# Security Leaders Report Confidence as Password Use and AI Attacks Persist

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/28777
Published: 2026-10-09T07:08:02.000Z
Updated: 2026-10-09T07:08:02.000Z
Section: Technology

> Yubico and Okta’s 2026 survey found that 43% still use passwords at work, while 44% experienced at least one successful AI-driven attack.

Security leaders expressed confidence in their organizations’ defenses even as password use, fragmented login systems and successful AI-driven attacks remained widespread in Yubico and Okta’s 2026 Global State of Authentication survey.

The survey covered 1,890 technology and security professionals at companies with at least 500 employees across nine countries, including the United States. It was conducted July 2-16, 2026, and released Oct. 7.

Eighty-eight percent of security leaders expressed confidence in their organizations’ security posture. At the same time, 43% of respondents said they still relied on passwords to log in to work systems.

The authentication gap often began when employees joined their organizations. Fifty-two percent said they received username-and-password credentials when starting their roles. Seventy-six percent said their organizations used fragmented authentication methods across internal applications, while 45% said those systems relied on usernames and passwords.

The survey also found that phishing activity had increased. Seventy percent of respondents reported more organizational phishing during the previous year, and 44% said their organizations experienced at least one successful AI-driven attack.

Impersonation attempts were also common. Forty-three percent reported suspicious video, voice or phone impersonations targeting executives or clients. In a test comparing human- and AI-generated communications, only 36% correctly identified the human-written message.

Passkeys were widely recognized but less widely treated as the strongest option. Eighty-seven percent of respondents were familiar with passkeys, which bind authentication to a legitimate website and resist credential capture by phishing sites. Thirty-one percent considered device-bound, hardware-backed passkeys the most secure credential.

The survey also measured expectations for artificial-intelligence agents. Ninety-one percent of respondents considered verifying an AI agent’s identity essential, including 57% who called it critical. The same 91% wanted human approval before autonomous agents performed high-stakes actions such as changing privileges or handling financial transactions.
