
Tim Keary, Contributor
· 1 min read
Why Security Pros Are Still Using Passwords In An Age Of AI Phishing
Security pros are still using passwords despite the security concerns. Today, Yubico and Okta released the 2026 Global State of Authentication report, surveying over 1,800 enterprise security and IT professionals globally, finding that while over 80% are familiar with passkeys, nearly half still log into work accounts with a username and password.
Reliance on passwords is leaving defenders vulnerable to phishing attempts. For instance, the study found that 70% of respondents noted an increase in organizational phishing over the past year, with 55% being targeted by personalized attacks directly.
Across the enterprise, AI tools are making it easier for threat actors to create more convincing scams, while making it harder for employees to use “legacy indicators,” like typos or awkward phrasing, to identify phishing attempts. Yubico and Okta found 44% of respondents experienced an AI-driven attack in the last 12 months, with 39% of security professionals failing to distinguish between AI-generated text and human writing.
The fact that security experts are struggling to identify phishing attempts highlights that difficulties of preventing social engineering breaches in the era of AI. With generative AI tools like ChatGPT and Gemini widely available, it’s easier than ever for attackers to generate phishing emails that can be used as part of social engineering scams to trick employees into handing over sensitive information and credentials.
Passwords And The Attack Surface
Credentials and online accounts have been a key part of the attack surface for years, with threat actors seeing to compromise employee accounts to gain access to sensitive data. Since it was founded in 2007, Yubico has looked to passkeys and multi-factor authentication as an answer to phishing attacks.
Original source
This story was published by Forbes: Innovation and written by Tim Keary, Contributor. SyncAI.news shows a preview; the complete article is on the publisher's site.
Read the full story on forbes.com


