TL;DR: Passwords and SMS-based authentication still dominate, while passkey awareness remains uneven and AI-driven phishing concerns are rising, according to Yubico’s 2025 Global State of Authentication survey of 18,000 employed adults across nine countries. The gap is not technical novelty but user education, inconsistent policy, and weak phishing-resistant coverage across work and personal accounts.
At a glance
What this is: This survey shows that global authentication habits still rely heavily on passwords, SMS, and uneven MFA adoption, even as passkey awareness and phishing fears rise.
Why it matters: It matters because IAM teams cannot reduce account takeover risk or close human authentication gaps if weak methods remain accepted for both personal and work access.
By the numbers:
- 26% of all respondents still believe a simple username and password is the most secure way to protect an account.
- 45% of people who have never used a passkey say they had never heard of them.
- 18% of US respondents use device-bound passkeys for work.
- 71% of respondents in France used MFA for personal accounts this year, up from 29% in 2024.
👉 Read Yubico's 2025 Global State of Authentication survey findings
Context
Authentication is only as strong as the methods users are willing to adopt and organisations are willing to enforce. This survey is about the gap between perceived security and actual phishing resistance, especially where usernames, passwords, SMS, and inconsistent MFA policies still shape access for work and personal accounts.
For IAM leaders, the problem is not just credential theft. It is the persistence of legacy authentication habits, uneven role-based protection, and low passkey familiarity, which together keep account takeover risk high even in organisations that believe they have modernised.
The global pattern is mixed rather than uniformly weak. Some countries are moving quickly toward stronger authentication, but the data shows that awareness, training, and policy consistency still determine whether phishing-resistant methods become the default or remain a niche option.
Key questions
Q: How should organisations roll out passkeys without disrupting existing login flows?
A: Start by adding passkeys alongside current authentication methods, then use adoption and recovery data to decide when to reduce password dependence. The rollout should be phased by user group and application risk, with clear fallback and support paths so users are not forced into brittle recovery journeys.
Q: Why does SMS-based MFA still create account takeover risk?
A: SMS creates risk because the factor travels through a channel that can be redirected through SIM swapping, message interception, or social engineering. It may block low-effort attacks, but it does not provide strong assurance against an attacker who can compromise the phone number or trick the user into sharing the code. That makes it unsuitable for sensitive or privileged access.
Q: What do security teams get wrong about MFA in identity attacks?
A: They often assume MFA ends the problem once the code is entered. In reality, an attacker can still register devices, sustain sessions, and exploit downstream trust if post-authentication controls are weak. MFA helps, but it does not replace continuous authorization, device governance, or review of delegated access.
Q: Should organisations prioritise passkey adoption or remove SMS first?
A: Remove SMS first for high-value accounts, because it preserves a weak recovery and verification path even when stronger options exist. Then expand passkeys and hardware security keys as the default, since adoption works best when the insecure alternative is no longer the easy choice.
Technical breakdown
Why passwords and SMS remain fragile authentication controls
Passwords remain phishable, reusable, and easily harvested through credential stuffing, while SMS-based authentication adds a weak second factor that can still be intercepted, redirected, or socially engineered. In identity terms, both methods depend on shared secrets and user judgment rather than phishing-resistant proof of possession. That is why these controls continue to fail at scale even when users believe they are familiar and convenient. The survey’s core signal is not that authentication has not evolved, but that legacy methods still anchor daily access decisions.
Practical implication: treat passwords and SMS as residual-risk controls, not as acceptable primary protection for high-value accounts.
Passkeys and hardware security keys change the phishing equation
Passkeys and hardware security keys reduce reliance on secrets that users can reveal or reuse. They bind authentication to a device and a cryptographic challenge, which means the user is not copying a password into a form that an attacker can replay later. That is why phishing-resistant MFA is materially different from code-based MFA. Adoption, however, still depends on user education and application coverage, because a strong method that is not understood or not enabled everywhere leaves the same access gap in practice.
Practical implication: prioritise phishing-resistant MFA for all high-risk access paths, then remove fallback methods that weaken the control.
Why role-based inconsistency weakens the whole authentication model
When security differs by role, department, country, or device type, the access model becomes only as strong as the weakest policy boundary. This is not merely an admin problem. It creates an attacker strategy: target the least protected population, then pivot through trusted accounts or shared systems. For IAM and IGA teams, the deeper issue is governance consistency across the joiner-mover-leaver lifecycle and across every account type that can reach business systems. Fragmentation produces exception pathways, and exception pathways become the practical attack surface.
Practical implication: standardise authentication policy by risk tier and remove role-based exceptions that are not explicitly justified.
Threat narrative
Attacker objective: The attacker wants reliable account access that can be reused across services, roles, and devices without triggering strong phishing-resistant controls.
- Entry begins with credential phishing or social engineering that harvests usernames, passwords, or weak second factors from users who trust familiar authentication patterns.
- Escalation follows when attackers replay stolen credentials, abuse SMS-based verification, or exploit inconsistent MFA coverage across work and personal accounts.
- Impact is account takeover, which can lead to fraud, lateral movement, and compromise of both enterprise and personal services from a single weak login method.
Breaches seen in the wild
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
- Replit AI Tool Database Deletion — Replit vibe coding AI assistant deletes live production database and creates 4,000 fake user records.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Passwords are no longer an acceptable strategic control for modern identity programmes: They remain common because they are familiar, not because they are secure. The survey shows that user confidence is still detached from authentication reality, which is exactly why password-heavy programmes continue to underperform. IAM teams should treat this as a governance failure, not a user preference issue.
Phishing resistance only matters when it is universally enforced: A strong method with broad exception handling becomes a partial control, not a security baseline. The article’s country comparisons show that organisations can modernise quickly in one population and still leave large attack surfaces elsewhere. Practitioners should interpret this as a policy consistency problem across the entire access estate.
Passkey adoption is really an education and rollout problem, not a technology-awareness problem: The survey shows that many users have never even heard of passkeys, which means the barrier is operational adoption rather than abstract resistance. That makes authentication modernisation a cross-functional programme spanning IAM, workforce enablement, application teams, and support.
Identity governance now has to account for the human decision layer in authentication adoption: Security leaders cannot assume that better controls will be used just because they are available. The lasting failure mode here is not only credential theft, but inconsistent user trust in the strongest method. The implication is that authentication programmes must be designed around adoption, enforcement, and exception removal together.
From our research:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
- That gap between policy intent and operational control is explored further in OWASP NHI Top 10, which maps the agentic risk surface practitioners need to govern next.
What this signals
Authentication modernisation is increasingly a governance programme, not a feature rollout. The organisations that will reduce account takeover most effectively are the ones that standardise phishing-resistant MFA, remove weak fallbacks, and treat role-based exceptions as temporary risk decisions rather than permanent access design. The pattern is clear in the 2026 Infrastructure Identity Survey, where 70% of organisations grant AI systems more access than they would give a human employee, which shows how quickly access policy drifts when governance is inconsistent.
Phishing-resistant baseline: This is the point at which passkeys, hardware security keys, and consistent MFA enforcement become the default access posture rather than the premium option. For programmes that still depend on passwords and SMS, the practical signal is simple: if a control can be phished, it is not the end state.
IAM teams should expect user enablement and policy enforcement to move together. Where adoption stalls, the blocker is usually not cryptography but workflow friction, helpdesk readiness, or application exceptions that were never retired. The next programme milestone is not broader MFA coverage alone, but removal of the insecure recovery and fallback paths that keep old habits alive.
For practitioners
- Replace password-first access paths Make phishing-resistant MFA the default for all workforce and privileged applications, then remove password-only fallback where business risk justifies the change.
- Eliminate weak second factors from critical workflows Phase out SMS-based authentication for accounts that can reach sensitive data, finance systems, or administrative consoles, and document every remaining exception.
- Standardise authentication by risk tier Apply the same minimum authentication baseline across roles, countries, and device classes unless a formal exception is recorded and reviewed.
- Run a passkey awareness campaign tied to rollout Pair enablement with user-facing education so employees know what passkeys are, why they matter, and how to use them in daily access.
Key takeaways
- The survey shows a clear gap between how secure people feel and how secure authentication actually is.
- Passwords and SMS remain common because they are convenient, not because they are resilient against modern phishing and credential theft.
- IAM teams should focus on consistent phishing-resistant access, because partial rollout and weak fallback paths leave the same attack surface in place.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B | The article centers on authentication assurance and phishing-resistant methods. |
| NIST CSF 2.0 | PR.AC-1 | Authentication policy and access control are the core governance issues in the survey. |
| NIST Zero Trust (SP 800-207) | Phishing-resistant authentication supports continuous trust decisions in zero-trust access. | |
| NIST SP 800-53 Rev 5 | IA-2 | The survey focuses on how users authenticate and how strong the authenticator is. |
Map authentication baselines to PR.AC-1 and remove weak exceptions that undermine consistency.
Key terms
- Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
- Passkey: A passkey is a passwordless credential based on public key cryptography. A private key stays on the user’s device, while a public key is stored by the service. During login, the device signs a challenge after local unlock, which reduces phishing and eliminates shared secret reuse.
- Legacy authentication: Older login or protocol methods that remain in place for compatibility even after stronger controls exist. They often preserve weaker trust assumptions, which makes them attractive to attackers and difficult to defend if they are not tightly scoped and eventually retired.
- Authentication fallback: Authentication fallback is any alternate path used when the primary login method fails, such as recovery codes, help desk resets, or secondary factors. It often becomes the weakest part of the identity stack because attackers target the human process rather than the cryptographic control.
What's in the full report
Yubico's full report covers the operational detail this post intentionally leaves for the source:
- Country-by-country breakdowns of MFA, passkey familiarity, and device-bound authentication adoption.
- Survey methodology across 18,000 employed adults in nine countries, useful for benchmarking your own workforce data.
- Comparisons between personal and work account behaviour that help separate consumer habits from enterprise controls.
- Regional differences in concern about AI-driven phishing, which can inform awareness and training priorities.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org