with photo-based authentication that cannot be extracted or replayed. Photolok integrates with platforms like Okta Workforce and sits at the identity layer beneath all applications, delivering consistent protection across the entire environment.
Photo-based authentication. Users identify images from a photo panel rather than entering a password.Because authentication is based on visual recognition of login photos rather than a password, there is nothing for an attacker to steal, copy, or use to gain access. A successful phishing campaign that captures nothing of operational value does not generate a breach.
1 Time Photo. Users can configure up to five single-use photos for authentication. When a 1 Time Photo is active, only the designated single-use panel appears during login and the user’s standard login photos remain hidden. Once used, that photo is no longer available. Even if an attacker intercepts a login flow or records a session, there is nothing to steal, copy, or use to gain access. There is no pattern for AI to learn and no value in replaying what was observed.
Duress Photo. Users can configure up to two Duress Photos, randomly selected for display during login. If an employee is pressured into authenticating under coercion — a scenario that AI-generated voice clones and deepfake impersonation make increasingly plausible — selecting a Duress Photo triggers a real-time alert to security teams the moment it is chosen. The attacker sees a completed login. The security operations center receives a real-time distress signal. This is a capability that passwords, passkeys, and biometrics do not provide. The Duress Photo protects the person behind the credential, not just the credential itself.
For organizations where AI-powered phishing is generating click-through rates that no awareness program was designed to absorb, Photolok changes the calculus entirely. When there is no password to steal, the campaign has nothing to deliver.
AI has not invented a new threat. It has made an old one significantly faster, more convincing, and harder to stop by filtering messages alone. Phishing remains effective in 2026 for the same reason it has always been effective: identity is the most reliable way to look legitimate inside an enterprise environment. The Verizon 2026 DBIR confirms that credential abuse is present in 39% of all breaches. IBM’s 2025 findings put the average cost of a phishing-related breach at $4.8 million. And Microsoft’s research shows that AI is already achieving click-through rates that fundamentally change the risk equation for every organization.
The strategic response is not to concede the inbox and hope detection catches what gets through. It is to ensure that what gets through has nothing of value to deliver. Photolok replaces traditional credentials at the identity layer, simplifies the login experience for employees, and gives security teams a real-time signal when someone is authenticating under duress.
When there is no password to steal, the speed of the attack is irrelevant.
Request Your Personalized Demo
About the Author
Kasey Cromer is Director of Customer Experience at Netlok.
Sources
[1] Microsoft. ‘Microsoft Digital Defense Report 2025.’ October 2025. microsoft.com
[2] Verizon. ‘2026 Data Breach Investigations Report.’ May 2026. verizon.com/business/resources/reports/dbir
[3] IBM. ‘Cost of a Data Breach Report 2025.’ 2025. ibm.com/reports/data-breach
[4] Mandiant / Google Threat Intelligence Group. ‘M-Trends 2026.’ March 2026. mandiant.com
[5] KnowBe4. ‘Phishing Threat Trends Report, Vol. 5.’ March 2025. knowbe4.com
[6] Netlok. ‘How Photolok Works.’ netlok.com
Kasey Cromer, Netlok | June 9, 2026
In 2026, the most dangerous entry point in your organization is no longer a misconfigured firewall or an unpatched server. It is a phone call, a Microsoft Teams message, or a support ticket. According to Palo Alto Networks Unit 42, social engineering is now the top initial access vector globally, present in 36% of all incidents tracked between May 2024 and May 2025. And once an attacker gains that foothold, they are no longer operating at human speed. Mandiant’s M-Trends 2026 report found that the median time between initial access and handoff to a ransomware operator has collapsed from over eight hours in 2022 to just 22 seconds in 2025. In practice, defenders have seconds, not hours, to detect and respond.
Enterprises are responding by automating the helpdesk entirely. AI-powered support agents now handle a large share of IT requests autonomously. But this shift does not eliminate the social engineering threat. It transforms it. The same manipulation that convinced a human helpdesk agent to reset a multi-factor authentication (MFA) device can now be used to convince an AI agent to do the same thing at machine scale.
The only defense that breaks this cycle permanently is not better training for humans or smarter guardrails for AI. It is removing the credential reset as an attack surface entirely. Photolok by Netlok is built for exactly that outcome.
The IT helpdesk has become one of the most valuable targets for hackers in enterprise security. It sits at the intersection of identity management and operational urgency, with the authority to reset passwords, de-register MFA devices, and provision emergency access. That combination makes it irresistible to attackers.
The playbook is straightforward. An attacker gathers basic information about an employee from LinkedIn, public records, or data exposed in previous breaches. They call the helpdesk pretending to be that employee — a technique known as voice phishing (vishing) — cite an urgent situation, and ask for a credential reset or a new MFA device enrollment. In many organizations, a convincing story and a few verifiable details are enough to get the request approved.
Scattered Spider, the threat cluster responsible for the MGM Resorts breach in 2023, used exactly this technique. An operative impersonated an employee over the phone, convinced the helpdesk to clear active MFA devices, and registered their own phone as the trusted authentication device on the account. That single conversation opened the door to ransomware deployment that cost MGM over $100 million in remediation and lost revenue.
The threat has escalated significantly since then. AI-generated voice clones now allow attackers to match the voice profiles of specific executives with alarming accuracy. Real-time deepfake video wrappers can defeat organizations that require employees to appear on camera during support calls. The Health Sector Cybersecurity Coordination Center has issued specific warnings about campaigns where attackers called hospital helpdesks from localized area codes, presented verified employee data including IDs and dates of birth scraped from prior breaches, and requested credential overrides before security teams could respond.
According to the ISACA 2026 Tech Trends and Priorities report, based on a survey of 3,000 IT and cybersecurity professionals, AI-driven social engineering is now the top cybersecurity threat organizations expect to face, cited by 63% of respondents. This is the first time it has topped the ISACA findings, surpassing ransomware at 54% and insider threats at 35%.
The reason this threat is so persistent is structural. As long as the helpdesk retains the authority to reset credentials, attackers will find a way to exploit it.
Faced with rising ticket volumes and lean security teams, enterprises are moving quickly to automate internal IT support. ServiceNow’s $2.85 billion acquisition of Moveworks and the subsequent launch of its Autonomous Workforce platform represents the most visible signal of this shift. AI specialists now resolve a large share of IT and customer support requests end to end, without human involvement.
This automation delivers real operational value in cost and response time. But it does not eliminate the social engineering attack surface — it simply moves it from the call center to the AI agent’s chat window. When the first responder to a locked-out employee is an AI agent, the attack vector shifts from a voice call to a text string. Prompt injection — embedding hidden instructions inside a message to trick an AI into executing unauthorized commands — is ranked the number one risk in the Open Worldwide Application Security Project (OWASP) Top 10 for Large Language Model Applications, and exploits the same vulnerability that human social engineering does: trust. An AI agent does not get suspicious. It cannot sense that a story sounds wrong. A successful injection exploit requires a carefully crafted text string, and once discovered, it can be replicated across thousands of accounts simultaneously.
The pace of modern attacks makes this especially dangerous. Mandiant’s M-Trends 2026, based on more than 500,000 hours of incident response investigations, found that the median time between initial access and handoff to a ransomware group has collapsed to just 22 seconds. With an AI agent processing requests at machine speed, there is no window for second thoughts.
Solving this requires changing what the helpdesk is allowed to touch in the first place. Organizations that automate their helpdesk without rethinking the credential reset workflow are not solving the problem. They are automating their exposure.
The standard response to helpdesk social engineering has been to train humans to be more skeptical and to engineer AI systems to be harder to manipulate. Both approaches are necessary. Neither is sufficient.
Human awareness training reduces susceptibility but cannot eliminate it. Helpdesk staff are trained to be helpful, and that helpfulness is exactly what attackers exploit. They engineer fabricated scenarios to create urgency and iterate constantly as organizations update their verification procedures.
For AI systems, prompt injection guardrails and input validation are important baseline controls. But the attack surface is enormous. AI helpdesk agents ingest data from support tickets, chat logs, email portals, and knowledge bases — every one a potential injection vector. The OWASP guidance acknowledges that defending against prompt injection comprehensively remains an unsolved problem.
Both approaches share the same flaw: they assume the helpdesk must retain authority to reset credentials. The correct strategic response is to eliminate the target, not to fortify it indefinitely.
The most effective way to break the helpdesk social engineering attack sequence is to eliminate the prize the attacker is hunting. If there is no password to reset, the vishing call has no payload and the prompt injection string has no credential to harvest. Photolok by Netlok is a passwordless identity provider that sits at the identity layer and integrates with platforms like Okta Workforce, replacing passwords with photo-based authentication and removing the fixed credential that helpdesk social engineering is designed to obtain.
Photo-based authentication: Users identify images from a personal photo panel rather than entering a password. Because authentication is based on visual recognition of private images rather than recall of a text string, the most common categories of a helpdesk ticket — forgotten passwords, expired credentials, account lockouts from character errors — are removed from the environment entirely. There is no credential for a social engineer to request, and no reset process to manipulate.
1 Time Photo: Users can configure up to five single-use photos for authentication. When a 1 Time Photo is active, only the designated single-use panel appears during login. Regular photos stay hidden. Once the 1 Time Photo is used, it is immediately invalidated and cannot be reused. Even if an attacker observes a session, records the screen, or uses a remote access tool during a support interaction, the credential captured has no replay value whatsoever.
Duress Photo: Users can select up to two rotating photos with the Duress label. If an employee is pressured into authenticating under coercion, selecting a Duress Photo triggers a real-time alert to security teams the moment it is chosen. The attacker sees a completed login. The security operations center receives an immediate distress signal. If both a Duress Photo and a 1 Time Photo are active, both appear on the first photo panel together.
This last capability addresses something no password, passkey, or biometric system provides. Traditional credentials are passive — they cannot communicate whether the person entering them is acting freely or under duress. Photolok’s Duress Photo gives employees a safe way to signal danger while appearing to comply, matching the real-time velocity of modern attacks.
For organizations deploying AI helpdesk systems, Photolok changes the calculus entirely. When there is no password in the environment, an AI agent has nothing to reset and prompt injection attacks targeting credential workflows lose their operational value.
The helpdesk social engineering threat will not be resolved by incremental improvements to verification procedures or AI guardrails. It requires a structural change to how identity is managed. These steps can move an organization in the right direction.
Social engineering has survived every enterprise defense upgrade for a simple reason: the asset it targets has never changed. As long as there is a credential to reset and a helpdesk with the authority to reset it, attackers will find a way to exploit that process. Better training, stricter verification, and smarter AI all raise the cost of the attack. None of them remove the incentive.
In 2026, with attack handoff times measured in seconds and AI enabling social engineering at industrial scale, organizations cannot afford to keep defending a credential infrastructure that was designed for a different era.
Photolok eliminates passwords at the identity layer, removes the credential reset from the helpdesk workflow, and gives security teams a real-time signal when an employee is authenticating under duress. It does not make the helpdesk more resilient. It makes the helpdesk irrelevant as an attack surface.
The conversation attackers are counting on cannot happen if the elements they are after do not exist.
Request Your Personalized Demo
About the Author
Kasey Cromer is Director of Customer Experience at Netlok.
Sources
[1] Palo Alto Networks Unit 42. ‘2025 Global Incident Response Report: Social Engineering Edition.’ July 2025. unit42.paloaltonetworks.com
[2] Google Threat Intelligence Group / Mandiant. ‘M-Trends 2026.’ March 2026. mandiant.com
[3] ISACA. ‘2026 Tech Trends and Priorities Pulse Poll.’ October 2025. isaca.org
[4] ServiceNow. ‘ServiceNow Completes Moveworks Acquisition.’ December 2025. servicenow.com
[5] OWASP. ‘OWASP Top 10 for Large Language Model Applications.’ January 2026. owasp.org
[6] Health Sector Cybersecurity Coordination Center (HC3). ‘Social Engineering Threats Targeting Healthcare IT Helpdesks.’ 2025. hhs.gov/hc3
[7] CISA. ‘Scattered Spider Threat Advisory.’ 2025. cisa.gov
[8] Netlok. ‘How Photolok Works.’ netlok.com