July 20, 2026
I

The Rise of Login Fraud: Why Identity Has Become Cybercriminals’ Primary Target

As artificial intelligence continues to evolve, cyberattacks are reaching a new level of sophistication. In the enterprise environment, AI is not only accelerating threats—it is also changing how attackers compromise organizations. Rather than exploiting technical vulnerabilities, cybercriminals are increasingly targeting users’ digital identities.

The shift is already measurable. Industry data shows that AI-driven identity fraud now accounts for a significant share of detected fraud attempts, while deepfake-based attacks continue to rise rapidly.

Digital identity theft

This trend is also highlighted in PwC’s Annual Threat Dynamics 2026: Cyber Threats in Motion report, which describes a structural shift in attacker tactics. Instead of breaching systems from the outside, cybercriminals are increasingly logging in using compromised credentials, session tokens, and federated identities, allowing them to bypass many traditional perimeter security controls.

In other words, the goal is no longer to "break down the door," but to enter as though they were legitimate users. This type of login fraud is becoming increasingly common as cloud applications and SaaS platforms host a growing share of business operations. A single compromised identity "can enable cascading access to multiple applications, critical data, and services".

The evolution of these attacks is also reflected in the latest Identity World Economic Forum Fraud Report. Although the global fraud rate declined slightly—from 2.6% to 2.2% between 2024 and 2025—multi-stage attacks increased by 180% year over year, demonstrating that the greatest risk no longer lies in the volume of attacks, but in their ability to adapt and remain undetected.

Compromised credentials and synthetic identities

According to PwC, financially motivated cybercrime remains the primary driver of enterprise threats, with credential theft, digital fraud, ransomware, and attacks targeting cloud environments serving as the leading attack vectors.

However, the threat landscape has moved well beyond stolen usernames and passwords. Attackers now combine artificial intelligence, automation, and social engineering to create synthetic identities, launch highly personalized phishing campaigns, and execute automated credential-stuffing attacks that test millions of stolen credentials across multiple services until valid access is found.

At the same time, PwC notes that threat actors are making AI a core component of their operations. They automate target reconnaissance, generate more convincing phishing lures, accelerate malware development, and scale social engineering campaigns across multiple languages and platforms.

The magnitude of the challenge is also becoming evident in organizations' real-world experience. A global study by Regula found that 87% of companies have already detected attempts to bypass their identity verification processes using AI. Yet only 26% consider this phenomenon to be a strategic business risk, highlighting a significant gap between actual exposure and organizational risk perception.

The blind Spot

(Source: Regula)

Enterprise cybersecurity

In today's environment, protecting identity is no longer simply an operational function—it has become one of the foundational pillars of enterprise cybersecurity.

PwC argues that the most resilient organizations will be those that manage identity strategically, continuously validate trust, and align security with business decision-making.

This trend is forcing organizations to rethink how identity is verified. Validating documents or static credentials is no longer sufficient. Modern systems now incorporate device intelligence, behavioral analytics, contextual signals, and real-time verification to determine whether the entity requesting access is a legitimate user or an automated system designed to impersonate one.

In this context, mobile identity solutions powered by network APIs make it possible to leverage additional signals from the mobile network itself to strengthen authentication and reduce identity fraud without affecting the user experience. Plusmo integrates these capabilities to reinforce real-time identity verification and enhance the security of business operations.

Download PDF
Go Back