Old Passwords & AI Phishing: Why 2026’s Biggest Breaches Were Preventable

by The Creator | Jul 11, 2026

Old passwords caused 2026's largest breaches, not zero-days. The Klue breach exposed nearly 200 companies through a four-year-old pilot account that was never disabled, forcing manufacturers and professional services firms to audit and expire all temporary credentials immediately.

Meanwhile, AI is supercharging phishing. Dutch authorities reported a 58% surge in cyberattacks, with AI phishing kits eliminating the grammar errors that once exposed fake emails. These off-the-shelf toolkits cost criminals just dollars per month on Telegram and can bypass standard multi-factor authentication.

On the home front, even CISA got hit, a contractor accidentally exposed their AWS credentials on GitHub. Their takeaway? Better onboarding and automated secret scanning.

Action items: Review and expire old access credentials today, upgrade to phishing-resistant authentication like hardware keys, and train your team that convincing emails are now the norm, not the exception.

How do old passwords breach your SMB's defenses?

Forgotten credentials sitting in systems are open doors. The Klue incident shows a single four-year-old pilot account bypassed modern defenses entirely. ShinyHunters exploited this pattern, hitting over 30 million students through basic phone scams impersonating IT support, then using those old credentials to move sideways. CISA itself had a contractor leak AWS credentials on GitHub. For your SMB, the immediate action is inventory: run an access audit today, disable every pilot, temporary, and contractor account older than 90 days, and require out-of-band verification (a callback, a hardware key) for any helpdesk access requests. This single step eliminates the attack vector that damaged Klue and ShinyHunters' victims.

Key takeaways

  • Audit all credentials in your systems today. Disable any pilot, temporary, or contractor account older than 90 days.
  • Require out-of-band verification for helpdesk requests. Criminals now impersonate IT support via phone; a callback to a known number stops this cold.
  • Upgrade to phishing-resistant authentication. Hardware security keys cost $20-50 per employee and bypass AI phishing kits that now handle 58% more attacks.

Frequently asked questions

What is an old password breach and why did Klue get hit?

An old password breach happens when forgotten credentials remain active in your system. Klue's breach came from a four-year-old pilot account no one remembered to disable. Attackers found it through enumeration or leaked credential databases, then used it to access customer data for 200 companies. Check your systems for accounts older than one year that are still active.

How does AI phishing make this worse?

AI phishing kits now cost attackers just dollars per month and eliminate grammar errors that once exposed fake emails. Dutch authorities reported a 58% surge in attacks using these kits. Once an attacker has an old password, they use AI-generated phishing emails to trick your team into revealing the MFA code or hardware key, or they bypass MFA entirely if your system doesn't use phishing-resistant methods like hardware keys.

What do I do right now if I think old passwords are in my systems?

Run an access audit immediately using your directory (Active Directory, Okta, or equivalent). Disable every account older than 90 days unless it is actively used. For all user accounts, enable hardware key MFA (FIDO2 standard) or at minimum SMS-based out-of-band verification for any credential or password reset. Brief your helpdesk that calls requesting password resets must callback the employee's known number, not honor the request directly.

How much will phishing-resistant authentication cost us?

Hardware security keys run $20-50 per employee for a one-time purchase. For a 50-person manufacturing or professional services firm, that is $1,000-2,500 total. Compared to the downtime, data loss, and breach response costs that Klue and ShinyHunters' victims faced, the ROI is immediate. CISA's own breach could have been prevented by automated secret scanning, which is free or under $500 per year.

Sources

Keep reading