AI agents expand identity security risks for Singapore organisations, survey finds

by

Ansherina Baes

-

1 minute ago

Singapore – Singapore organisations are facing growing identity security challenges as AI-driven phishing becomes more sophisticated and AI agents take on greater responsibilities, according to new research from Yubico and Okta.

More than eight in 10 (81%) Singapore respondents said their organisations enforce multi-factor authentication (MFA) across all applications and services. However, 58% reported at least one successful AI-driven phishing attack within their organisation over the past 12 months.

The findings suggest that widespread MFA adoption does not necessarily eliminate exposure to increasingly sophisticated phishing attacks.

Nearly three-quarters (72%) of Singapore respondents said their organisations use different forms of authentication across applications. Mobile TOTP or push authenticator applications were the most commonly used method, cited by 49%, followed by usernames and passwords at 41%.

Mobile SMS-based authentication was used by 35% of respondents, while 33% used device-bound passkeys on mobile devices. Hardware security keys and synced passkeys were each cited by 26%.

Traditional credentials also remain common for new employees, with 58% of Singapore respondents saying they were issued a username and password when they joined their organisation.

“Enterprise cybersecurity has a critical execution gap,” said Poupak Enbom, Chief Market and Growth Officer at Yubico. 

“Security leaders know hardware-backed passkeys – specifically hardware security keys – offer the highest level of protection, yet nearly half still rely on basic usernames and passwords daily. The gap isn’t expertise; it’s overcoming the friction to user adoption,” Enbom continued.

The research also highlights a contrast between employees’ ability to identify AI-generated phishing and their organisations’ exposure to successful attacks.

Singapore respondents recorded the highest rate among the surveyed markets for correctly identifying an AI-generated phishing email, at 59%, compared with 53% globally. At the same time, Singapore had the highest proportion reporting at least one successful AI-driven phishing attack, at 58%, compared with 44% globally.

Phishing activity is also increasing, with 78% of Singapore respondents reporting a rise in attacks targeting their organisations over the past year.

“As AI agents take on more work, organisations need to verify who or what is acting, and keep people in control of critical decisions,” said Geoff Schomburgk, Regional Vice President, Asia Pacific and Japan at Yubico. 

“Businesses should adopt a human-in-the-loop approach that preserves human oversight and intervention for higher-risk AI actions. That oversight, when backed by strong authentication through a security key touch or biometric verification, helps ensure the person authorising the action is who they say they are,” Schomburgk continued.

AI agents are creating an additional identity security consideration as organisations increasingly use them to act on behalf of employees.

More than half (51%) of Singapore respondents said they are comfortable allowing AI agents to make low-risk operational decisions, compared with 40% globally. Meanwhile, 60% said they are comfortable allowing AI agents to communicate with colleagues or clients on their behalf.

Despite this willingness, respondents reported strong expectations around controls. Some 98% said verifying the identity and authenticity of AI agents is important, while 95% said reviewing and approving actions before an AI agent executes them on their behalf is important.

“Bridging this gap requires organisations to build security directly into the onboarding experience,” said Charlotte Wylie, SVP Deputy CSO at Okta. 

“When legacy login habits persist, enterprises remain vulnerable to modern attack vectors. Together with Yubico, we are providing a unified approach that ensures every employee is protected by zero-trust, phishing-resistant authentication from their first day on the job,” Wylie continued.

Yubico and Okta are also working to streamline how enterprise identity systems issue, manage and enforce hardware-backed credentials. The companies said the approach is intended to strengthen phishing-resistant authentication while reducing reliance on passwords and limiting operational friction for employees.

Recognise the innovators redefining commerce at the Retail & E-commerce Excellence Awards Asia Pacific 2026! Taking place this December 2026, we celebrate the region’s most impactful retail strategies, standout e-commerce experiences, and forward-thinking leaders—submit your entries today!
Honour the women shaping the future of marketing and technology at the Empowered Women Awards 2026! This December 2026, we celebrate inspiring leaders, changemakers, and rising voices driving impact across the industry—submit your entries today!
Share

RECENT ARTICLES

AI agents expand identity security risks for Singapore organisations, survey finds
Dell expands AI data platform with semantic layer and knowledge graph for enterprise AI agents
Sumsub launches Reusable KYC gateway with MiniPay as first live integrator
Tech Mahindra expands Gemini Enterprise readiness across 12,500 associates
Smartstream takes Air live at Rothera to automate derivatives reconciliations
Ellipse 3

RELATED ARTICLES

Salesforce strengthens Agentforce coverage with new portfolio of job-ready AI agents
boomi
Salesforce expands Headless 360 to give AI agents secure access across the enterprise
Ellipse 3

FEATURED ARTICLES

'Retail & E-Commerce Innovation Summit' returns for its 2nd edition in the Philippines — initial speaker lineup revealed
‘Retail & E-Commerce Excellence Awards Asia Pacific
EW2025_(UT)Launch Article_Feature Image_11zon

Subscribe to UpTech Media Newsletter

JOIN OUR NEWSLETTER

Subscribe to our newsletter to get the latest APAC marketing news.