TL;DR: 2023 breach patterns kept converging on stolen credentials, password reuse, and MFA bypass, while the average cost of a breach reached $4.5 million, according to IBM and Apple cited by Axiad. Passwordless, phishing-resistant authentication is no longer an edge case; it is the baseline control families now need to close.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Top Data Breaches in 2023 and Why Organizations Need Passwordless, Phishing-Resistant Authentication”.
By the numbers:
- The average cost of a data breach was $4.5 million in 2023, according to IBM research cited by Axiad.
- Data breaches were up by 20% over 2022 in the first nine months of 2023, according to Apple research cited by Axiad.
Key questions
A: Passwords and basic MFA break down when attackers already possess personal data or can intercept one-time codes.
Q: Why do password reuse and credential stuffing remain so effective?
A: They remain effective because many users still reuse passwords and many environments still accept credentials without enough contextual risk checks.
Q: How can security teams tell whether passwordless is actually safer?
A: Look for consistency, not just adoption.
Practitioner guidance
- Prioritise phishing-resistant authentication for high-risk users Move privileged admins, support personnel, and high-value customer accounts to FIDO or certificate-based authentication before broad rollout.
- Remove shared-secret fallback paths Map every recovery, reset, and help-desk flow that can restore access without a phishing-resistant factor.
- Separate genuine passwordless from hidden-password designs Review whether your passwordless stack still stores, recovers, or indirectly depends on a backend secret.
Bottom line: Passwords, reused credentials, and weak MFA remained recurring breach paths in 2023, so authentication design is still a primary control gap.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Password-based authentication has become a breach multiplier, not a control boundary. When breach patterns keep converging on stolen credentials, password reuse, and basic MFA bypass, the issue is no longer user discipline alone. The control assumption that a shared secret can still anchor trust has collapsed, and identity programmes have to treat that collapse as a design problem, not a training problem.
A few things that frame the scale:
- Roughly 1 in 3 phishing payloads are delivered outside email, through channels such as social media, search ads and messaging apps.
A question worth separating out:
Q: What is the difference between adaptive authentication and phishing-resistant MFA?
A: Adaptive authentication changes the challenge based on risk signals such as device, location, or behaviour. Phishing-resistant MFA changes the quality of the factor itself so stolen secrets are harder to reuse. The two controls solve different problems and work best together for regulated identity flows.
👉 Read our full editorial: Passwordless authentication is the real control gap in 2023 breaches