IDEX Biometrics · 7 September 2026
Phishing attempts do not have to end in a data breach
AI has industrialised credential theft. As cyberattacks become increasingly automated, attackers can target many organisations simultaneously. This also makes smaller and medium businesses more vulnerable than before.
Phishing and credential abuse are among the methods used to gain access. Credential abuse means the attacker has obtained valid details and uses them to log in. To the organisation, it can look like an ordinary login. The attacker does not necessarily need to break through the security system if they already hold the information the system uses to verify identity.
Is this right for my business?
Talk to us about how IDEX can strengthen your security. Our solutions work with existing infrastructure, making it simple and cost effective to upgrade authentication, increase security and meet compliance requirements.
Book a meetingSmall businesses are not the exception
Verizon’s 2026 Data Breach Investigations Report is based on more than 22,000 confirmed data breaches globally. Among 7,152 breaches at small and medium-sized businesses, credentials were compromised in 31 per cent of cases. In the extortion cases where the size of the affected business was known, 96 per cent were small and medium-sized businesses.
Europe is where phishing weighs heaviest. Among breaches involving social engineering, phishing appeared in 84 per cent of cases in EMEA, against 69 per cent globally.
The cost follows. Phishing is now the most common attack vector of all, behind 16 per cent of breaches, and across some 70,000 cyber insurance claims, insurable losses per claim rose from roughly USD 60,000 in 2019 to around USD 100,000 in 2024.
“AI is transforming the meaning of cybersecurity. And we must keep pace.”
Henna Virkkunen, Executive Vice-President, European Commission

Phishing can be avoided
Phishing becomes far less effective when access no longer rests on credentials that can be stolen and used by someone else, but on identifying the right person. To be safe online, authentication has to happen offline, out of reach of attackers.
IDEX develops fingerprint cards for digital login, where the user confirms their identity with a fingerprint directly on the card. The solution replaces passwords, PIN codes and one-time codes.
The card is FIDO2 certified, which means the authentication is cryptographically bound to the specific service. Even if the user visits a fake website, the login cannot be reused on the legitimate service.
Responsibility for compliance sits with senior management
Digital security is not something the IT department owns alone. Under NIS2, senior management has to approve the security measures, see that they are carried out, and answer for it when they are not.
Failing to meet the requirements costs money. Each country sets its own fines, but the directive decides how high they must be able to reach. For the most critical organisations that is at least 10 million euros or 2 per cent of worldwide annual turnover, whichever is higher. For the tier below, 7 million euros or 1.4 per cent.
The consequences do not stop with the company. For the most critical organisations, a chief executive can, as a last resort, be temporarily barred from holding management duties in that business. Regulators can also suspend the permits the business needs to operate.
NIS2 lists multi-factor authentication among the basic measures organisations must put in place. Relying on passwords alone is therefore not only a technical choice, it is one senior management has to answer for.
Act now, rather than waiting for “your turn”
Authentication must be part of the security strategy for anyone handling data, either themselves or their clients. When phishing is used to gain access to an organisation’s systems, data security should not rest on information that can be stolen and used by someone else.
Artificial intelligence makes it possible to carry out these attacks faster and at greater scale. That makes this a security problem organisations should address now.
Would you like to be contacted by an adviser?
IDEX helps organisations move from traditional login to phishing-resistant biometric authentication in a simple and cost-effective way.
Sources
- Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 (NIS2 Directive), Articles 20, 21, 32 and 34.
- European Commission. EU Action Plan on Cybersecurity and Artificial Intelligence. Presented 7 July 2026, including the statement by Executive Vice-President Henna Virkkunen.
- IBM. Cost of a Data Breach Report 2026.
- IDEX Biometrics. Product information and technical documentation on fingerprint-based authentication and FIDO2.
- Verizon. 2026 Data Breach Investigations Report. Verizon Business, 2026.
- Verizon. 2026 Data Breach Investigations Report: Business interruption and cyber insurance losses. Verizon Business, 2026.

