Brief
Yubico survey finds half of security pros still rely on passwords
The 2026 Global State of Authentication Survey shows many cybersecurity professionals continue to use insecure login methods despite knowing better.
By Felo News Desk · Published
Yubico, in partnership with Okta, released its fourth Global State of Authentication Survey on October 7, 2026, after questioning almost 2,000 security and IT specialists worldwide. The study highlights a gap between knowledge and practice among professionals tasked with protecting corporate networks.
What happened
The survey asked participants about their personal authentication habits. While 87% said they were aware that password‑less options such as passkeys exist, 48% reported that they still primarily use traditional usernames and passwords for personal accounts. Additionally, 28% disclosed that they do not enable two‑factor authentication (2FA) on their personal email accounts.
What the reports add
Yubico’s blog notes that the most common reason cited for these insecure choices is “login fatigue” – the inconvenience of repeatedly entering codes, passwords, or answering security questions throughout the day. The report also points out that the rise of AI‑generated phishing attacks has made it harder for even seasoned professionals to spot scams. In a test, only 36% of respondents correctly identified a human‑written message, while 54% mistakenly thought a human‑written email was generated by AI.
What was said
Yubico’s blog states, “Knowing better isn’t enough: the ‘path of least resistance’ trap,” emphasizing that convenience often outweighs security considerations. The company adds that “the issue isn’t that people aren’t trying hard enough, it’s that traditional passwords and login methods are fundamentally not secure.”
How it came about
The survey follows Yubico’s previous research on authentication trends and builds on earlier findings that password fatigue and the proliferation of AI tools are reshaping threat landscapes. The firm has repeatedly urged a shift toward password‑less solutions, a stance echoed in its earlier coverage of AI‑driven phishing risks.
Key facts
- 87% of surveyed security professionals know password‑less login methods exist (yubico.com)
- 48% still rely mainly on usernames and passwords for personal accounts (yubico.com)
- 28% do not use two‑factor authentication on personal email (yubico.com)
- Only 36% correctly identified a human‑written email in an AI‑phishing test (yubico.com)
- 54% mistakenly thought a human‑written email was generated by AI (yubico.com)
Sources
- [1] yubico.com — originally reported as “2026 Global Authentication Survey: Cybersecurity pros are still using passwords…”








