Passwords Are Getting Easier to Fake. Device Trust Is the Fix Companies Are Reaching For.
AI is turbocharging phishing and credential theft, and the old signals that told a company a login was fine are quietly failing. Here is what is replacing them.

Key points
- AI tools are making phishing emails and fake login pages cheaper and far more convincing in 2024 and 2025.
- Traditional login checks like passwords, multi-factor codes, IP address reputation and country-of-login can all be bypassed by a determined attacker.
- Companies are adding "device trust", a check on whether the actual laptop or phone logging in is a known, healthy company device, to their security stack.
- Device trust is a core piece of Zero Trust, the security model that assumes no user or machine should be trusted by default.
- The shift matters for ordinary staff because logins from unknown devices may now be blocked outright, even with the correct password and code.
The login box has been the front door of corporate computing for thirty years. That door is getting easier to pick.
Generative AI, the same technology behind chatbots like ChatGPT, has quietly handed attackers a productivity upgrade. Phishing emails, the fake messages criminals send to trick staff into typing their passwords into a lookalike website, used to be easy to spot: bad grammar, weird logos. Not any more.
An analysis by password-security firm Specops, flagged this week by BleepingComputer, argues that the checks companies have relied on for years to spot a dodgy login are quietly running out of road. The fix they point to is device trust.
What is device trust, in plain English?
Device trust means the company checks the machine, not just the person. The system asks whether this is the laptop it issued, whether it is patched, and whether the company's security software is running. If not, access is refused, even with the correct username and password.
Think of it like a nightclub that checks both your ID and the wristband it gave you at the door. Steal one, you still don't get in.
Why are the old checks failing?
Because every one of them can now be faked cheaply. Passwords get stolen in bulk breaches and sold. Multi-factor authentication codes, the six-digit numbers sent to your phone, can be intercepted or phished in real time using attacker-in-the-middle kits like Evilginx.
IP reputation, a score of how trustworthy a given internet address is, collapses the moment an attacker rents a residential proxy for a few dollars. Geolocation, the check that says "this login came from Germany", is undone by a VPN.
AI makes the human side worse. A convincing voice clone of a chief executive now costs pennies. Fake login pages can be generated in seconds. The economics have tipped. Our 15 July story on phishing found that fake emails now cause half of all ransomware attacks, with stolen passwords defeating even multi-factor authentication at an alarming rate.
How does this fit with Zero Trust?
Zero Trust is a security approach that assumes nothing inside or outside the network should be trusted automatically. Every request has to prove itself. For years, that mostly meant tighter identity checks on the user. Device trust adds the second half: proving the hardware is legitimate too.
The model has been pushed hard by the US Cybersecurity and Infrastructure Security Agency in its Zero Trust Maturity Model, which lists devices as one of five core pillars alongside identity, networks, data and applications.
What does this mean for ordinary staff?
Expect more logins to be refused, even when you type everything correctly. Try to reach work email from a personal laptop or a phone not enrolled with the company's device-management software, and you may be turned away.
That is not a bug. It is the point. The trade-off is fewer stolen-password incidents and, hopefully, fewer 3am calls from the security team.
Should smaller companies care?
Yes, and this is the shift worth watching. Device trust used to be the preserve of banks and defence contractors. Cloud identity providers like Microsoft and Okta now bundle device-check features into standard business plans, which puts the control within reach of a dentist's office or a mid-sized law firm.
The hard part is not the technology. It is the inventory: knowing which devices your staff actually use, and being willing to say no to the rest. As our July reporting on critical infrastructure showed, attackers rarely need fancy exploits when a valid password and an unchecked laptop will do.



