Authra insights

Credential theft is still one of the easiest ways in.

People still reuse passwords, delay MFA, forget which accounts they created, and fall back to unsafe recovery habits. This page tracks the reports, attack trends, and AI shifts that make those habits more dangerous over time.

Back to Authra homeJump to recent reports

Why this matters

  • Password reuse turns one breach into several.
  • No MFA means stolen credentials are often enough on their own.
  • Reset fatigue pushes people into shortcuts, weak storage, and unsafe recovery habits.
  • AI makes fake prompts, fake messages, and fake urgency easier to generate at scale.

Current signals

The numbers still point to identity and password risk.

The exact percentages move year to year, but the pattern keeps repeating: stolen credentials, weak reuse habits, and weak or missing MFA still give attackers a cheap path into accounts.

42,500+

calls to the ACSC hotline

Australia’s ACSC reported more than 42,500 hotline calls in FY2024–25.

1,200+

cyber security incidents

The ACSC responded to more than 1,200 incidents across the same year.

22%

credential abuse initial access

Verizon says credential abuse remains one of the leading initial attack vectors in the 2025 DBIR.

99%

unauthorised access attempts blocked by MFA

Microsoft says MFA blocks the overwhelming majority of unauthorised access attempts on its side.

MFA and safer sign-in

Passwords alone are still too easy to steal, replay, or phish.

Australia’s ACSC calls MFA one of the most effective ways to protect accounts, and recommends phishing-resistant approaches where possible. The practical lesson for users is simple: one secret is no longer enough.

What the ACSC says

The ACSC says MFA is one of the most effective controls available and explicitly warns that password reuse can turn one stolen password into access across several accounts.

ACSC MFA guidanceACSC consumer MFA explainerACSC implementation guidance

What Authra is trying to improve

Authra is built around the idea that sign-in should start with the phone, not with another password prompt. Then higher-value credentials can step up into BLE or NFC only where the user wants more protection.

See the product overviewBrowser plugin for paid users

AI and the threat landscape

AI is changing the speed and quality of attacks, not removing the need for identity controls.

Recent Microsoft and Google security guidance points in the same direction: AI is helping defenders, but it is also helping attackers localise phishing, automate workflows, and move faster through the identity layer.

Attackers are using AI to produce better phishing, social engineering, and attack automation faster than before.

Defenders are also using AI to triage alerts, summarise investigations, and close response gaps faster.

The result is not “passwords stop mattering”. It is the opposite: identity, approval, and phishing resistance become even more important.

Microsoft AI threat postGoogle Cybersecurity Forecast 2026Google AI for Security

Recent reports

Security reading worth tracking.

These are the reports and posts that are most useful for understanding current password, credential, MFA, and AI-driven threat trends without reading generic security fluff.

Australian Cyber Security Centre · October 14, 2025

Annual Cyber Threat Report 2024–25

Australia’s latest threat report shows incident activity, hotline demand, and malicious notifications all moving higher, with credential theft still a practical path into personal and business accounts.

Open source report

Verizon · 2025

2025 Data Breach Investigations Report

The latest DBIR keeps showing the same pattern: stolen credentials, third-party exposure, and unpatched systems are still among the easiest ways for attackers to get in.

Open source report

Microsoft Security · April 2, 2026

Threat actor abuse of AI accelerates

Attackers are using AI to move faster, localise phishing, improve social engineering, and iterate on attacks at a pace that feels more industrial than manual.

Open source report

Google Cloud · November 4, 2025

Preparing for Threats to Come: Cybersecurity Forecast 2026

Google’s threat team expects both attackers and defenders to scale up with AI, which means identity, approval flows, and phishing resistance matter more, not less.

Open source report

Bottom line

The old password habit is not getting safer by itself.

Attackers do not need perfect conditions. They need one reused password, one weak recovery flow, or one account without MFA. That is the gap Authra is trying to close: safer everyday sign-in, cleaner recovery, and optional step-up security when the user wants more than a basic password manager.

Explore AuthraSend feedback
Security Insights, attack trends, and MFA guidance | Authra