Report by Yubico

2025 Global State of Authentication Report

22 FINDINGSPublished Sep 30, 2025
View Original Report →

Key Findings

41% of respondents use personal email accounts lacking MFA to log in to banking services.

MFAPersonal email accountsBanking services

When shown a phishing email, 54% of respondents either believed it was an authentic message written by a human or were unsure.

Phishing

In the UK, concern about AI compromising security increased from 61% in 2024 to 81% in 2025 (a 20 percentage point increase).

AIUK

In the US, concern about AI compromising security increased from 61% in 2024 to 77% in 2025 (a 16-point increase).

AIUS

Only 48% of respondents said their company uses Multi-Factor Authentication (MFA) across all apps and services.

MFA

Usernames and passwords are used by 60% of respondents as an authentication method for personal accounts.

AuthenticationUsername and passwordPersonal accounts

The percentage of respondents who could correctly recognize a phishing attempt was similar across generations: Gen Z - 45%, Millennials - 47%, Gen X and baby boomers - 46% (both groups).

PhishingGen ZMillennialsGen XBoomer

70% of respondents believe phishing attempts have become more successful due to the use of AI.

PhishingAI

78% of respondents believe phishing attempts have become more sophisticated due to the use of AI.

PhishingAI

In Japan, concern about AI compromising security increased from 31% in 2024 to 74% in 2025 (a 43 percentage point increase).

AIJapan

44% of all participants admitted to having interacted with a phishing message in the last year.

Phishing

In Sweden, concern about AI compromising security increased from 37% in 2024 to 68% in 2025 (a 31 percentage point increase).

AISweden

Only 26% of respondents consider usernames and passwords to be the most secure authentication method.

AuthenticationUsername and password

Gen Z is the most susceptible demographic to phishing, with 62% reporting engagement (e.g., clicking a link or opening an attachment) with a phishing scam in the past year.

PhishingGen Z

29% of respondents still do not have MFA set up for their personal email accounts.

MFAPersonal email accounts

47% of respondents use personal email accounts lacking MFA to log in to social media accounts.

MFAPersonal email accountsSocial media

34% of respondents use personal email accounts lacking MFA to log in to mobile phone carriers.

MFAPersonal email accountsMobile phone carriers

In the UK, 37% of respondents believe hardware security keys and device-bound passkeys are the most secure authentication methods, up from 17% in 2024 (a 20-point increase).

AuthenticationHardware security keysPasskeysUK

In the US, 34% of respondents identify hardware security keys/passkeys as the most secure option, up from 18% last year (a 16-point increase)

AuthenticationHardware security keysPasskeysUS

40% of respondents reported never having received cybersecurity training from their employer.

Cybersecurity training

Usernames and passwords are used by 56% of respondents as an authentication method for work accounts.

AuthenticationUsername and passwordWork accounts

In France, the adoption of MFA for personal accounts surged from 29% in 2024 to 71% in 2025, marking a 42-percentage point increase.

MFA