Site navigation

AI Agents to Hasten Account Exposure Exploitation by 50% by 2027

DIGIT

,

ai crime
“In the face of this evolving threat, security leaders should expedite the move toward passwordless phishing-resistant MFA,” said Akif Khan, Gartner VP analyst.

Gartner, the technological research and consulting firm, has predicted that by 2027, AI agents will reduce the time it takes to exploit account exposures by 50%.

“Account takeover (ATO) remains a persistent attack vector because weak authentication credentials, such as passwords, are gathered by a variety of means including data breaches, phishing, social engineering and malware,” explained Jeremy D’Hoinne, who serves as VP analyst at Gartner.

“Attackers then leverage bots to automate a barrage of login attempts across a variety of services in the hope that the credentials have been reused on multiple platforms.”

The research firm highlighted that AI agents will enable automation for more steps in account takeover, from social engineering based on deepfake voices, to end-to-end automation of user credential abuses.

Because of this, vendors will introduce web, app, API, and voice channels to detect, monitor, and classify interactions involving AI agents.

“In the face of this evolving threat, security leaders should expedite the move toward passwordless phishing-resistant MFA,” said Akif Khan, also a VP analyst at Gartner.

“For customer use cases in which users may have a choice of authentication options, educate and incentivise users to migrate from passwords to multidevice passkeys where appropriate.”

Defence Amid The Threat of Social Engineering Attacks

Along with account takeover, technology-enabled social engineering will also pose a significant threat to corporate cybersecurity, the research firm noted, predicting that 40% of social engineering attacks will target executives as well as the broader workforce by 2028.

Attackers are now combining social engineering tactics with counterfeit reality techniques, such as deepfake audio and video, to deceive employees during calls.

Although only a few high-profile cases have been reported, these incidents have underscored the credibility of the threat, and resulted in substantial financial losses for victim organisations.

The challenge of detecting deepfakes is still in its early stages, particularly when applied to the diverse attack surfaces of real-time, person-to-person voice and video communications across various platforms.


Recommended reading


“Organisations will have to stay abreast of the market, and adapt procedures and workflows in an attempt to better resist attacks leveraging counterfeit reality techniques,” added Manuel Acosta, a senior director analyst at Gartner.

“Educating employees about the evolving threat landscape by using training specific to social engineering with deepfakes is a key step.”

DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data