cardboard robot under screen

When Machines Have Logins

AI agents, fragmented identity systems, and credential theft are converging to create cybersecurity’s next great crisis: a collapse of digital trust.

We used to worry about keeping humans out of systems. Now we’re trying to keep machines from impersonating each other. That’s the paradox facing cybersecurity as AI “agents” start making decisions — and mistakes — on our behalf. At the same time, identity frameworks are fracturing under digital sprawl, and stolen credentials remain the simplest way in. As Gartner’s Lee McMullen warned at RSA Conference, “You can’t uniquely identify an electron.” And yet, that’s exactly what cybersecurity is trying to do.

McMullen wasn’t speaking in hypotheticals. His session, Cybersecurity Isn’t Ready for Agent-Based Systems, described a near future where AI-powered software agents act with real autonomy — launching transactions, approving workflows, even communicating with other agents. It’s a model built on trust, and that’s precisely what makes it so dangerous. “You don’t hack agent-based systems because you don’t have to,” he said. “You just confuse them.”

That confusion has real-world parallels. The 2025 Verizon Data Breach Investigations Report found that credential abuse remains the number one method attackers use to gain access to organizations, showing up in roughly one-fifth of breaches. Info-stealer malware has created an industrial-scale supply chain for stolen logins — 21 billion credentials siphoned in 2024 alone. “We’re still seeing exposed RDP servers and reused passwords in 2025,” said Verizon’s lead data scientist Philip Langois. “Half of ransomware victims had credentials appear in infostealer logs before their attack even began.”

The problem, experts warn, isn’t just that passwords are weak — it’s that identity itself has become fragmented and fragile. In a recent SC Media webcast, Saviynt Field CIO Simon Gooch described identity as “the fabric that binds everything,” yet one increasingly torn apart by hybrid clouds, mergers, and SaaS sprawl. “Legacy IAM systems were never designed for this complexity,” he said. “Fragmentation introduces risk because every inconsistency becomes an exploit waiting to happen.”

As AI systems begin authenticating and interacting on their own, those inconsistencies multiply. Every agent will need a verifiable identity, a permissions model, and a way to communicate securely — all within ecosystems where even human users struggle to keep control. That shift extends the attack surface from people and devices to algorithms themselves. If an attacker can alter an AI agent’s goal, prompt, or policy, they can redirect an entire chain of automated decisions.

The consequences could be subtle or catastrophic. A confused AI underwriting system might misprice risk; a corrupted procurement bot might send payments to an attacker’s account. In both cases, there’s no human to blame — only a machine that “followed its rules.” Accountability breaks down just as automation scales up.

Cybersecurity leaders are already grappling with a version of this problem inside their own networks. Each cloud platform, identity provider, and business unit creates its own trust domain. The result is what Gooch called “identity fragmentation at industrial scale.” Moving to unified, cloud-native IAM systems, he said, isn’t just an operational upgrade — it’s a survival strategy.

Still, unifying IAM won’t be enough on its own. McMullen urged CISOs to start experimenting with “guardian agents” — oversight systems designed to monitor AI behavior and flag anomalies — before agentic architectures become too complex to audit. Others argue the industry must rethink authentication entirely, adopting passwordless frameworks, continuous verification, and AI-driven identity analytics capable of validating both human and machine actors in real time.

None of it will be easy. Even basic security hygiene remains elusive. Verizon’s data shows that 48 percent of users still reuse passwords across multiple accounts, and 46 percent of compromised corporate logins come from unmanaged devices — machines the organization didn’t even know were part of its environment. If today’s security teams can’t protect a human laptop, how will they secure a swarm of autonomous digital workers?

The irony isn’t lost on McMullen. After decades of teaching users to “trust the system,” the system itself has become untrustworthy. “You cannot manage a feedback loop in automation without giving something enough agency to disobey you,” he said. “And once you do that, you’ve given it power.”

In other words: the next generation of cybersecurity may not be about defending networks at all. It may be about teaching machines — and the humans who build them — how to earn trust again.

Total
0
Shares
Previous Article

Autonomous Agents, Fragmented Identities, and the New Crisis of Digital Trust

Next Article

CyberPower Adds Cloud Monitoring for Legacy Power Gear

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading