Authra insights
Credential theft is still one of the easiest ways in.
People still reuse passwords, delay MFA, forget which accounts they created, and fall back to unsafe recovery habits. This page tracks the reports, attack trends, and AI shifts that make those habits more dangerous over time.
Why this matters
- Password reuse turns one breach into several.
- No MFA means stolen credentials are often enough on their own.
- Reset fatigue pushes people into shortcuts, weak storage, and unsafe recovery habits.
- AI makes fake prompts, fake messages, and fake urgency easier to generate at scale.
Current signals
The numbers still point to identity and password risk.
The exact percentages move year to year, but the pattern keeps repeating: stolen credentials, weak reuse habits, and weak or missing MFA still give attackers a cheap path into accounts.
42,500+
calls to the ACSC hotline
Australia’s ACSC reported more than 42,500 hotline calls in FY2024–25.
1,200+
cyber security incidents
The ACSC responded to more than 1,200 incidents across the same year.
22%
credential abuse initial access
Verizon says credential abuse remains one of the leading initial attack vectors in the 2025 DBIR.
99%
unauthorised access attempts blocked by MFA
Microsoft says MFA blocks the overwhelming majority of unauthorised access attempts on its side.
MFA and safer sign-in
Passwords alone are still too easy to steal, replay, or phish.
Australia’s ACSC calls MFA one of the most effective ways to protect accounts, and recommends phishing-resistant approaches where possible. The practical lesson for users is simple: one secret is no longer enough.
What the ACSC says
The ACSC says MFA is one of the most effective controls available and explicitly warns that password reuse can turn one stolen password into access across several accounts.
What Authra is trying to improve
Authra is built around the idea that sign-in should start with the phone, not with another password prompt. Then higher-value credentials can step up into BLE or NFC only where the user wants more protection.
AI and the threat landscape
AI is changing the speed and quality of attacks, not removing the need for identity controls.
Recent Microsoft and Google security guidance points in the same direction: AI is helping defenders, but it is also helping attackers localise phishing, automate workflows, and move faster through the identity layer.
Attackers are using AI to produce better phishing, social engineering, and attack automation faster than before.
Defenders are also using AI to triage alerts, summarise investigations, and close response gaps faster.
The result is not “passwords stop mattering”. It is the opposite: identity, approval, and phishing resistance become even more important.
Recent reports
Security reading worth tracking.
These are the reports and posts that are most useful for understanding current password, credential, MFA, and AI-driven threat trends without reading generic security fluff.
Australian Cyber Security Centre · October 14, 2025
Annual Cyber Threat Report 2024–25
Australia’s latest threat report shows incident activity, hotline demand, and malicious notifications all moving higher, with credential theft still a practical path into personal and business accounts.
Open source reportVerizon · 2025
2025 Data Breach Investigations Report
The latest DBIR keeps showing the same pattern: stolen credentials, third-party exposure, and unpatched systems are still among the easiest ways for attackers to get in.
Open source reportMicrosoft Security · April 2, 2026
Threat actor abuse of AI accelerates
Attackers are using AI to move faster, localise phishing, improve social engineering, and iterate on attacks at a pace that feels more industrial than manual.
Open source reportGoogle Cloud · November 4, 2025
Preparing for Threats to Come: Cybersecurity Forecast 2026
Google’s threat team expects both attackers and defenders to scale up with AI, which means identity, approval flows, and phishing resistance matter more, not less.
Open source reportBottom line
The old password habit is not getting safer by itself.
Attackers do not need perfect conditions. They need one reused password, one weak recovery flow, or one account without MFA. That is the gap Authra is trying to close: safer everyday sign-in, cleaner recovery, and optional step-up security when the user wants more than a basic password manager.