For years, the standard security advice has been consistent: use a strong password, turn on two-factor authentication, and your accounts will be protected. That advice was sound. It is also no longer sufficient on its own.

A new wave of AI-powered attack tools is making it faster and cheaper than ever to steal login credentials, intercept two-factor codes, and bypass the traditional signals that security systems use to decide whether a login looks legitimate. The result is a growing gap between what businesses think is protecting them and what is actually holding up under pressure.
What Has Changed
Attackers have always relied on the same basic techniques: phishing emails to steal passwords, malware to harvest credentials, and social engineering to trick employees into handing over access. None of that is new. What AI has changed is the scale and speed at which those techniques can be deployed.
Sending thousands of convincing, personalized phishing emails used to require significant human effort. AI compresses that work dramatically. An attacker can now pull publicly available information about a target, build a detailed profile, and craft a message tailored to that specific person's role, language, and business context, all with minimal manual effort. A finance employee might receive a supplier payment request that matches their real vendor relationships. An IT administrator might receive a cloud access alert that mirrors their actual environment.
The volume of attacks that can be run simultaneously has increased. The cost of personalization has dropped. And the accounts with the highest expected value, executive email, financial systems, remote access portals, are increasingly the primary focus.
Why Traditional Security Signals Are Losing Ground
Identity platforms typically combine several signals to decide whether a login should be trusted. Each of those signals is under pressure.
Passwords remain the foundation of most login flows, but stolen credentials from previous breaches are widely available and actively reused. Earlier this year, a well-known media outlet had its live stream hijacked using credentials that had been sitting in a stolen data dump for roughly a month before anyone used them.
Two-factor authentication adds an important layer, but it is not a complete defense. One-time codes sent by text message can be intercepted. Push notifications can be abused by sending repeated prompts until a fatigued user approves one. Sophisticated phishing attacks can relay both the password and the two-factor code to the real service in real time, completing the login before the victim realizes anything happened.
Location and IP address checks have similar limitations. Attackers route traffic through residential networks and compromised devices to make logins appear geographically normal. With so many employees working remotely and using VPNs, distinguishing a legitimate login from a distant location from a malicious one has become genuinely difficult.
The core problem is that all of these signals can be stolen, spoofed, or worked around. They verify that someone knows the right credentials. They do not verify that the person logging in is actually who they claim to be, or that they are doing so from a device your organization has ever seen before.
The Missing Layer: Device Trust
The security concept gaining traction in response to this shift is called device trust, and the principle behind it is straightforward. Instead of only asking whether someone has the right password and two-factor code, systems that implement device trust also ask whether the login is coming from a device that has been previously registered and approved.
If a correct username, password, and two-factor code arrive from a device the organization has never seen, that combination should raise an alert, not be automatically granted access. Stolen credentials presented from an attacker's machine should not open the same doors they would from an employee's known, managed laptop.
Device trust also introduces the concept of continuous evaluation. A successful login should not create permanent access for the rest of a session. If the device's security posture changes mid-session, such as endpoint protection being disabled or the device falling out of compliance with security standards, the level of access should be reduced accordingly. Trust is earned and maintained, not granted once and forgotten.
This approach aligns with a growing security framework called Zero Trust, which operates on a simple principle: never assume a connection is safe just because it came from the right credentials or the right location. Verify continuously, limit access to only what is needed, and treat every login as potentially suspicious until it has been validated.
Why This Matters for Small Businesses
The principle of device trust is not just a large enterprise concern. Small and mid-sized businesses are frequently targeted precisely because they are assumed to have fewer controls in place. An attacker who successfully steals an employee's credentials and two-factor code faces very little additional friction if there is no device-level check standing between those stolen credentials and full account access.
Remote work has made this more relevant for every business. When employees access company systems from home computers, personal laptops, and mobile devices that the organization has no visibility into, the attack surface grows significantly. A compromised personal device accessing company email or cloud platforms is a risk that password policies and two-factor authentication alone cannot address.
What Your Business Should Be Thinking About Right Now
Review which devices have access to your business systems. If employees are accessing company email, cloud platforms, remote desktop tools, or financial systems from personal or unmanaged devices, that is a risk worth addressing. Knowing which devices are connecting to your environment is the first step toward controlling it.
Treat stolen credential alerts seriously and act on them immediately. If your organization runs a Dark Web Scan and finds employee credentials in breach databases, assume those credentials may already be in use and take action, including password resets and review of recent account activity, before an attacker does.
Move away from SMS-based two-factor authentication where possible. Text message codes are the weakest form of multi-factor authentication and the most vulnerable to interception. Authenticator apps provide meaningfully stronger protection, and hardware security keys are stronger still.
Consider what access controls are in place at the session level, not just at the login screen. Once an employee is logged in, what can they reach? Limiting access to only what each employee genuinely needs for their role reduces the damage that a compromised account can cause.
Work with your IT provider to understand which of your business systems support device-based access controls and whether those controls are currently active. Many modern platforms include these features and simply require configuration to enable them.
The Bottom Line
A password and a two-factor code confirm that someone knows the right information. They do not confirm who is actually sitting at the keyboard or what device they are using. As AI lowers the cost of stealing that information at scale, the businesses that will stay protected are the ones that add device-level verification to their security strategy, rather than relying on credentials alone.
Have questions about your business's current security setup or how to add stronger access controls for your team? Reach out to us — we are here to help.
