Enterprise identity theft is a multi-layered crisis that no business can ignore

Last month, Verizon’s 2026 Data Breach Report warned that software flaws had overtaken stolen credentials for the first time. But does that really mean that vulnerabilities are now the biggest security weakness for the enterprise?

Not everyone is convinced, especially following the release of the 2026 Trends in Identity Report from the Identity Theft Resource Center. This found the unauthorised access to devices had increased by 78% year-over-year, now accounting for 27% of all compromises.

Little wonder one chief technology officer cited in the report insisted that identity has most certainly become the new security perimeter.

It gets worse: 26% of victims analysed between 1 April 2025 and 31 March 2026 were managing at least two concurrent identity theft incidents, the report states.

“Identity crimes are no longer isolated, single events, they are becoming increasingly complex,” said Mona Terry, Chief Operating & Programs Officer at ITRC. “A single compromise can trigger a chain reaction that spreads across multiple accounts and institutions, making it much harder for people to recover.”

Enterprise identity theft and AI

When it comes to the root cause of much identity theft, I’m sorry to say that our friend AI rears its head once more.

With AI’s help, once an attacker gets into the phone or laptop they have potential access to logged-in apps, stored credentials, messages, MFA flows, and recovery paths. Which is far more valuable than tricking a victim one account at a time.

“AI-enhanced phishing, malware delivery, voice cloning, and account-takeover techniques, are making it easier to get that foothold and use it quickly,” said Patrick Harr, CEO at DataVisor.

But you would be mistaken for thinking that this is just a consumer issue. It is not.

“Identity has become the new perimeter as businesses and individuals move their entire lives into cloud applications and services,” James Maude, Field CTO at BeyondTrust, told me, “meaning that a compromised identity can provide access to large amounts of data and systems.”

Blurs between professional and personal

Importantly, the lines between personal and professional accounts have become increasingly blurred, which only adds to the enterprise peril. “A user’s personal accounts or devices being compromised can impact their business identity as well,” Maude warned.

Indeed, this has prompted Maude to stress that identity is the new security perimeter.

“Organisations, as well as individuals, are beginning to realise this and better understand and protect their identity attack surface,” Maude said, citing the use of robust MFA controls on all high-value personal accounts as an absolutely basic essential.

“At the organisation level, being able to understand all the paths to privilege an identity has in your environment and proactively reduce those risks is key to success.”

More by Davey Winder

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.