"Identity security is under growing strain," wrote Specops Software in a sponsored analysis of modern account takeover risks.
Verizon: stolen credentials remain a central lever — 44.7% of breaches
That strain is reflected in concrete metrics. Verizon’s Data Breach Investigation Report, cited in the analysis, found that stolen credentials are involved in 44.7% of breaches. The report underscores a persistent reality: credentials, whether phished, harvested by malware, or reused from prior leaks, continue to be the primary foothold for attackers.
How AI compresses attacker effort without inventing new attack classes
Specops frames the effect of artificial intelligence not as the creation of novel attack vectors but as an industrial accelerator for existing techniques. Phishing, credential theft, MFA abuse, session hijacking and social engineering remain the techniques attackers use; AI lowers the labor cost between information gathering and action. Threat actors can now generate and send thousands of convincing phishing messages with little manual effort and use AI to assemble public data into personalized lures tailored to a finance employee, an administrator, or another high-value target. The analysis stresses that humans still choose targets and control infrastructure, but AI lets teams run more campaigns and prioritize accounts with the highest expected value.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadWhy IP reputation, geolocation and MFA are increasingly ambiguous signals
Traditional login signals retain value but are growing easier for attackers to steal, imitate, or bypass. The analysis notes several specific pressure points: one-time MFA codes can be captured through phishing; push notifications can be abused through repeated prompts or social engineering; and adversary-in-the-middle phishing can relay credentials and MFA responses in real time. IP and geolocation signals also carry limits — attackers route traffic through residential proxies, mobile networks or compromised systems, and may place exit nodes close enough to the victim to appear geographically plausible. Conversely, legitimate remote work and corporate VPNs produce unfamiliar locations on a routine basis. The analysis cites NIST’s Zero Trust Architecture guidance, SP 800-207, which advises against granting implicit trust based solely on physical or network location and treats user and device authentication as separate functions.
Device binding, continuous posture and proportional enforcement as a fourth trust layer
To blunt attacks that present otherwise-valid credentials, Specops advocates extending access decisions to include device trust. The report lays out four core elements:
- Tying access to approved hardware — register and limit trusted devices, and apply different policies to corporate, personal and third-party hardware so unknown devices are treated as meaningful changes in risk.
- Continuously evaluating user identity and device health — a successful login should not create permanent session trust; posture changes such as disabled endpoint protection or falling out of compliance should reduce access.
- Matching enforcement to risk — posture checks need not always block access; organizations can reduce privileges or allow short remediation windows so a missing update is not handled the same as a rooted device or disabled endpoint protection.
- Making remediation straightforward for users — self-guided remediation reduces disruption while restoring required security posture.
These measures are presented as ways to make valid credentials insufficient on their own by requiring the device context they were intended to be used from.
The IGN/Restream example and the continuing role of credential leakage
The analysis cites a recent incident in which IGN’s Twitch stream was hijacked using Restream.io credentials that had appeared in infostealer dumps roughly a month earlier. That example illustrates the lifecycle described: credentials harvested by malware or exposed in breaches can remain viable for weeks and be reused by attackers, reinforcing the need for additional trust signals beyond passwords and standard MFA.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: Expect to integrate device posture and continuous evaluation into identity platforms so that authentication decisions combine identity and device context rather than relying on credentials alone.
- Procurement leaders and enterprise IT buyers: Evaluate solutions that can register and differentiate corporate, personal and third-party hardware, and that offer graduated enforcement and user remediation workflows to limit business disruption.
- End users: Be prepared for authentication systems that check device health and provide guided remediation steps if a posture issue reduces access or privileges.
Specops positions device trust as the practical next layer in a Zero Trust approach: not a replacement for MFA or network-based signals, but a way to reduce the effectiveness of AI-assisted, industrial-scale phishing and credential abuse. As login signals become easier for attackers to imitate or relay in real time, the analysis concludes, making credentials insufficient without device context will be the distinguishing control between routine compromise and a blocked takeover.
Read the original analysis: When Credentials Are No Longer Enough: Device Trust in the AI Era




