Identity Breaches Hit 72% of Singapore Firms as AI-Driven Identity Risks Escalate, Sophos Finds
A new Sophos survey reveals that 72% of Singapore organisations suffered identity-related breaches in the past year. Human error, weak non-human identity management, and AI-driven attack techniques are increasing cybersecurity risks and recovery costs.
Xcademia Team
Xcademia Research Team

Identity Security Emerges as the New Cybersecurity Battleground
Identity-based attacks have become one of the most significant cybersecurity threats facing organisations worldwide. A new Sophos survey reveals that identity compromise is no longer a secondary security concern but a primary attack vector that is enabling ransomware, data theft, and financial fraud at an unprecedented scale.
The findings paint a concerning picture for Singapore's business landscape. More than seven in ten organisations in Singapore reported experiencing at least one identity-related security breach over the past year, slightly exceeding the already alarming global average.
As enterprises accelerate digital transformation, cloud adoption, and AI deployment, cybercriminals are increasingly targeting identities rather than traditional network vulnerabilities. The rapid growth of non-human identities, such as service accounts, API keys, machine credentials, and AI agents, is creating a new security challenge that many organisations are struggling to manage.
Sophos Survey Highlights Global Identity Security Crisis
The findings come from a vendor-neutral Sophos survey conducted during the first quarter of 2026. The study gathered responses from 5,000 IT and cybersecurity leaders across 17 countries and 14 industry sectors, covering organisations with between 100 and 5,000 employees.
Key global findings include:
71% of organisations experienced at least one identity-related breach in the past year
Organisations suffered an average of three identity-related incidents
5% reported six or more identity breaches
67% of ransomware victims said their attack originated from an identity compromise
73% incurred recovery costs exceeding US$250,000
Average recovery costs reached US$1.64 million
These numbers demonstrate how identity attacks have evolved from isolated incidents into persistent and recurring business risks.

Singapore Organisations Face Elevated Identity Risks
Singapore organisations reported a 72% identity breach rate, slightly above the global average of 71%.
While the difference may appear small, it highlights the growing challenges facing one of Asia's most digitally connected economies. Singapore's extensive adoption of cloud services, digital business platforms, and AI technologies makes identity security a critical area of concern.
The survey found that identity breaches often result in serious business consequences:
Data theft affected 49% of victims
Ransomware impacted 48%
Financial theft occurred in 47% of incidents
These outcomes demonstrate that compromised credentials frequently serve as the starting point for broader cyberattacks.
According to Ross McKerchar, Chief Information Security Officer at Sophos, identity has effectively become the primary attack surface in modern cybersecurity environments.
Why Identity Attacks Are Becoming More Dangerous
Traditional cybersecurity strategies focused heavily on protecting networks, endpoints, and applications. Modern attackers increasingly bypass these defenses by targeting identities.
When attackers successfully compromise an identity, they often gain legitimate access to systems, making detection far more difficult.
Several factors are driving the rise in identity attacks:
Human Error Remains a Leading Cause
The survey found that nearly 43% of identity-related incidents involved employees being tricked into providing credentials.
Common techniques include:
Phishing emails
Fake login portals
Social engineering campaigns
Business email compromise schemes
Multi-factor authentication fatigue attacks
Even organisations with advanced security tools remain vulnerable when users unknowingly grant access to attackers.
Weak Non-Human Identity Management
A major emerging concern involves non-human identities (NHIs).
NHIs include:
API keys
Service accounts
Application credentials
Automation accounts
Machine identities
AI agent credentials
Weak management of these identities contributed to 41% of reported incidents.
Examples of poor NHI practices include:
Hardcoded API keys stored in source code
Static credentials that never expire
Unused orphaned accounts
Excessive privileges
Lack of auditing and monitoring
Organisations with weak NHI management were found to be 22% more likely to experience financial theft and spent approximately US$150,000 more on recovery compared to average organisations.
AI Agents Are Creating a New Identity Challenge
One of the most significant findings from the report involves the impact of artificial intelligence on identity security.
As organisations deploy agentic AI systems, AI agents increasingly operate autonomously and interact with applications, cloud environments, and enterprise data.
Each AI agent typically requires credentials and permissions to perform tasks.
The challenge becomes even more complex when AI agents create additional sub-agents, each requiring their own identities and access rights.
According to Sophos, these AI-generated identities can quickly multiply, creating:
Credential sprawl
Excessive permissions
Persistent access risks
Reduced human oversight
Increased attack opportunities
Many existing identity and access management frameworks were not designed to handle large-scale AI-driven identity ecosystems.

Visibility and Monitoring Gaps Continue to Expose Organisations
The report highlights another significant issue: insufficient identity monitoring.
Only 24% of organisations continuously monitor for unusual login activity.
More concerning is that more than half review identity activity only every three months or less.
This creates long periods during which attackers can maintain access without detection.
Detection challenges remain widespread:
14% of breached organisations failed to detect their most significant identity attack before damage occurred
Many security teams lack real-time identity analytics
Privileged access monitoring remains inconsistent
Non-human identities often operate without continuous oversight
Without proactive monitoring, attackers can exploit legitimate credentials for extended periods before security teams respond.
Critical Infrastructure Faces the Highest Exposure
The survey found that critical infrastructure sectors experienced the highest rates of identity-related breaches.
Industry breach rates included:
Industry | Breach Rate |
|---|---|
Energy, Oil & Gas, Utilities | 80% |
Federal and Central Government | 78% |
Overall Global Average | 71% |
These sectors represent attractive targets because they manage critical services, sensitive information, and large operational environments.
As operational technology environments become increasingly connected to digital systems, identity protection is becoming essential for national resilience and public safety.
Compliance Challenges Correlate with Higher Breach Rates
The survey also uncovered a strong connection between compliance difficulties and security outcomes.
Organisations that reported significant challenges meeting compliance requirements experienced an identity breach rate of 82.4%.
In contrast, organisations with fewer compliance difficulties reported breach rates of 68.3%.
This suggests that organisations struggling with governance, policy enforcement, and security controls may also be less effective at managing identity risks.
Rather than treating compliance as a regulatory obligation alone, many organisations may need to view it as a foundation for stronger identity security practices.

What Organisations Should Do Next
The findings highlight the urgent need for modern identity security strategies.
Key recommendations include:
1. Strengthen Identity Governance
Implement centralized identity and access management systems that provide visibility across human and non-human identities.
2. Continuously Monitor Authentication Activity
Deploy real-time monitoring for:
Suspicious login attempts
Privilege escalation
Credential misuse
Unusual account behavior
3. Improve Non-Human Identity Security
Regularly:
Rotate API keys
Audit service accounts
Remove orphaned identities
Apply least-privilege principles
4. Secure AI Agent Deployments
As agentic AI adoption grows, organisations should establish governance frameworks that track AI-generated identities and enforce access controls.
5. Enhance Employee Security Awareness
Because human error remains a leading cause of compromise, continuous security training should focus on phishing resistance, credential protection, and identity verification practices.
The Future of Identity Security
The cybersecurity industry is rapidly moving toward identity-centric security models. Concepts such as Zero Trust, continuous authentication, identity threat detection and response (ITDR), and AI-powered identity analytics are becoming essential components of modern security architectures.
The rise of AI agents will further accelerate the need for stronger identity governance. Security teams must prepare for environments where machine identities vastly outnumber human users and where automated systems create and manage credentials at scale.
Organisations that modernise their identity security strategies today will be better positioned to defend against increasingly sophisticated attacks in the years ahead.
Conclusion
Sophos' latest research highlights a troubling reality: identity-related attacks have become a dominant cybersecurity threat globally and in Singapore. With 72% of Singapore organisations experiencing identity breaches and ransomware increasingly linked to credential compromise, identity security can no longer be treated as a secondary defense layer.
The growing number of non-human identities and AI-driven systems is introducing new complexities that traditional security frameworks were not designed to handle. At the same time, human error, inadequate monitoring, and weak governance continue to create opportunities for attackers.
For organisations navigating the AI era, strengthening identity security, improving visibility, and implementing robust governance controls will be critical to reducing risk, limiting financial losses, and building long-term cyber resilience.
Source: Frontier Enterprise
About the Author