www.infosecurity-magazine.com 7 Oct 2026, 10:15 UTC

Cybersecurity Pros Still Rely on Passwords as AI Phishing Surges

AROUND half of cybersecurity professionals rely on usernames and passwords to access their personal accounts (48%), and this method remains the single most common way to log into work accounts (43%), despite being viewed as one of the least secure options. The findings point to an execution gap in enterprise security, driven by operational friction and outdated onboarding defaults rather than awareness.

Only a minority use device-bound, hardware-backed passkeys (25% for work, 20% for personal accounts) or password managers (24% for work, 30% for personal). A large portion rely on one-time mobile passcodes and SMS-based authentication, methods that have been shown to be vulnerable to interception.

The report from Yubico and Okta also highlights significant fragmentation in authentication: 76% of respondents report mixed methods across internal applications, and 23% say MFA is not mandated across all enterprise services. Over half of surveyed professionals (52%) were issued traditional credentials on starting their roles, underscoring persistent legacy habits.

The same study underscores an AI-driven surge in social engineering: 44% say their organisation experienced at least one AI-powered phishing attack in the past year, with 70% noting an uptick in phishing and 55% targeted by personalised schemes. Deepfake techniques are increasingly used in campaigns, with 43% of organisations reporting suspicious impersonations and 29% directly targeted by deepfake communications.

View full article

Article by CyberSIXT