cybersecurity

Identity Breaches Hit 72% of Singapore Firms as AI-Driven Identity Risks Escalate, Sophos Finds

A new Sophos survey reveals that 72% of Singapore organisations suffered identity-related breaches in the past year. Human error, weak non-human identity management, and AI-driven attack techniques are increasing cybersecurity risks and recovery costs.

Xcademia Team

Xcademia Research Team

Jul 20, 20267 min read8 views
Share:
Identity Breaches Hit 72% of Singapore Firms as AI-Driven Identity Risks Escalate, Sophos Finds

Identity Security Emerges as the New Cybersecurity Battleground

Identity-based attacks have become one of the most significant cybersecurity threats facing organisations worldwide. A new Sophos survey reveals that identity compromise is no longer a secondary security concern but a primary attack vector that is enabling ransomware, data theft, and financial fraud at an unprecedented scale.

The findings paint a concerning picture for Singapore's business landscape. More than seven in ten organisations in Singapore reported experiencing at least one identity-related security breach over the past year, slightly exceeding the already alarming global average.

As enterprises accelerate digital transformation, cloud adoption, and AI deployment, cybercriminals are increasingly targeting identities rather than traditional network vulnerabilities. The rapid growth of non-human identities, such as service accounts, API keys, machine credentials, and AI agents, is creating a new security challenge that many organisations are struggling to manage.

Sophos Survey Highlights Global Identity Security Crisis

The findings come from a vendor-neutral Sophos survey conducted during the first quarter of 2026. The study gathered responses from 5,000 IT and cybersecurity leaders across 17 countries and 14 industry sectors, covering organisations with between 100 and 5,000 employees.

Key global findings include:

  • 71% of organisations experienced at least one identity-related breach in the past year

  • Organisations suffered an average of three identity-related incidents

  • 5% reported six or more identity breaches

  • 67% of ransomware victims said their attack originated from an identity compromise

  • 73% incurred recovery costs exceeding US$250,000

  • Average recovery costs reached US$1.64 million

These numbers demonstrate how identity attacks have evolved from isolated incidents into persistent and recurring business risks.

info-1

Singapore Organisations Face Elevated Identity Risks

Singapore organisations reported a 72% identity breach rate, slightly above the global average of 71%.

While the difference may appear small, it highlights the growing challenges facing one of Asia's most digitally connected economies. Singapore's extensive adoption of cloud services, digital business platforms, and AI technologies makes identity security a critical area of concern.

The survey found that identity breaches often result in serious business consequences:

  • Data theft affected 49% of victims

  • Ransomware impacted 48%

  • Financial theft occurred in 47% of incidents

These outcomes demonstrate that compromised credentials frequently serve as the starting point for broader cyberattacks.

According to Ross McKerchar, Chief Information Security Officer at Sophos, identity has effectively become the primary attack surface in modern cybersecurity environments.

Why Identity Attacks Are Becoming More Dangerous

Traditional cybersecurity strategies focused heavily on protecting networks, endpoints, and applications. Modern attackers increasingly bypass these defenses by targeting identities.

When attackers successfully compromise an identity, they often gain legitimate access to systems, making detection far more difficult.

Several factors are driving the rise in identity attacks:

Human Error Remains a Leading Cause

The survey found that nearly 43% of identity-related incidents involved employees being tricked into providing credentials.

Common techniques include:

  • Phishing emails

  • Fake login portals

  • Social engineering campaigns

  • Business email compromise schemes

  • Multi-factor authentication fatigue attacks

Even organisations with advanced security tools remain vulnerable when users unknowingly grant access to attackers.

Weak Non-Human Identity Management

A major emerging concern involves non-human identities (NHIs).

NHIs include:

  • API keys

  • Service accounts

  • Application credentials

  • Automation accounts

  • Machine identities

  • AI agent credentials

Weak management of these identities contributed to 41% of reported incidents.

Examples of poor NHI practices include:

  • Hardcoded API keys stored in source code

  • Static credentials that never expire

  • Unused orphaned accounts

  • Excessive privileges

  • Lack of auditing and monitoring

Organisations with weak NHI management were found to be 22% more likely to experience financial theft and spent approximately US$150,000 more on recovery compared to average organisations.

AI Agents Are Creating a New Identity Challenge

One of the most significant findings from the report involves the impact of artificial intelligence on identity security.

As organisations deploy agentic AI systems, AI agents increasingly operate autonomously and interact with applications, cloud environments, and enterprise data.

Each AI agent typically requires credentials and permissions to perform tasks.

The challenge becomes even more complex when AI agents create additional sub-agents, each requiring their own identities and access rights.

According to Sophos, these AI-generated identities can quickly multiply, creating:

  • Credential sprawl

  • Excessive permissions

  • Persistent access risks

  • Reduced human oversight

  • Increased attack opportunities

Many existing identity and access management frameworks were not designed to handle large-scale AI-driven identity ecosystems.

info-2

Visibility and Monitoring Gaps Continue to Expose Organisations

The report highlights another significant issue: insufficient identity monitoring.

Only 24% of organisations continuously monitor for unusual login activity.

More concerning is that more than half review identity activity only every three months or less.

This creates long periods during which attackers can maintain access without detection.

Detection challenges remain widespread:

  • 14% of breached organisations failed to detect their most significant identity attack before damage occurred

  • Many security teams lack real-time identity analytics

  • Privileged access monitoring remains inconsistent

  • Non-human identities often operate without continuous oversight

Without proactive monitoring, attackers can exploit legitimate credentials for extended periods before security teams respond.

Critical Infrastructure Faces the Highest Exposure

The survey found that critical infrastructure sectors experienced the highest rates of identity-related breaches.

Industry breach rates included:

Industry

Breach Rate

Energy, Oil & Gas, Utilities

80%

Federal and Central Government

78%

Overall Global Average

71%

These sectors represent attractive targets because they manage critical services, sensitive information, and large operational environments.

As operational technology environments become increasingly connected to digital systems, identity protection is becoming essential for national resilience and public safety.

Compliance Challenges Correlate with Higher Breach Rates

The survey also uncovered a strong connection between compliance difficulties and security outcomes.

Organisations that reported significant challenges meeting compliance requirements experienced an identity breach rate of 82.4%.

In contrast, organisations with fewer compliance difficulties reported breach rates of 68.3%.

This suggests that organisations struggling with governance, policy enforcement, and security controls may also be less effective at managing identity risks.

Rather than treating compliance as a regulatory obligation alone, many organisations may need to view it as a foundation for stronger identity security practices.

info-3

What Organisations Should Do Next

The findings highlight the urgent need for modern identity security strategies.

Key recommendations include:

1. Strengthen Identity Governance

Implement centralized identity and access management systems that provide visibility across human and non-human identities.

2. Continuously Monitor Authentication Activity

Deploy real-time monitoring for:

  • Suspicious login attempts

  • Privilege escalation

  • Credential misuse

  • Unusual account behavior

3. Improve Non-Human Identity Security

Regularly:

  • Rotate API keys

  • Audit service accounts

  • Remove orphaned identities

  • Apply least-privilege principles

4. Secure AI Agent Deployments

As agentic AI adoption grows, organisations should establish governance frameworks that track AI-generated identities and enforce access controls.

5. Enhance Employee Security Awareness

Because human error remains a leading cause of compromise, continuous security training should focus on phishing resistance, credential protection, and identity verification practices.

The Future of Identity Security

The cybersecurity industry is rapidly moving toward identity-centric security models. Concepts such as Zero Trust, continuous authentication, identity threat detection and response (ITDR), and AI-powered identity analytics are becoming essential components of modern security architectures.

The rise of AI agents will further accelerate the need for stronger identity governance. Security teams must prepare for environments where machine identities vastly outnumber human users and where automated systems create and manage credentials at scale.

Organisations that modernise their identity security strategies today will be better positioned to defend against increasingly sophisticated attacks in the years ahead.

Conclusion

Sophos' latest research highlights a troubling reality: identity-related attacks have become a dominant cybersecurity threat globally and in Singapore. With 72% of Singapore organisations experiencing identity breaches and ransomware increasingly linked to credential compromise, identity security can no longer be treated as a secondary defense layer.

The growing number of non-human identities and AI-driven systems is introducing new complexities that traditional security frameworks were not designed to handle. At the same time, human error, inadequate monitoring, and weak governance continue to create opportunities for attackers.

For organisations navigating the AI era, strengthening identity security, improving visibility, and implementing robust governance controls will be critical to reducing risk, limiting financial losses, and building long-term cyber resilience.

#Cybersecurity#IdentitySecurity#Sophos#Ransomware#AIAgents#ZeroTrust#EnterpriseSecurity#CyberRisk

About the Author

X
Xcademia Team
Xcademia Research Team
Share:
Learn to stop attacks like this oneCybersecurity Engineer Bootcamp: live cohorts enrolling now, Career+ support included.