Okta has reported a 300% surge in credential stuffing attacks during Q2 2026, with attackers now using AI-driven behavioral mimicry to evade traditional rate limiting and bot detection mechanisms. The attacks originate from distributed residential proxy networks that make them nearly indistinguishable from legitimate user traffic.
Traditional defenses such as IP-based rate limiting, CAPTCHA, and device fingerprinting are increasingly ineffective against these sophisticated attacks. Okta recommends organizations accelerate their migration to passwordless authentication, specifically FIDO2 passkeys, as the only effective long-term defense.
In the interim, Okta recommends implementing continuous authentication — verifying user identity throughout a session, not just at login — using behavioral biometrics and risk-based access policies to detect and block compromised sessions.