Cybersecurity leaders are using World Password Day to highlight a growing shift away from password-centric security, as AI-driven attacks make it easier to steal credentials across increasingly connected IoT environments. They say that, rather than changing how passwords are broken, AI is dramatically scaling how they are stolen, particularly through more convincing phishing, impersonation, and social engineering campaigns targeting users and connected systems. As commercial and industrial IoT deployments continue to scale, security controls have struggled to keep pace, leaving many organisations exposed across connected environments. World Password Day serves as a timely reminder of these risks, but experts argue the issue is no longer simply about choosing stronger passwords. Instead, it reflects a broader challenge around identity management across sprawling digital and IoT ecosystems. “AI does not fundamentally change how passwords are cracked; it makes stealing them through deception more efficient,” says Adrian Podkaminer, Head of Security at digital entertainment marketplace G2A.COM. “Weak or reused passwords are still one of the primary attack vectors, but the threat landscape is also evolving through AI-enabled phishing and social engineering. Threat actors are increasingly using generative AI to scale credential-harvesting campaigns, create more convincing impersonation attempts, and produce fraudulent communications that are harder to distinguish from legitimate ones. A continuously managed system Chris Newton-Smith, Chief Executive Officer at information security and data privacy specialist IO, says organisations need to move beyond point-in-time thinking about security. “The real challenge isn’t that employees use weak passwords. It’s that organisations treat security as a series of one-off actions rather than a continuously managed system,” he says. “Password hygiene matters. But it’s one signal in a much bigger system. The question worth asking today isn’t ‘how strong is our password policy?’ It’s ‘what are we doing on every other day of the year?’” The problem becomes