Kasey Cromer, Netlok | July 15, 2026
In 2026, the most consequential cyberattacks are not breaking down digital walls. They are walking through digital doors left open by a single compromised login. IBM’s X-Force Threat Intelligence Index 2025 (IBM X-Force) found that critical infrastructure organizations accounted for 70% of all attacks IBM X-Force responded to in 2024. The systems that keep hospitals running, payments clearing, and power flowing are not peripheral targets anymore. They are the primary ones.
What connects nearly every one of these incidents is not a sophisticated exploit. It is a login. Attackers may use many different technical paths to reach a critical system, but they almost always need a working login to turn access into real-world impact. For security leaders across healthcare, finance, energy, public services, and logistics, that makes login security the place where infrastructure risk concentrates. Photolok by Netlok is built to remove the credential type attackers rely on most to make that move.
The reason stolen login information leads the way is straightforward: it is the easiest path. Attackers do not need to find a software flaw or engineer an elaborate deception. They use credentials that are already available — bought, stolen, or guessed — and walk in through the front door.
AI is speeding up every stage of an attack, from the first scouting of a target to breaking in to maintaining long-term access. It is helping attackers find and exploit the weaknesses organizations already have, particularly around weak logins and unpatched systems.
The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 87% of organizations identify AI-related vulnerabilities among their fastest-growing cyber risks. IBM X-Force found that login theft occurred in roughly 30% of analyzed incidents in 2024, driven by a surge in phishing campaigns that deliver malware designed to steal saved passwords. Together, these findings show AI speeding up a pattern that already existed, rather than introducing something entirely new.
For critical infrastructure operators, this means the same AI tools used to generate convincing phishing against a finance team or a hospital’s billing department can just as easily target the administrators and engineers who control access to grid consoles, claims systems, or logistics platforms. The business process differs by sector. The underlying tactic does not: steal the login, and the rest of the access follows.
Critical infrastructure is no longer a secondary concern. It is the focus. IBM X-Force reports that critical infrastructure organizations accounted for 70% of all attacks IBM X-Force responded to in 2024 — most of the real-world incidents IBM’s responders handled that year were directed at organizations whose services underpin health, finance, energy, logistics, or public administration.
This concentration of attacks is not limited to one type of adversary. Financially motivated groups and state-aligned actors both recognize that disrupting or extorting critical infrastructure produces an outsized payoff for the effort it takes. When a hospital’s clinical systems, a payment clearing engine, or an energy scheduling platform goes down, the organization’s tolerance for downtime is extremely low — and that low tolerance is exactly what makes these environments so attractive to attackers, regardless of who is behind them.
Across regulated industries, the systems that matter most tend to be the oldest and hardest to change — core banking platforms, electronic health record systems, grid backends, and public-sector case management systems were often built for reliability long before AI-accelerated threats became the norm.
TXOne Networks’ 2024 Annual Industrial Cybersecurity Report, based on a Frost & Sullivan survey of 150 C-suite executives, shows how this plays out in the systems that run physical equipment, such as power plants and water treatment facilities. Two findings stand out. First, 85% of organizations do not conduct regular software updates on these systems, with most updating quarterly or less often. Separately, 85% say outdated systems limit their ability to apply timely security updates at all — and within that group, one-third have no security software protecting these devices, only 22% know exactly what devices are connected to their network, and 41% still use factory-set passwords that were never changed.
The connection between office networks and plant systems compounds this exposure. The TXOne Networks’ report found that 94% of organizations encountered at least one security incident involving their industrial systems in the past 12 months, and office network breaches played a role in 98% of those cases — 68% through direct penetration and 30% through collateral damage, where an office-side incident spilled over into plant operations, usually with a login acting as the bridge.
This research is framed around industrial systems, but the structural pattern holds across regulated sectors broadly: outdated platforms, infrequent updates, and login boundaries that are easier to cross than they should be.
As network defenses have improved, attackers have rationally shifted toward stealing logins as the easiest, most scalable way to reach high-impact systems. Instead of battering down firewalls, they log in using valid credentials, tokens, and administrator-level access that already belong to people the organization trusts.
Verizon’s 2025 Data Breach Investigations Report confirms this shift directly. Across all types of breaches analyzed, stolen login information was the most common way attackers first got in, present in 22% of cases — ahead of exploiting software flaws at 20% and phishing at 16%. When looking specifically at attacks targeting websites and web-based systems, the figure is even starker: 88% of those breaches involved stolen passwords. The 22% reflects the full picture across all attack types; the 88% reflects how dominant stolen credentials are within that specific category.
IBM X-Force findings point in the same direction: roughly 30% of the incidents IBM responders analyzed in 2024 involved attackers going after someone’s login directly rather than hunting for a software flaw first, because that route was simpler and more reliable. For regulated organizations whose operations depend on logging in securely — claims adjudication, payment approvals, clinical orders, grid operations, case management — this makes the login the main point of control. The system behind that login may be cloud-based or decades old. Once a valid login is compromised, the sophistication of the technology behind it matters far less than the breadth of access that login carries.
AI is changing not just how attackers find systems, but how they steal the logins that guard access to those systems. AI tools make it straightforward to craft highly tailored phishing emails that impersonate executives, internal systems, or trusted vendors, at a level of personalization static templates never achieved.
IBM X-Force ties the rise in login theft directly to a surge in phishing emails that deliver malware designed to steal saved passwords. This malware quietly harvests browser-stored passwords and other saved login information, which is then sold or reused to log into business systems and admin dashboards.
Remote identity checks are under similar pressure. iProov’s Threat Intelligence Report 2025 documents a sharp increase in AI-generated video and image attacks and face-swap attempts during 2024, driven by widely available AI tools. Attackers no longer need custom-built tools — they can combine off-the-shelf deepfake tools and virtual cameras to fool identity checks at scale, directly relevant wherever remote contractors are granted high-level access based on identity checks performed at a distance.
The net effect is that the traditional pillars of authentication — something you know, something you have, something you are — are all being eroded by AI’s ability to simulate, steal, or bypass them.
Modern critical infrastructure runs on ecosystems, not single organizations. Cloud platforms, software providers, and equipment vendors all play a role in keeping these systems running, and every one of those relationships introduces outside logins with access to internal systems.
Verizon’s 2025 DBIR shows how much this is amplifying breach impact. The share of breaches involving a third party rose from 15% in the prior year to 30% in the 2025 dataset — nearly one in three breaches now involves a third party somewhere in the chain. The risk an organization faces is no longer limited to its own systems. It includes every login in the extended ecosystem that can reach critical services, from a vendor admin account to a service provider’s remote access credential.
Photolok by Netlok operates at the identity layer. It does not claim specialized industrial system integrations or control over the equipment behind those systems. Instead, Photolok focuses on the human side of critical infrastructure: the people who log in to access high-value systems, whether those systems are core banking platforms, clinical applications, energy scheduling portals, or public-sector case management tools.
Photo-based authentication. Users identify images from a photo panel rather than entering a password. What makes this more than a visual password is what happens behind the scenes: each photo carries an encrypted code that changes with every login, is tied to the user’s registered device, and requires a server-side access code to validate. Even if an attacker somehow captures or steals the photos, they cannot use them — the encryption and device binding lock them out. There is no static secret to phish, no password database to raid, and no captured image that can be reused to break in.
1 Time Photo. Users can configure up to five single-use photos for authentication. Once used, that photo is no longer available. Even if an attacker intercepts a login or records a session, the encrypted codes tied to that photo have already expired — there is nothing to capture that can be reused to break in again.
Duress Photo. Users can configure up to two Duress Photos, randomly selected for display during login. If an employee with high-level access to a critical system is pressured into authenticating under coercion, selecting a Duress Photo triggers a real-time alert to security teams the moment it is chosen. The security operations center receives a real-time distress signal while the person doing the coercing sees a normal login — a capability that passwords, passkeys, and biometrics do not provide.
For organizations managing critical infrastructure, the strategic question is not whether login security matters. The research from IBM, Verizon, WEF, and TXOne makes that clear. The real question is how much residual risk is still tied to passwords sitting in front of the systems that matter most. Photolok offers a way to reduce that risk at the identity layer, without requiring any change to the industrial systems, core banking, clinical, or public-sector platforms behind it.
The pattern across this research is consistent. AI is not inventing new ways to attack critical infrastructure. It is making an old and reliable tactic — stealing login information — faster, more convenient, and easier to scale. Critical infrastructure organizations accounted for 70% of the attacks IBM’s responders handled in 2024. Stolen login information remains the top way attackers get in, according to Verizon’s 2025 DBIR. And outdated systems across nearly every regulated sector share the same structural weaknesses: hard to update, closely connected to broader office networks, and reachable through logins that span multiple systems.
When the system that fails is a power grid, a hospital network, or a payment platform, the consequences are not abstract. They are operational and immediate. Photolok removes passwords from the login process, replacing them with a credential type that is inherently resistant to phishing, reuse, and large-scale password theft, and gives security teams a real-time signal when someone is authenticating under duress.
Critical infrastructure does not get breached by a sophisticated exploit nearly as often as it gets logged into by someone who should never have had access in the first place.
Request Your Personalized Demo
About the Author
Kasey Cromer is Director of Customer Experience at Netlok.
Sources
[1] IBM. ‘X-Force Threat Intelligence Index 2025.’ April 2025. ibm.com
[2] World Economic Forum. ‘Global Cybersecurity Outlook 2026.’ January 2026. weforum.org
[3] TXOne Networks. ‘2024 Annual OT/ICS Cybersecurity Report.’ March 2025. txone.com
[4] Verizon. ‘2025 Data Breach Investigations Report.’ May 2025. verizon.com/business/resources/reports/dbir
[5] iProov. ‘Threat Intelligence Report 2025: Remote Identity Under Attack.’ 2025. iproov.com
[6] IBM. ‘Cost of a Data Breach Report 2024.’ July 2024. ibm.com/reports/data-breach
[7] Netlok. ‘How Photolok Works.’ netlok.com
Critical Infrastructure Isn’t Breached. It’s Logged Into.
Kasey Cromer, Netlok | July 15, 2026 Executive Summary In 2026, the most consequential cyberattac[...more]
AI-Powered Phishing and the Speed of Attack
Kasey Cromer, Netlok | June 16, 2026 Executive Summary In 2026, phishing is no longer a numbers game[...more]
Helpdesk is the Easiest Breach in Your Organization
Kasey Cromer, Netlok | June 9, 2026 Executive Summary In 2026, the most dangerous entry point in you[...more]
Leaner Teams, Smarter Logins: Why Eliminating Passwords Is the Right Move for 2026
Kasey Cromer, Netlok | May 27, 2026 Executive Summary In 2026, security leaders are being asked to d[...more]
When anyone can be faked: Photolok as the identity layer for the AI era
Kasey Cromer, Netlok | May 13, 2026 Executive summary As we move through 2026, the corporate world i[...more]
App Overload: Why SaaS apps and AI Sprawl Are Breaking Enterprise Security
Kasey Cromer, Netlok | April 29, 2026 Executive summary In 2026, most enterprises are running more a[...more]
Identity Crisis: When Attackers Log In Instead of Break In
Kasey Cromer, Netlok | April 10, 2026 Executive Summary Geopolitical escalation reliably coincides w[...more]
Protecting the Person, Not Just the Account
Kasey Cromer, Netlok | March 31, 2026 Executive Summary Traditional authentication was designed to a[...more]
Why Passwords and Biometrics are Failing in 2026
Kasey Cromer, Netlok | March 18, 2026 Executive Summary The identity and authe[...more]