www.businesswire.com 2026 Identity Security Report Reveals Confidence Gap in Financial Organizations
Article Content
- •82% of IAM leaders in financial services trust their authentication controls despite rising phishing.
- •Only 28% of MFA methods used are phishing-resistant, exposing organizations to account takeover risks.
- •Only 15% of authentication flows are passwordless, with significant barriers to implementing stronger security.
Secret Double Octopus released its 2026 State of Identity Security report, surveying 200 IAM leaders in financial services across the US and Canada. The report highlights a significant confidence gap, with 82% of respondents trusting their authentication controls despite a 94% increase in phishing attacks. Only 28% of their multi-factor authentication (MFA) methods are phishing-resistant, raising concerns about account takeover risks. MFA coverage is fragmented, with 74% for SaaS applications but only 50% for legacy systems. Additionally, only 15% of authentication flows are truly passwordless, and many methods still rely on hidden passwords. The report identifies technical complexity, cost, and legacy system support as major obstacles to implementing phishing-resistant MFA. The findings suggest that financial organizations may be underestimating their vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Secret Double Octopus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…