Identity, AI/ML, Vulnerability Management, Threat Intelligence, RSAC

Thwarting AI-powered attacks: How identity management can help

An evil-looking robot on all fours waits in the darkness, ready to pounce.

Last November, the AI-development company Anthropic reported that its researchers had detected a Chinese state-sponsored campaign of AI-powered attacks upon "large tech companies, financial institutions, chemical manufacturing companies, and government agencies" that was "executed without substantial human intervention."

Many resulting headlines implied that this was a fully automated attack, the next step toward AI eventually taking over the world.

It wasn't. Human operators directed each stage of the attack campaign, as Anthropic's full report made clear.

The big difference from previous campaigns, however, was that the human operators had AI agents based on Anthropic's own Claude Code model doing most of the grunt work, including scanning and probing the targets for known vulnerabilities and weaknesses.

Most significantly, after the targeted systems were profiled, the AI agents — not human coders — wrote their own exploit code tailored to the targets.

Creeping toward complete autonomy

This may not be an entirely AI-powered attack, but it's a big step on the path to such attacks becoming real.

"At this stage, there are a couple of examples, but really, there is some sort of human in the loop," said Charlotte Wylie, Senior Vice President and Deputy Chief Security Officer at Okta, at a recent Okta showcase in New York. "I think that will change very dramatically, and in the not-too-distant future, when we see more autonomous AI attacks."

"I would not say completely autonomous, only because I haven't seen it," concurred Brett Winterford, Vice President of Okta Threat Intelligence, at the same event. But, he added, "we are seeing semi-autonomous attacks. If the prompt is strong enough and allows enough leeway for the agent, the agent can get a lot done."

As Okta Co-Founder and CEO Todd McKinnon said about the Anthropic report during his keynote at the Okta event, the "attackers socially engineered the model, posing as threat researchers" to bypass Claude Code's built-in restrictions against aiding in malicious activity.

"Your prompt obviously has to bypass the model guardrails in the first place," explained Winterford, "and then it also has to give the agent sufficient leeway to pivot and try something new and not get stuck on a particular task, because that's when the human operator is always required."

Regardless of whether such attacks are 50%, 90% or 100%-percent AI-powered, the biggest threat to system defenders is the speed of the attacks. An AI-assisted attack campaign can register domains, create infrastructure, send out malicious emails, penetrate targets and harvest data many times faster than human threat actors can.

The techniques may not be different from those used by humans, but the volume and rate of the attacks certainly will be. To combat such attacks, Wylie thinks we'll need AI on the defensive side.

"From a defender perspective, we need to rapidly adopt AI agents. They don't sleep, they don't need to eat," she said. "Rapid adoption of agentic AI is an absolute imperative so that we can scale appropriately, as the attackers do."

Prove who — or what — you are

Okta's identity protections can't fully defend an organization against all cyberattacks, AI-powered or otherwise, especially attacks based on software vulnerabilities, misconfigurations and other weaknesses.

But Okta and other identity-management systems can slow down attacks. Most cybersecurity breaches these days involve some sort of credential compromise, whether through stolen passwords, brute-force cracking or social engineering.

"In any successful account takeover event of an Okta customer, it's more often than not going to start with phishing," noted Winterford.

Through restriction of privileges, multi-factor authentication, re-authentication requests and continuous monitoring for unusual user behavior, identity protections can greatly reduce an adversary's abilities — whether that adversary is a human or an AI agent — to penetrate external defenses or move through a system.

"The control set that we have is as relevant to an agentic world as not," said Winterford. "Identity- based controls creat[e] an expected set of access conditions for any given machine or human user, such that anything that is outside of that norm can be better understood and perhaps even detected."

The hardest sort of credential compromise to defend against involves stolen session cookies, the temporary "golden tickets" to online accounts that can often bypass MFA.

But even that can be mitigated, if not eliminated, by the dynamic/adaptive MFA authentication challenges built into Okta and other identity providers that are triggered if a logged-in user suddenly switches to a unfamiliar IP address or exhibits other unusual behavior.

Authentication challenges can protect any internal system, Wylie pointed out, even AI agents.

"Okta adaptive MFA is a really good starting point," she said. "if an attacker is going to use a user's account, they can gain a foothold on that user account and go and see where the access has been provisioned to an agent, and then go and attack appropriately."

Living off the AI land

In that way, Okta helps thwart "living off the land" techniques that use existing system resources like PowerShell instead of malware to penetrate further into systems. Attackers are already hunting LLMs and AI agents, which may have substantial system privileges, to aid in such attacks.

"It would make total sense to me that agents that are already authorized in an environment would become targets for any attacker," said Winterford.

Wylie added that not only are AI agents vulnerable to compromise, but they are often eager to help attackers if they're tricked into thinking that their instructions come from a legitimate user.

"AI agents, their prerogative is to be pervasive and determined, and so they're going to try and do whatever they can with the level of access that they have," she explained. "People will start to realize that what we see and how we think about the security of agents is something that they're going to have to double down on incredibly quickly."

Okta's new Okta for AI Agents platform can stop compromised AI agents directly by flipping a "kill switch" that instantly cuts off an agent's access to resources. It can also tighten an agent's privileges and monitor its behavior for strange behavior and other indicators of possible compromise.

"If we can scope down what the privileges are, and what the access required is for that agent and manage them as a new identity type, we can start to reduce our risk," Wylie said.

Back to the basics

AI-powered defenses, identity-based or not, can only slow, not stop, AI-powered attacks. They put defenders on an equal footing with AI-powered attackers. But the presence of AI on either side doesn't change the nature of the overall game — it just speeds it up.

The best way to defend against attacks of any sort, and achieve the highest possible level of resilience, is to strip things down to the basics and implement the zero-trust model, the principle of least privilege, and network micro-segmentation across your entire organization — all things that Okta and other identity-protection services will help you establish.

"What I would encourage people to focus on initially is just ensuring that the basic hygiene is there," said Winterford. "The strong authentication policies, least-privilege approach to authorization, strong governance, and privileged access management."

Paul Wagenseil

Paul Wagenseil is a custom content strategist for CyberRisk Alliance, leading creation of content developed from CRA research and aligned to the most critical topics of interest for the cybersecurity community. He previously held editor roles focused on the security market at Tom’s Guide, Laptop Magazine, TechNewsDaily.com and SecurityNewsDaily.com.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds