We have been seeing this shift and evidence in our data for a while now. The attacker doesn’t necessarily need your password anymore. They need something that lets them act as you. It could be a session cookie, OAuth token, refresh token, API key, device authorization, or other identity artifact. MFA can be working exactly as designed while an attacker still ends up holding valid authorization material.
Before, that landed as a warning. Now, it’s a headline.
Anthropic recently published its most detailed threat intelligence report to date, documenting how state-sponsored groups, financially motivated criminals, and lone hacktivists are using AI to run operations that previously took entire teams.
Shortly after, NIST and CISA finalized their own interagency report – federal guidance aimed squarely at stopping attackers from forging, stealing, or replaying identity tokens. This all comes amid the backdrop of the Hugging Face breach from July, where OpenAI models broke out of their designed sandboxes to gain access to the internet, exfiltrate assets, and take full access of at least one server. An autonomous AI attacker chained vulnerabilities together to get into production infrastructure, with a machine on the other end doing the defending, too.
Three institutions, three separate reports, all consistent with one story we’ve been telling on calls since last year: The identity threat playbook has moved past the person logging in. It’s a strange kind of validation when an AI lab and the federal government start describing, in their own words, the exact attack pattern you’ve been talking to customers about since the beginning of the year.
The password isn't the prize anymore
There’s one specific case in Anthropic’s report that’s particularly instructive: GTG-20006, an actor whose tradecraft links to Russian state-nexus espionage, ran a device code phishing campaign that abused the legitimate sign-in flow for cloud email services.
The report states: “GTG-20006 employed a custom toolkit composed of two families of Windows-based implants, a mobile exploitation kit, a credential stealing tool that targets browser password stores, a phishing platform designed to mimic priority targets like government organizations, and an administrative console used to manage compromised accounts.”
No fake login page. No stolen password. The victim signs in exactly the way they always do, MFA clears, and the attacker walks away with the session token issued at the end of that real login. Depending on configuration, that token can keep working for weeks, and in some cases survive a password reset or even MFA re-enrollment.
The investment in passwordless and stronger MFA is real, and it still matters. It just solves for an entry point attackers have largely moved on from. Post-authentication artifacts – session cookies, refresh tokens, forged assertions – are the window left open after you lock the front door. This is why it’s important to understand when the identity artifacts that attackers depend upon have escaped into the criminal ecosystem.
There’s a separate finding from the report that should worry security leaders more. A French-speaking hacktivist, using AI to manage sub-agents that handled reconnaissance and exploitation, gained internal access to at least 14 of 42 targeted organizations. That’s a multi-victim campaign that a year ago needed a staffed team, now run by one person. Anthropic’s own conclusion is this: Sophistication is no longer always a reliable signal of who’s behind an intrusion.
We’ve seen this coming. We now have criminals running armies of agents, some doing reconnaissance, others building phishing kits or testing against defenses, while others still automatically rewrite the kit’s code the moment something trips a detection. They stay a step ahead, and the next attempt doesn’t fail the same way.
Now, imagine the very real scenario of one criminal administrator who has hundreds of AI agents working collectively to do this. The speed at which an average criminal can now build this at scale has lowered the bar tremendously in terms of the level of sophistication that’s involved.
The gaps aren't only human anymore
This is where NIST and CISA’s guidance gets interesting. The agency report is written for federal agencies and cloud providers, but its scope quietly extends to machine-to-machine authentication – tokens used by workloads and automated services, not just people.
But, unlike people, service accounts and API keys don’t get an MFA prompt, so they don’t notice when they’ve been phished. Non-human identity (NHI) isn’t a side conversation to the token-theft problem; it’s the same problem, aimed at an audience that can’t tell you when something’s gone wrong. This bore out in the data from our recent Identity Threat Report, and will continue to be a key storyline as we monitor emerging threats.
What we’re telling customers now
Credential management and MFA is still very important, but certain assumptions have to change. A compromised account isn’t fixed by a password reset if the session token underneath it is still live. NIST agrees – tokens should be short-lived, expired tokens rejected, signing keys rotated. That’s good hygiene, but it assumes you already know a token has been stolen, something most organizations still can’t answer.
That’s not theoretical. This week, SpyCloud Labs’ data helped Microsoft’s DCU, Health-ISAC, and law enforcement take down EvilTokens – the phishing-as-a-service platform that commercialized this exact device code phishing technique.
Our data helped identify more than 8,700 compromised accounts across 79 countries. Most of us have spent the last few years hardening the front door, but once someone’s already inside, you need something that acts on what happens next.
That’s the gap we at SpyCloud think about and monitor every day. While most of the industry spent the last year debating whether this was a real trend, we’ve been collecting data that proves it. If NIST’s report shows agencies where the control gap is, and Anthropic’s shows how fast attackers are moving through it, the question I keep coming back to with customers is simpler: how do you actually know when a specific token in your environment has already been stolen?
See which identity exposures may be tied to your organization
Check your exposure to see what identity threats may already be tied to your organization’s domain.