By NHI Mgmt Group Editorial TeamBased on RSA Security: “Soaring Identity Costs and Stalling Passwordless Progress in Japan: RSA ID IQ Report Unveils Top Identity Threats” (November 5, 2025)

TL;DR: 69% of organisations experienced an identity-related breach in the last three years, a 27-point year-over-year increase, while 45% said breach costs exceeded IBM's benchmark and 24% said losses passed $10M, according to RSA Security's 2026 ID IQ Report. Identity failure is now a governance and cost problem, not just an authentication problem.


At a glance

What this is: RSA Security's 2026 ID IQ Report links rising identity breach frequency and cost with stalled passwordless adoption, especially in Japan.

Why it matters: IAM and security teams should treat identity as a breach-cost control plane, because weak authentication, help desk abuse, and slow passwordless adoption all expand operational and financial exposure.

By the numbers:

  • 69% of global organizations experienced an identity-related breach in the last three years, a 27-percentage-point increase year-over-year.
  • 45% of organizations said that the cost of an identity-related breach exceeded the typical cost of a breach as defined by IBM.
  • 24% of organizations said identity-related breach costs exceeded $10M.
  • 90% of organizations reported challenges in moving toward passwordless authentication.

Context

Identity security now spans more than login friction. When breaches are driven by phishing, help desk abuse, or weak recovery paths, the real failure sits in identity governance, not just in the authentication screen.

RSA Security's report frames Japan as a useful stress test because credential entry remains frequent there and passwordless adoption lags. That makes the article relevant to human IAM, but the governance lesson extends to non-human identities where lifecycle and trust assumptions are equally brittle.

The central issue is not whether passwordless exists in the stack. It is whether identity programmes can reduce standing exposure fast enough to lower both breach likelihood and breach cost.


Key questions

Q: What breaks when passwordless still depends on password recovery?

A: The assurance model breaks because the passwordless front end is undercut by a password-based back door. If recovery, reset, or help-desk escalation reintroduces secrets, attackers can target the weakest exception path instead of the primary login. The programme then reduces friction without eliminating the original credential risk.

Q: Why do help desk hijacks create such high breach costs?

A: Because the attack does not stop at access. Once an attacker uses the support channel to reset credentials or rebind MFA, the organisation must contain authenticated access, review downstream activity, restore user trust, and often reset multiple adjacent accounts. The operational cleanup is what drives cost.

Q: How can IAM teams tell whether passwordless is actually reducing risk?

A: Look for fewer password-related support events, lower exposure to reused secrets, and a narrower attack path for phishing and replay attacks. Also track whether recovery, enrollment, and device replacement are operating cleanly at scale. If those processes are noisy, passwordless may be reducing one risk while creating another.

Q: Who should own account recovery risk in an identity programme?

A: Recovery risk should be owned jointly by IAM, service desk leadership, and security governance. Authentication is not complete until recovery is controlled, so the accountable team must cover the full identity journey, including fallback access, verification rules, and support approvals.


Technical breakdown

Why passwordless stalls when recovery paths stay weak

Passwordless authentication only removes password dependence if account recovery, help desk verification, and fallback authentication are equally controlled. Otherwise, attackers bypass the front door and target the support path, where social engineering, weak identity proofing, or inconsistent approvals recreate the same trust problem. In practice, passwordless projects fail when organisations modernise primary login while leaving recovery channels and escalation rules unchanged. That creates a split control plane: strong user authentication at one layer and weak identity recovery at another. The result is not just user friction but a predictable bypass route for attackers.

Practical implication: govern passwordless together with recovery and help desk workflows, or attackers will simply move to the weaker path.

How help desk hijacks turn identity into a breach-cost problem

Help desk hijacks work because support staff are often authorised to override normal authentication controls after a convincing story or partial identity proof. That makes the help desk part of the trust boundary, not an administrative back office. Once an attacker obtains an account reset, MFA rebind, or credential recovery, they can move from social engineering into authenticated access with little further resistance. The article's emphasis on rising breach costs reflects this shift: the control failure is not just access loss, but the scale of downstream containment, recovery, and business interruption that follows.

Practical implication: treat account recovery and support overrides as privileged workflows with the same scrutiny as admin access.

Why identity breach cost rises faster than breach frequency

Identity incidents become expensive because they collapse access, trust, and recovery into one incident chain. When an attacker uses identity controls to enter, the response usually involves resetting credentials, investigating lateral access, restoring user confidence, and often revalidating many accounts at once. That drives direct response cost and indirect operational disruption. The report's cost figures suggest organisations are still underestimating the blast radius of identity compromise, especially where authentication, federation, and lifecycle controls are managed separately. The expensive part is not the first login failure, but the organisational churn that follows.

Practical implication: measure identity controls by the blast radius they constrain, not by the number of logins they support.


Threat narrative

Attacker objective: The attacker aims to convert a support or authentication weakness into valid account access that can be monetised, expanded, or used for broader compromise.

  1. Entry begins with phishing or help desk social engineering that induces a reset, override, or credential capture through the identity support path.
  2. Credential access follows when the attacker obtains valid login access, an MFA rebind, or a recovered session that bypasses the original authentication control.
  3. Escalation occurs as the attacker uses the newly granted access to move into higher-value systems, privilege-bearing accounts, or broader identity workflows.
  4. Impact is breach disclosure, user account compromise, business interruption, and higher recovery cost because the organisation must trust and rebuild the same identity plane that was abused.
  • MGM Resorts breach 2023: A help desk call gave attackers Okta and Azure admin access at MGM, leading to ransomware, ten days of outages and a $100 million hit.
  • Caesars Entertainment breach 2023: Social engineering of an IT support vendor let attackers copy Caesars loyalty database; about $15 million was reportedly paid.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Help desk recovery is now part of the identity perimeter: RSA Security's findings show that modern identity attacks increasingly target the support path rather than the login box. That matters because passwordless only reduces risk when recovery, re-verification, and override workflows are governed as privileged access. The practitioner conclusion is simple: the control boundary has moved.

Identity breach cost is a governance signal, not just an incident metric: The fact that 45% of organisations saw costs exceed IBM's benchmark and 24% crossed $10M shows that identity compromise now drives material business disruption. This is not just about blocked logins or reset fatigue. It means identity governance needs to be measured by containment and recovery burden, not only by authentication success rates.

Japan's passwordless lag exposes the trust gap between primary authentication and fallback authentication: Frequent credential typing is a symptom of a system where the most common path remains familiar, not necessarily safer. The underlying issue is that organisations often modernise the front-end experience while preserving old fallback assumptions. The practitioner conclusion is that passwordless cannot be evaluated independently of help desk proofing, federation, and account recovery.

Standing recovery authority is the overlooked privilege class: Help desk staff, delegated support vendors, and identity operations teams often hold the practical ability to rebind trust even when they do not appear as privileged users in access reviews. That creates a hidden governance surface across human IAM and third-party operations. Practitioners should treat recovery authority as a distinct privilege domain, not a clerical function.

Passwordless adoption will stall until organisations remove the incentive to bypass it: If users can fall back to weak recovery paths or repeated password entry, the organisation preserves the very behaviours passwordless is meant to eliminate. The consequence is not failure of the technology alone, but of the operating model around it. The practitioner conclusion is to align policy, recovery, and assurance before calling passwordless mature.

From our research library:

What this signals

Recovery-path governance is now the deciding factor in passwordless programmes: The practical question is not whether users can sign in without passwords, but whether every fallback route is more trustworthy than the method it replaces. When recovery remains weak, the organisation has merely displaced the attack surface into support workflows and delegated override paths.

Identity cost pressure is pushing IAM teams to rethink assurance boundaries: Breaches that begin with support abuse or credential replay create disproportionate response effort, because the organisation must re-establish trust across users, devices, sessions, and delegated help desk actions. That makes recovery governance a cost-control issue as much as a security issue.


For practitioners

  • Audit recovery-path trust boundaries Map every account recovery, reset, and MFA rebind workflow to identify where support staff can override authentication without equivalent proofing.
  • Reclassify help desk overrides as privileged actions Require step-up verification, approval logging, and limited delegation for any support action that can restore or alter identity credentials.
  • Measure passwordless alongside fallback use Track how often users are forced back to passwords, resets, or support-mediated recovery, then treat those paths as risk indicators rather than exceptions.
  • Reduce manual password dependence in high-friction environments Prioritise passkeys or other passwordless methods where repeated password entry is driving support calls and user workarounds.

Key takeaways

  • Identity breaches are rising because attackers are increasingly targeting the recovery path, not just the password prompt.
  • The report's cost figures show that identity compromise now has material operational and financial impact, not only access consequences.
  • Passwordless programmes only reduce risk when help desk verification, fallback authentication, and recovery authority are governed as part of the same control plane.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article centres on weak authentication paths and passwordless adoption gaps.
NHI-10 — Human Use of NHIHelp desk and recovery workflows let humans act through identity controls that should be tightly governed.
Recommendation — Harden authentication and fallback paths so passwordless does not leave weak recovery channels exposed. Review who can operate recovery workflows and limit human-initiated overrides to approved cases.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe report discusses passwordless adoption, resets, and credential recovery lifecycles.
Recommendation — Apply authenticator management controls to reduce weak fallback paths and reset abuse.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe issue is who can re-establish access through recovery and support workflows.
Recommendation — Constrain and log recovery entitlements so support actions cannot silently restore trust.
MITRE ATT&CKTA0001;TA0006 — Initial Access; Credential AccessPhishing and help desk social engineering are the attack paths highlighted in the article.
Recommendation — Map support-channel abuse to initial access and credential access so detections cover recovery abuse.

Key terms

  • Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
  • Help Desk Hijack: A help desk hijack is when an attacker uses social engineering to get support staff to reset, re-enrol, or bypass identity controls. The tactic turns operational trust into access, making the support workflow part of the attack surface rather than a neutral service channel.
  • Fallback authentication: Fallback authentication is the secondary method used when the primary sign-in factor is unavailable. For passkey deployments, fallback must be tightly governed because it often becomes the attacker’s preferred route if it remains easier to abuse than the main login path.
  • Recovery governance: Recovery governance is the control structure around password reset, factor reset, and account restoration. It matters because recovery paths often become a weaker security boundary than primary authentication if verification, escalation, and logging are not designed as strict controls.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org