Account takeover confidence at financial firms sits far above the evidence supporting it. Secret Double Octopus, a passwordless authentication vendor, published its 2026 State of Identity Security in Financial Organizations report this week, based on a survey of 200 identity and access management leaders at US and Canadian financial services firms.
The topline is a confidence gap. While 94% of respondents said phishing attacks rose over the past year, and only 28% of the multi-factor authentication protecting their workforce is phishing-resistant, 82% still said they feel protected from account takeover.
The Account Takeover Numbers Behind the Confidence
This is a vendor-commissioned survey, so the obvious caveat applies. A passwordless authentication company is not a neutral party when the finding is that your authentication is weaker than you think.
That does not make the observation wrong. Account takeover and credential-based fraud have been the most persistent attack vector against financial institutions for years. The reason is not budget. Identity infrastructure at most large financial firms is a patchwork of legacy directory services, single sign-on layers bolted on in the 2010s, and MFA rollouts that cover some systems and not others. IAM leaders rating their own posture generously while their environment carries known gaps is the standard pattern in every security maturity study going back a decade.
Where the Account Takeover Gaps Really Sit
To the report’s credit, it does not stop at one headline number. The breakdown is where the useful signal lives, and it points squarely at legacy systems.
MFA covers 74% of SaaS applications on average but only 50% of legacy applications. More than half of surveyed organisations said legacy systems make up between 50% and 74% of their applications and infrastructure. Smaller firms fare worse on method quality: password-plus-one-time-code remains more common at organisations under 500 employees than at larger enterprises. And the firms citing regulatory compliance as their main driver for MFA modernisation tend to carry the largest legacy estates.
That is the account takeover exposure in one line. The systems least likely to have phishing-resistant authentication are the systems that hold the most sensitive functions, and they are the hardest to replace.
Why the Account Takeover Report Lands Now
The timing is not neutral. Financial regulators and examiners have grown more explicit that identity and access controls fall within supervisory scope, not just transaction monitoring.
A vendor publishing this now is positioning passwordless authentication as compliance infrastructure rather than a convenience upgrade. That is a smart go-to-market move, and the research methodology deserves normal skepticism regardless. Worth noting, though, that the survey was administered by Global Surveyz Research, an independent research firm, with responses collected in April 2026 across four evenly split company-size bands. That is a better setup than most vendor surveys manage.
What the Account Takeover Finding Is Worth
Secret Double Octopus is a smaller player in an authentication market that includes Okta, Ping Identity, and a wave of newer AI-native identity vendors. A report like this is straightforwardly a way to put the company’s name in front of the exact buyers it wants.
That does not make the finding false. CEO Raz Rafaeli argued the alarming part is not the size of the gaps but “how confident financial organizations feel despite them,” which is the honest reading of the data. Strong-sounding MFA is not phishing-resistant MFA, and partial coverage leaves the most sensitive systems exposed.
The broader fraud picture supports the urgency. Phishing and credential theft are getting cheaper to run at scale as generative AI improves impersonation. An account takeover defence built on password-plus-code across half a bank’s legacy estate is not a defence that ages well.
So the number to watch is not 82%. It is whether any of the surveyed banks change their identity architecture as a result, or whether this becomes another study cited in vendor decks for twelve months without moving anyone’s roadmap.
Fintechbits covers financial technology, cybersecurity, and fraud prevention. Nothing here constitutes security or financial advice. The report cited is vendor-commissioned research conducted by an independent survey firm.
