Singapore – Singapore organisations are facing growing identity security challenges as AI-driven phishing becomes more sophisticated and AI agents take on greater responsibilities, according to new research from Yubico and Okta.
More than eight in 10 (81%) Singapore respondents said their organisations enforce multi-factor authentication (MFA) across all applications and services. However, 58% reported at least one successful AI-driven phishing attack within their organisation over the past 12 months.
The findings suggest that widespread MFA adoption does not necessarily eliminate exposure to increasingly sophisticated phishing attacks.
Nearly three-quarters (72%) of Singapore respondents said their organisations use different forms of authentication across applications. Mobile TOTP or push authenticator applications were the most commonly used method, cited by 49%, followed by usernames and passwords at 41%.
Mobile SMS-based authentication was used by 35% of respondents, while 33% used device-bound passkeys on mobile devices. Hardware security keys and synced passkeys were each cited by 26%.
Traditional credentials also remain common for new employees, with 58% of Singapore respondents saying they were issued a username and password when they joined their organisation.
“Enterprise cybersecurity has a critical execution gap,” said Poupak Enbom, Chief Market and Growth Officer at Yubico.
“Security leaders know hardware-backed passkeys – specifically hardware security keys – offer the highest level of protection, yet nearly half still rely on basic usernames and passwords daily. The gap isn’t expertise; it’s overcoming the friction to user adoption,” Enbom continued.
The research also highlights a contrast between employees’ ability to identify AI-generated phishing and their organisations’ exposure to successful attacks.
Singapore respondents recorded the highest rate among the surveyed markets for correctly identifying an AI-generated phishing email, at 59%, compared with 53% globally. At the same time, Singapore had the highest proportion reporting at least one successful AI-driven phishing attack, at 58%, compared with 44% globally.
Phishing activity is also increasing, with 78% of Singapore respondents reporting a rise in attacks targeting their organisations over the past year.
“As AI agents take on more work, organisations need to verify who or what is acting, and keep people in control of critical decisions,” said Geoff Schomburgk, Regional Vice President, Asia Pacific and Japan at Yubico.
“Businesses should adopt a human-in-the-loop approach that preserves human oversight and intervention for higher-risk AI actions. That oversight, when backed by strong authentication through a security key touch or biometric verification, helps ensure the person authorising the action is who they say they are,” Schomburgk continued.
AI agents are creating an additional identity security consideration as organisations increasingly use them to act on behalf of employees.
More than half (51%) of Singapore respondents said they are comfortable allowing AI agents to make low-risk operational decisions, compared with 40% globally. Meanwhile, 60% said they are comfortable allowing AI agents to communicate with colleagues or clients on their behalf.
Despite this willingness, respondents reported strong expectations around controls. Some 98% said verifying the identity and authenticity of AI agents is important, while 95% said reviewing and approving actions before an AI agent executes them on their behalf is important.
“Bridging this gap requires organisations to build security directly into the onboarding experience,” said Charlotte Wylie, SVP Deputy CSO at Okta.
“When legacy login habits persist, enterprises remain vulnerable to modern attack vectors. Together with Yubico, we are providing a unified approach that ensures every employee is protected by zero-trust, phishing-resistant authentication from their first day on the job,” Wylie continued.
Yubico and Okta are also working to streamline how enterprise identity systems issue, manage and enforce hardware-backed credentials. The companies said the approach is intended to strengthen phishing-resistant authentication while reducing reliance on passwords and limiting operational friction for employees.

