How AI Is Scaling Credential Theft—and Why Device Trust Matters
On September 8, the Google Threat Intelligence Group (GTIG) published details about an AI-enabled attack that demonstrates how rapidly artificial intelligence is changing the economics of cybercrime.
In one credential-harvesting campaign, attackers first compromised an organization’s cloud infrastructure before building and deploying a multi-agent attack framework. The entire operation took less than six hours and resulted in the compromise of thousands of third-party credentials.
AI also managed parts of the vulnerability-scanning pipeline, troubleshooting problems as they occurred and rotating IP addresses with minimal human intervention.
One of the main benefits of AI for organizations is increased productivity. Unfortunately, threat actors can use the same capabilities to scale attacks more quickly and easily. Credentials are already routinely harvested through information stealers. AI simply reduces the amount of manual work required to carry out these attacks.
As credentials become vulnerable to theft at scale, security teams must ensure that their authentication processes are robust enough to determine whether users and devices connecting to internal networks can be trusted.
AI automates the credential-theft playbook
Microsoft reported in April that AI-powered phishing campaigns achieved click-through rates as high as 54%, compared with approximately 12% for traditional campaigns.
When attackers can make phishing campaigns more convincing without spending proportionally more time creating them, the economics of phishing shift in their favor. This is particularly important for credential theft, which is partly a numbers game. Not every recipient will click, and even compromised accounts may not provide useful access.
AI allows attackers to generate targeted messages faster, adapt them for different languages and industries, and create variations without developing every message from scratch. Improving the success rate at the beginning of the process allows attackers to test more credentials and increases their chances of finding accounts with valuable access.
AI does not need to introduce new ways to steal credentials to change an organization’s risk. Streamlining established attack techniques may be enough.
Verizon’s Data Breach Investigations Report found that 44.7% of breaches involved stolen credentials.
Easily protect your Active Directory with compliant password policies, block more than 4 billion leaked passwords, improve security, and reduce support effort.
How to find compromised credentials in Active Directory
Although AI can make credential theft faster and easier to scale, attackers still benefit from common weaknesses such as weak or reused passwords. Visibility is therefore an important first step. Before security teams can reduce credential exposure, they need to understand where weaknesses exist in their environments.
Specops Password Auditor performs a read-only scan of Active Directory to identify password-related vulnerabilities and highlight user and password policy issues.
The resulting reports give security teams a clearer view of existing credential risks, helping them prioritize the issues that require attention.
Download Specops Password Auditor for free.
Successful authentication does not always mean a request is trustworthy
The threat posed by credential theft is straightforward: stolen credentials allow attackers to use the same access routes as legitimate users. Identity weaknesses played a significant role in 89% of targeted investigations, according to Unit 42’s 2026 Global Incident Response Report. Attackers use stolen credentials and tokens to gain access and move through environments.
When attackers abuse a valid identity, their activity may look less suspicious to defenders. Exploitation attempts and obviously malicious login mechanisms may not be involved.
Attackers can access cloud services, SaaS applications, and other resources through the same authentication processes employees use every day. The credentials may be valid, even when the intent behind their use is malicious.
A key challenge for security teams is that stolen credentials, regardless of where they originated, can provide access that an organization’s authentication systems are designed to accept.
This makes the distinction between authentication and trust important. A correct password, successful MFA response, or valid session can show that authentication requirements have been met. On its own, however, it cannot confirm that the request is coming from a device the organization knows and trusts.
To build an identity security strategy that is more resistant to AI-powered attacks, organizations must ask more than, “Did this user successfully authenticate?” They must also ask, “Which device is requesting access, and should it be trusted?”
Reduce the value of stolen credentials with device trust
Password hygiene can reduce exposure, but no organization can assume that credentials will never be compromised. The prevalence of credential-harvesting malware means attackers may obtain valid authentication material despite preventive controls.
The next question is: What can an attacker do with those credentials?
If authentication is restricted to devices that are authorized and bound to the user’s identity, a valid password alone is no longer enough. An attacker attempting to reuse that password from an unknown device must overcome an additional trust check.
That is the principle behind Specops Device Trust. By binding a user’s identity to a trusted device, access depends on both the user and the device used to sign in. In practice, stolen credentials used from an attacker-controlled machine can be blocked.
These Zero Trust measures are particularly important for today’s blended workforce. BYOD policies span multiple operating systems and endpoint types, making it difficult to implement security controls that cover every device.
Specops Device Trust applies device trust across Windows, macOS, Linux, and mobile devices. This gives security teams visibility into the devices connecting to their networks.
The principle is simple: authenticate the user, verify the device, and require both.
Evolve your identity security strategy with Specops
AI is making credential theft faster and more scalable, making traditional authentication signals alone more difficult to trust. Strong password hygiene remains essential, but organizations must also plan for what happens if valid credentials or tokens fall into the wrong hands.
That means evolving identity security beyond the question, “Did this user authenticate?” Organizations should also verify whether the device is trusted and whether it can remain trusted throughout the session.
Book a demo to see how Specops can help align your identity security strategy with Zero Trust principles by incorporating device trust.
Sponsored and written by Specops Software.
Source: www.bleepingcomputer.com


