Special Reports
A special report is content that is edited and produced by the special reports unit within The Irish Times Content Studio. It is supported by advertisers who may contribute to the report but do not have editorial control.

It is easier to log in than to break in

‘For many criminals, it is easier to steal a password than to hack through technical defences’

Staff training on cybersecurity is essential as people are the weakest link in the system.
Staff training on cybersecurity is essential as people are the weakest link in the system.

Why go to the trouble of trying to break in when you can get someone to give you the keys instead? That’s the basic premise underlying cyber credential theft. In this case, credentials mean login details like usernames, passwords or digital security keys.

“Stolen credentials give criminals access, credibility and cover,” says PwC Ireland cybersecurity and privacy director Stephen O’Keeffe. “If they can sign in as a real employee or customer, their activity may look legitimate at first glance. From there, they can read emails, steal data, divert payments, impersonate staff or prepare a larger attack. Credentials can also be sold to other criminals. A working username and password can be traded quickly on criminal marketplaces, making them both a tool for attack and a source of profit.”

Credential theft is popular because it is highly effective, he adds. “For many criminals, it is easier to steal a password than to hack through technical defences. Once they have an individual’s login details, they can walk through the front door rather than break a window. The problem is often made worse by password reuse: if one account is exposed, others may be at risk too. As more of our personal and working lives move online, login details have become prime targets.”

Dani Michaux, EMA cyber leader KPMG in Ireland agrees: “Criminals increasingly find it easier to log in than to break in,” she notes. “Stolen passwords, session tokens and weak multi-factor set-ups hand attackers a direct route past defences. KPMG’s Cybersecurity Considerations 2026 report highlights that identity itself has become the primary attack surface, and that this now extends beyond human users.”

Dani Michaux, EMA cyber leader, KPMG in Ireland: 'AI tools are helping attackers automate credential-harvesting and social engineering at greater speed and scale.'
Dani Michaux, EMA cyber leader, KPMG in Ireland: 'AI tools are helping attackers automate credential-harvesting and social engineering at greater speed and scale.'

Artificial intelligence (AI) agents, service accounts and machine credentials are proliferating faster than organisations can govern them, she points out. “Because these non-human identities often lack proper ownership and life-cycle controls, they’re an increasingly attractive target and AI tools are helping attackers automate credential-harvesting and social engineering at greater speed and scale.”

The most common route for criminals to steal credentials is deception, according to O’Keeffe. “Criminals send fake emails, texts or messages or calls that appear to come from a trusted company, then direct victims to a convincing but fraudulent login page. Others pose as IT support, banks, government agencies or suppliers to pressure people into handing over passwords, Pins or other credentials. All of this is called social engineering and beyond this, malicious software can also steal passwords saved on a device. Attackers frequently use previously leaked passwords too, testing them against other accounts in the hope people have reused them.”

David McNamara, founder of indigenous IT security company Commsec, describes a more brazen route. “A classic one is where a hacker goes to the reception desk of a company and says they are there for an interview, but they have spilled coffee over their CV and asks the receptionist if they would mind printing it off from a USB stick. The receptionist inserts the USB stick and they’re in.” In this case, the USB stick contains malware which harvests credentials from the infected device.

Practical steps

Fortunately, there are ways for organisations to protect themselves against credential theft. “Individuals should use a password manager, turn on multifactor authentication (MFA) everywhere, and stay alert to increasingly convincing scams,” says Michaux. “Businesses need to think about identity more broadly than just staff logins, like covering service accounts, application programming interface keys and AI tools too. Practical steps include phishing-resistant MFA, regularly rotating credentials, limiting access to what’s needed, and monitoring for unusual machine behaviour, not just human activity.”

McNamara emphasises the need for staff training. “People are the weakest link because they do the same things over and over again,” he says. “It’s really important that you train your staff on what to look out for. It’s not just phishing simulation training. It needs to go a bit deeper than that, where people are educated on what’s happening with voice and vishing attacks as well as smishing and everything else.”

CommSec founder David McNamara: 'Use a third-party password manager.'
CommSec founder David McNamara: 'Use a third-party password manager.'

He also advises organisations to implement very strong privilege access management. “This ensures hackers aren’t able to traverse your network after they gain entry.”

In essence, what it means is that each individual’s credentials only allow very limited access to the areas of the network they need to use. A useful analogy is a house with all the internal doors locked; having the key to one door only allows access to a single room.

When it comes to password management, he advises against using standard web browser-based applications. A hacker gaining access to a device can simply open up the browser to steal all of the user’s passwords. “Use a third-party password manager instead. It populates secure passwords with multiple characters for you. You don’t have to remember them. You only have one very long secure password to use to manage your passwords. It automatically populates the password for you in each application you log into once you have that extension plugged in. It’s much more secure because it’s fully encrypted.”

He also recommends the use of applications like Microsoft Authenticator, which add an extra layer of security. These applications work by generating unique codes on a smartphone to authenticate logins, which expire in 30 seconds or less. “That means people need to have both their phone and the device they are using before they can log in. That makes it more difficult for attackers.”

Ultimately, it comes back to basics. “Use different passwords for every account, store them in a password manager and switch on multifactor authentication so stolen passwords alone cannot grant access,” says O’Keeffe. “Never click unexpected links, download attachments from unknown senders, or respond to unsolicited login requests.”

Barry McCall

Barry McCall is a contributor to The Irish Times