Two Futures, One Choice
I. The Wave: A 20-Year Cycle of Digital Identity Theft
Every wave has an origin, a crest, and a decline. The wave we are currently riding began quietly in the mid-2010s, when data breaches were still shocking news. By 2025, that wave had become a tsunami.
Origin (2015–2019): The early years of the data breach economy. Breaches were noisy, public, and relatively unsophisticated. Attackers broke in; they took data; they left traces. Consumers received notifications in the mail. Businesses issued press releases. The wave was visible, and it was manageable.
Acceleration (2020–2024): The pandemic accelerated everything. Remote work expanded the attack surface. Cloud adoption exploded. Identity became the new perimeter—and attackers noticed. By 2024, the wave was building.
Crest (2025–2026): This is where we are now. The wave has crested. Identity-based attacks surged in 2025, accounting for 53% of all detected threats. Phishing-as-a-Service (PhaaS) platforms were responsible for 63% of all account compromise cases.
Globally, 425.7 million user accounts were compromised in 2025—the equivalent of 13.5 accounts every second. The United States accounted for 142.9 million of them, or 34% of the global total, followed by France, India, Germany and Russia. Consumer infection rates surged by over 60% year-over-year.
Where we are now: We are at the crest of the wave. The water is highest. The force is greatest. This is the moment of maximum danger—and maximum opportunity to act.
II. Two Futures
The wave does not have to crash on us. We have a choice. Two futures are possible.
Future One: The Accelerated Collapse
Defences continue to erode. Attackers grow faster. The wave crashes.
This is not a hypothetical. It is the path we are currently on.
In 2025, overall prevention effectiveness dropped to 62% from 69% in 2024. Technology effectiveness fell from 47% to 37%. Process effectiveness dropped from 43% to 35%. Only 3% of data exfiltration attempts were stopped, down from 9% in 2024. Only 14% of attacks generated alerts, meaning most malicious activities went undetected.
Attacks using valid credentials succeeded 98% of the time. Ninety-eight percent. The perimeter is gone. Identity is the new attack surface, and we are not defending it.
OAuth abuse is accelerating at a breathtaking rate. Guardz recorded a 2,000% spike in Google Workspace OAuth abuse between September 2025 and February 2026. OAuth consent events rose 45% between October and January and another 24% from January to February. In a standard 10,000-user organisation, an average of 4,371 connected apps link to both Microsoft 365 and Google Workspace. Thirty-nine percent of Microsoft 365-connected apps are high risk. Seventy-eight percent of Google Workspace apps pose medium risk requiring access to sensitive permissions.
This is not a resource problem. Despite billions spent, defences are getting worse. Ninety-nine percent of organisations say they need more budget, yet effectiveness continues to decline. Something is structurally broken.
In this future, by 2028, 95% of businesses and 87% of consumers will have experienced at least one data breach. By 2031, the number approaches 100%.
Future Two: The Pivot
Defences are rebuilt. The EU Digital Identity Wallet reaches critical mass. MFA becomes universal. The wave is pushed back.
This future is not guaranteed. But it is achievable. And the tools are already here.
The EU Digital Identity Wallet (EUDI Wallet) represents the most ambitious digital identity project in history. By December 2026, every EU member state must offer at least one EUDI Wallet to its citizens. This is not a recommendation. It is a requirement. The regulation establishes the requirements for European Digital Identity Wallets, with conformity certified by accredited bodies.
The adoption trajectory is already visible. Finland already has 98% eID adoption. Norway has 97%. ABI Research forecasts 83 million wallets in circulation by the end of 2025, more than doubling to 169 million in 2026. The foundation is laid.
Microsoft will enable a managed consent policy by default starting July 2026. Users will not be able to consent to third-party applications accessing their files and sites without administrator approval. This signals the severity of the problem. When a platform provider restricts user autonomy at this level, the threat landscape has shifted.
Public awareness is rising. Seven in ten Europeans say they are more concerned about cybersecurity than they were two years ago. Two-thirds believe protecting personal data online is harder than securing their own homes. Cybersecurity is becoming a dinner-table topic. Just over half of Europeans think about it at least weekly.
In this future, high-severity exposure—account takeover, financial fraud, identity theft—remains below 20% indefinitely. The catastrophe is delayed by 2–4 years. And when it arrives, it is a notification—not a life-altering event.
III. The Attack Profile: How They Get In
The attacker’s playbook has changed fundamentally. They are no longer breaking in. They are logging in. Attackers don’t hack in; they log in. This shift is the defining feature of the current threat landscape.
The Modern Attack Chain
Step 1: Phishing as the Entry Point
Spear phishing now represents the majority of phishing activity. The modern attack does not look suspicious. It looks routine. AI has automated the personalisation process—personal details can be scraped and assembled instantly, messaging can be tailored to roles, habits, and relationships, and campaigns can be generated and iterated in real time.
Email-initiated account compromise incidents rose from 36.9% to 55% of total security incidents in 2025. ENISA warns that as of early 2025, over 80% of observed social engineering activity involves using AI in their campaigns.
Step 2: OAuth and Token Abuse
Attackers are increasingly abusing OAuth consent flows and device code phishing to bypass MFA entirely. The credential theft happens through legitimate OAuth infrastructure, with tokens intercepted mid-transit and routed to attacker-controlled callbacks.
In August 2025, a large-scale supply chain attack involving Salesloft’s Drift integration impacted more than 700 organisations. Attackers compromised OAuth tokens to access Salesforce environments, systematically exfiltrating sensitive data. Token theft accounted for 31% of Microsoft 365 breaches in 2025.
Step 3: Account Takeover
Attackers can begin exploiting compromised accounts in as little as 14 minutes. The overall ATO attack rate rose to 2.5% in Q2 2025, marking a 4% year-over-year increase.
Step 4: Persistence and Exfiltration
Once inside, attackers establish persistence through forwarding rules, OAuth tokens, and passkeys. They exfiltrate data, launch follow-on phishing campaigns, and monetise the access through Business Email Compromise (BEC), invoice fraud, and credential resale. The FBI reported $2.8 billion in BEC losses in 2024.
IV. The Scale: What the Numbers Tell Us
Consumers
Global exposure is staggering. In 2025, 425.7 million user accounts were compromised globally—the equivalent of 13.5 accounts every second. Data breaches are no longer isolated incidents but a real threat that has become an integral part of today’s digital environment.
The trend is accelerating. The number of breached accounts tripled in Q1 2026 compared to the same period in 2025 and increased by 22% compared to the last quarter of 2025.
The human cost is real. One in four millennial adults reported being a victim of identity theft in the past year. Nearly a quarter say they have fallen for a phishing attack at home or work in the past 12 months.
Businesses
The corporate landscape is under siege. Ransomware attacks rose 52% in 2025 compared to 2024. Supply chain attacks soared by 93%. Ransomware leak-site disclosures rose 45% to 9,251 cases.
Eighty-nine percent of SMBs monitored by Guardz had at least one user with confirmed credential compromise. Non-human identities—service principals, system accounts, OAuth applications—outnumbered human users by 25:1 in many Microsoft 365 tenants.
The cost is enormous. Cybercrime is projected to cost $10.5 trillion in 2025**, outpacing cybersecurity investment by nearly 50x. The average cost of a ransomware incident is **$4.4 million—over 38 times more than the average ransom demand of $115,000.
V. The Wave’s Drivers: Why We Are Here
Driver 1: The Industrialisation of Cybercrime
Cybercrime has become an industry. Phishing-as-a-Service platforms like Tycoon2FA, FlowerStorm, and EvilProxy offer comprehensive, continuously updated offerings, designed to bypass modern security controls, such as Multi-Factor Authentication. These kits are not simple templates—they are sophisticated, professionally maintained products.
Driver 2: AI as an Accelerant
AI has changed everything. Cybercriminals are often the first to adopt tools like AI to outpace defences and exploit vulnerabilities. Attacks are becoming more personalised, persistent, and technologically advanced. Over 80% of social engineering activity now involves AI.
Driver 3: Identity as the New Perimeter
Identity has become the primary attack surface. Identity-based attacks now account for more than half of all detected threats. Attackers are increasingly targeting valid user accounts instead of relying on software flaws because account compromise usually allows immediate access to several systems and services at once. The perimeter is no longer the network—it is the identity.
Driver 4: The Shift to Stealth
Today’s attacks favour stealth and quality over quantity—smaller numbers of incidents now involve much larger datasets, and a growing share of stolen data circulates through private channels or infostealer logs rather than public forums. The threat is not lessening; it is becoming harder to see.
Driver 5: Defences Are Not Improving
This is the most troubling finding. Across every dimension of cybersecurity—technology, process, and people—effectiveness has eroded significantly. Technology effectiveness dropped 10 points. Process effectiveness lost 8 points. People effectiveness declined 3 points. Ninety-six percent of organisations report incomplete protection. This is not a resource problem. It is a structural one.
VI. Where We Are Heading: The Two Futures
Future One: No Action (Current Trajectory)
| Year | Consumer Cumulative Exposure | Business Cumulative Exposure |
|---|---|---|
| 2025 | 35% | 50% |
| 2026 | 60% | 76% |
| 2027 | 76% | 89% |
| 2028 | 87% | 95% |
| 2029 | 93% | 98% |
| 2030 | 96% | 99% |
| 2031 | 98% | ~100% |
| 2032 | ~99% | ~100% |
By 2028, 95% of businesses and 87% of consumers will have been exposed. By 2031, essentially every business and 98% of consumers. High-severity exposure—account takeover, financial fraud, identity theft—affects nearly half the population.
Future Two: Mass Adoption (The Pivot)
| Year | Consumer Cumulative Exposure | Business Cumulative Exposure |
|---|---|---|
| 2025 | 35% | 50% |
| 2026 | 53% | 70% |
| 2027 | 63% | 80% |
| 2028 | 70% | 85% |
| 2029 | 74% | 88% |
| 2030 | 77% | 90% |
| 2031 | 80% | 92% |
| 2032 | 82% | 93% |
Total exposure is delayed by 2–4 years. But more importantly: high-severity exposure drops by 65–70%. The catastrophe is redefined—from life-altering fraud to a notification.
VII. For Consumers: What You Can Do
Act now. The window is closing.
Critical Actions (0–24 Hours)
Enable Multi-Factor Authentication (MFA). This is the single most effective measure against account takeover. Prioritise authenticator apps or physical security keys over SMS-based codes. If you have not enabled MFA on your primary email, banking, and social media accounts, you are an open door.
Use a password manager. Unique, strong passwords for every account are no longer optional. Password managers generate and store them securely. Credential reuse is how attackers move from one account to another.
Review and revoke OAuth permissions. Regularly check your Google Account and other major online accounts for third-party applications and OAuth tokens. Remove anything you do not recognise, do not remember authorising, or no longer use. Attackers abuse OAuth to maintain persistent access that survives password changes.
Sign out all unknown devices. In your account security settings, select “Sign out all devices” to forcibly terminate any active sessions you do not recognise.
Recommended Actions (1–7 Days)
Migrate to an EU-based email service. Consider Proton Mail (Switzerland), Tuta (Germany), Mailfence (Belgium), or Posteo (Germany). These services are protected by GDPR and offer end-to-end encryption. Your data deserves better than default settings.
Adopt EU-based office and cloud services. Consider OnlyOffice (Latvia), CryptPad (France), or Nextcloud (Germany) for document storage and collaboration. Keep your data within EU jurisdiction.
Update local device security. Ensure your operating systems, applications, and antivirus software are up to date. Run regular malware scans on your computers and phones.
Join the EU Digital Identity Wallet. When available in your country, this is a critical step toward a secure, unified digital identity that can fundamentally reduce the risk of identity theft and account takeover. By December 2026, every EU member state must offer one.
Ongoing Actions (Quarterly)
Check for compromised accounts using services like “Have I Been Pwned.”
Review OAuth permissions and device sessions. Remove unused apps and sign out unknown devices.
Update passwords for critical accounts annually or after any breach notification.
VIII. For Businesses: What You Can Do
The threat is not coming. It is already here.
Identity Infrastructure
Treat identity infrastructure with the same rigor as the network perimeter. Identity-based systems are now the most critical security boundary for most organisations. That means MFA enforcement on both human and non-human accounts, monitoring for risky logins, and auditing exposed credentials in source code and cloud environments.
Assume breach. Attacks using valid credentials succeeded 98% of the time in 2025. “We must operate under the assumption that adversaries already have access,” said Dr Süleyman Ozarslan, co-founder of Picus Security. Your detection and response capabilities must operate at speed.
Monitor for OAuth abuse. OAuth consent abuse surged 2,000% in Google Workspace. Device code phishing is being used increasingly to hijack OAuth tokens because of its phishing-friendly user codes and built-in MFA bypass.
Employee Security
Invest in security awareness that goes beyond “suspicious emails.” The modern attack does not look suspicious. It looks routine. Spear phishing now represents the majority of phishing activity, driven by AI-assisted personalisation and the ease of profiling targets at scale.
Secure the Downloads folder. The Downloads folder is now a primary infection vector, especially in business environments. Users are not being hacked. They are being convinced. Files are delivered through trusted channels, and execution is initiated by the user.
Protect SMBs. Small and mid-sized businesses are being actively targeted, and that targeting is accelerating. Eighty-nine percent of SMBs have at least one user with confirmed credential compromise. Do not assume you are too small to be noticed.
Incident Response
Prepare for the 14-minute window. Attackers can begin exploiting compromised accounts in as little as 14 minutes. Your incident response must be measured in minutes, not hours.
Plan for ransomware. Ransomware incidents increased 45% from 2024 to 2025. The average cost of a ransomware incident is $4.4 million.
Document and drill. The time to plan is now, not when the breach is already in progress.
IX. The EU Context: A Fragmented but Active Threat Landscape
Europe faces a fragmented but highly active cyber threat landscape. The region witnessed over 2,700 cyber incidents across critical sectors including BFSI, Government, Retail, and Energy.
France is a major target—ranked second globally for data breaches in 2025, with 34% of all breaches occurring in the US, followed by France, India, Germany and Russia.
Data is forever. As Surfshark’s Chief Security Officer notes: “For people, a data leak means their personal information is forever on the internet. It’s not a one-time threat that disappears after a user changes their compromised email address and password. It becomes a constant security risk as hackers reuse leaked data, package it into ‘combo lists,’ combine it with new leaks, and resell it repeatedly”.
The EUDI Wallet is the pivot point. By December 2026, every EU member state must offer a EUDI Wallet. This is not optional. It is the single most ambitious digital identity project in history. ABI Research forecasts 169 million wallets in circulation by 2026. The infrastructure is being built. The question is whether we use it.
X. The Price of Inaction
Cybercrime costs are escalating. Global cybercrime costs reached **$10.5 trillion in 2025**. FBI IC3 losses hit $20.9 billion in 2025, a 26% increase from 2024. Financial institution fraud losses are projected to rise by over 150% to more than $55.3 billion by 2030.
But the cost is not just financial. Over three-quarters of consumers (76%) believe that cybercrime will continue to increase and be impossible to slow down because of AI. Sixty-nine percent do not believe their bank or retailer is adequately prepared to defend against AI-driven cyber attacks. More than three in five (62%) who have had their data stolen or exposed did not receive adequate support from the organisation that lost it.
Trust is eroding. Consumers question whether the companies they trust are ready to defend against sophisticated cyber threats. Organisations that fail to protect their customers’ data will face not just regulatory fines but also irreparable reputational damage.
XI. The Window Is Closing
We are at the crest of the wave. The water is highest. The force is greatest. This is the moment of maximum danger—and maximum opportunity to act.
For consumers: Every day you delay enabling MFA, every day you reuse a password, every day you ignore that OAuth permission request, you are rolling the dice. The odds are not in your favour.
For businesses: Every day you delay implementing identity-based security controls, every day you rely on outdated perimeter defences, every day you assume your employees will spot the phishing email, you are gambling with your organisation’s future. The attackers are not gambling. They are calculating.
Two futures are possible. One where the wave crashes and half the population suffers account takeover, financial fraud, and identity theft. One where the wave is pushed back, and the catastrophe is reduced to a notification.
The choice is ours.
XII. What This Means for You
| Action | Impact |
|---|---|
| Adopt the checklist yourself | You move from the “No Action” curve to the “Mass Adoption” curve—your personal exposure drops by an estimated 40–50% compared to baseline |
| Advocate for mass adoption | The collective benefit is a 2–4 year delay in the catastrophe threshold—time that saves millions of individuals and thousands of businesses |
| Join the EUDI Wallet | When available, this is the single most effective long-term defence against identity theft and account takeover |
| Stay ahead of the curve | The gap between the two scenarios peaks around 2029–2030. Those who adopt early benefit from lower cumulative exposure and the time buffer to further harden their defences |
XIII. Closing
“We must operate under the assumption that adversaries already have access.”
The attackers have a playbook. They are industrialised. They are using AI. They are moving fast.
But so can you.
The tools exist. The knowledge exists. The EU frameworks exist. The EUDI Wallet is coming. The only question is whether you will use them before the wave crashes.
Two futures are possible. Choose the one where you are not a statistic.
The time to act is now. Not tomorrow. Not next week. Now.
This analysis is based on current threat trends, breach data, and projected impacts. All projections are estimates and should be interpreted as directional, not precise predictions.
Citations
- Surfshark: “Global data breaches hit 425.7 million accounts in 2025” — Globally, 425.7 million user accounts were compromised in 2025, the equivalent of 13.5 accounts every second. France ranked second globally.
- eSentire: “2025 Year in Review, 2026 Threat Outlook Report” — Identity-based attacks surged in 2025. Email-initiated account compromise incidents rose to 55% of total security incidents, with PhaaS-related threats responsible for 63% of all account compromise cases.
- Guardz: “2026 State of MSP Threat Report” — 89% of SMBs had at least one user with confirmed credential compromise. Guardz recorded a 2,000% spike in Google Workspace OAuth abuse between September 2025 and February 2026.
- Spin.AI: “OAuth App Risk in 2026” — In a standard 10,000-user organisation, an average of 4,371 connected apps link to both M365 and Google Workspace. 39% of M365-connected apps are high risk. 78% of Google Workspace apps pose medium risk.
- Picus Security: “Blue Report 2025” — Prevention effectiveness dropped to 62% in 2025 from 69% in 2024. Only 3% of data exfiltration attempts were stopped. Attacks using valid credentials succeeded 98% of the time.
- Mimecast: “The state of human risk in 2026” — Technology effectiveness dropped from 47% to 37%. Process effectiveness fell from 43% to 35%. People effectiveness slipped from 38% to 35%. 99% of organisations say they need more budget.
- IBM: “Cost of a Data Breach Report 2025” — The average cost of a ransomware incident is $4.4 million—over 38 times more than the average ransom demand.
- ENISA: “European Cybersecurity Month 2025” — Over 80% of observed social engineering activity involves using AI in their campaigns.
- EU Digital Identity Wallet Regulation: By December 2026, every EU member state must offer at least one EUDI Wallet. ABI Research forecasts 169 million wallets in circulation by 2026.
- Authologic: “eID Adoption Race 2026” — Finland has 98% eID adoption; Norway has 97%.
