Site navigation

Does Identity Security Have a “Post-Login” Problem?

Tom Quinn

,

digital identity attacks
As AI stretches identity verification to breaking point, a new study argues trust must be continually re‑evaluated after access is granted.

The explosion in real-time deepfakes and AI‑generated content has broken traditional visual verification systems, a new report from Prove has warned, with our own eyes no match for machine-speed adversaries.

The identity platform’s latest State of Identity Report found that humans can only reliably spot deepfake images and videos 40% of the time, a number likely to fall as technology advances, making verification methods like ID checks, selfies, or videos increasingly unreliable.

AI, of course, is the driving force behind this deception, with 76% of organisations reporting an increase in identity attacks powered by the technology, and 69% fearing it will lead to highly sophisticated social engineering or machine-speed attacks that will weaken identity security.

The study found confidence in traditional safeguards is fading, with 75% of organisations saying they “cannot stop” AI‑enabled phishing attacks, 71% struggling to prevent social‑engineering attempts, and 69% unable to block credential‑stuffing attacks.

Prove said that the volume of identity-focused attacks is evidence of AI’s role in industrialising fraud and leading to unprecedented identity data exposure. 

Since 2022, the year that AI steamed into the public consciousness, 2.2 billion digital identities have been compromised, providing the fuel for personalised attacks and mass credential testing.

But while AI is opening the door, Prove warns that outdated verification systems are leaving persistent gaps that allow attackers to take root and easily exploit the trust process for lateral movement.

“Modern identity failures are not caused by a lack of verification, but by how trust is granted and maintained over time,” said Rich Rezek, head of platform at Prove, in a blog outlining the findings.

“Organisations verify users at key moments, then allow that trust to extend far beyond the conditions under which it was earned…Increasingly, identity doesn’t fail because organisations stop verifying users altogether. It fails because trust has no mechanism to persist and recalibrate as users, devices, and context evolve.”

For example, the study found 68% of firms lack continuous authentication across user journeys, while 70% do not take into account behavioural or device risk data, signals that can detect anomalies in real time.


Recommended reading


Prove said this is creating a critical gap after login, leaving platforms exposed to mid‑session takeovers with no reliable way to detect them.

“Post-login fraud is now one of the most common and costly forms of fraud. Fraudsters take over accounts mid-session or make unauthorised changes while the account is authenticated. Abuse hides behind the appearance of legitimacy,” said Rezek.

Instead, the report argues firms must rethink their identity security, moving away from one‑time or single‑layer methods like OTPs and passwords, and towards continuous systems that use behavioural validation, device intelligence and real‑time risk scoring, where identity is constantly assessed, and trust recalculated at every moment.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data