IT Brief India - Technology news for CIOs & IT decision-makers
India
India leads in passkeys, but phishing & deepfakes rise

India leads in passkeys, but phishing & deepfakes rise

Thu, 8th Oct 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Research published by Yubico and Okta shows Indian enterprise technology and cybersecurity professionals lead globally in passkey familiarity and universal multi-factor authentication enforcement. At the same time, many Indian organisations still issue passwords at onboarding, and nearly half of respondents continue to use them for work accounts.

The survey of 1,890 technology and security professionals across nine markets found that 53% of Indian enterprise organisations had suffered at least one successful AI-driven phishing attack in the past 12 months. It also found that 72% of Indian technical staff had seen a significant year-on-year rise in personal phishing attempts, the highest level in the study.

India also stood out for workplace exposure to suspected deepfakes. The findings showed that 45% of Indian respondents had personally received a suspicious video call, phone call or voice memo they believed was an AI deepfake impersonating an executive, colleague or client. Another 45% had seen such attempts aimed at colleagues, bringing total workplace exposure to 90%.

That threat landscape has driven a high level of concern. Some 53% said they were very concerned about AI affecting business account security, while 49% were very concerned about personal account security.

Authentication split

India ranked first among the surveyed markets for passkey familiarity, with 68% saying they were very familiar with the technology. The country also led in universal MFA enforcement, with 89% saying their employer required MFA across all applications and services.

Yet the data pointed to a gap between security policy and daily practice. More than half, or 52%, said they were issued basic passwords when they started their role, and 49% said they still rely on passwords to access work accounts.

The report also suggested Indian respondents were more confident in security controls than peers elsewhere. Some 58% described their organisation's security posture as very secure, the highest share among the markets surveyed, and 82% said financial and healthcare institutions were doing enough to protect personal data.

Yubico said this contrast reflected an execution problem rather than a lack of awareness.

"Enterprise cybersecurity has a critical execution gap. Security leaders know hardware-backed passkeys - specifically hardware security keys - offer the highest level of protection, yet nearly half still rely on basic usernames and passwords daily. The gap isn't expertise; it's overcoming the friction to user adoption," said Poupak Enbom, Chief Market and Growth Officer, Yubico.

Human judgement

The research also tested whether respondents could distinguish between human-written and AI-generated emails. In that exercise, 52% of Indian technical experts wrongly flagged a genuine human-written HR email as AI-generated, while 42% correctly identified it as human-written.

By contrast, 56% correctly identified an AI-written email. The findings suggest staff are better at spotting some synthetic content than reliably identifying authentic communications, a problem as phishing attacks become harder to detect by sight alone.

AI agents

India also led the surveyed markets in demand for stronger verification of AI agents in the workplace. The study found that 77% of Indian respondents saw verifying an AI agent's identity and authenticity as very important, ahead of the United States and Australia.

At the same time, Indian respondents were also the most open to allowing AI agents to act on their behalf. Some 41% said they were very comfortable allowing AI agents to communicate with clients or colleagues for them, and India had the lowest refusal rate, at 8%, for trusting AI agents to make business decisions without human-in-the-loop review.

According to the companies, that combination of openness and caution points to a need for stronger identity checks not only for people but also for software agents operating inside organisations.

"Indian enterprises are leading the global transition toward passkeys and universal MFA enforcement, yet 90% of technical staff are encountering workplace deepfakes. As generative AI makes identity spoofing virtually indistinguishable from genuine interaction, security leaders must move beyond user vigilance. Cryptographic, hardware-backed authentication is essential to ensure that every human and AI agent identity is verified without reliance on passwords," said Geoff Schomburgk, Vice President Asia Pacific & Japan, Yubico.

The report was based on a survey of enterprise organisations with more than 500 employees across the United States, the United Kingdom, Australia, India, Japan, Singapore, France, Germany and Sweden. It covered respondents in cybersecurity, IT, product management, software engineering and hardware engineering.