Australia is trailing other advanced economies in cybersecurity readiness as artificial intelligence (AI) amplifies the sophistication and success of phishing attacks, according to new research from Yubico.
The 2025 Global State of Authentication Report, conducted by Talker Research and timed for October’s Cybersecurity Awareness Month, surveyed 18,000 employees across nine countries, including 2,000 Australians. It found that despite widespread awareness of rising threats, many individuals and organisations still rely on weak or outdated authentication practices.
Awareness rising, but complacency persists
“Our survey revealed a glaring disconnect between awareness and action,” said Geoff Schomburgk, vice president for Asia Pacific and Japan at Yubico.
“Individuals are complacent about securing their own online accounts, and Australian organisations appear to be slow to adopt security best practices,” he added. “It’s not surprising that phishing is one of the easiest ways for hackers to gain access, and 46% of Australian respondents said they have interacted with a phishing message in the last year. We must close the gap with strong, phishing-resistant authentication, education and action.”
The report highlights a persistent overreliance on passwords despite low confidence in their security. Just 24% of Australians consider usernames and passwords the most secure method, yet 56% still use them for work accounts and 57% for personal logins.
AI drives new wave of phishing attacks
Nearly three-quarters (73%) of Australians believe AI has made phishing more successful, while 82% say attacks have grown more sophisticated as a result of AI. Among those duped, 24% disclosed their email address, 21% provided their full name and 18% gave away their phone number — potentially exposing both personal and corporate data.
Younger Australians were identified as the most vulnerable demographic: 62% of Gen Z respondents admitted engaging with a phishing scam, far exceeding older age groups.
When presented with a phishing email, more than half of respondents (54%) either believed it was legitimate or were unsure, while 35% said they thought it came from a trusted source.
Corporate defences fall short
While most Australians (79%) said their organisation’s systems are secure, only 55% reported that multi-factor authentication (MFA) is used across all apps and services. Alarmingly, 41% said they have never received cybersecurity training from their employer — a gap Yubico says leaves businesses exposed.
Even after falling victim to phishing, behavioural change remains limited. Only 15% of respondents said they started using MFA afterwards, and just 18% reported the incident to someone at work.
Slow adoption of stronger authentication
As cyber threats become increasingly sophisticated, awareness of stronger, phishing-resistant authentication methods is on the rise in Australia, though actual adoption remains low, Schomburgk said.
“Both individuals and organisations have the power to protect themselves by adopting these phishing-resistant solutions today,” he said. “Modern MFA is clearly no longer just a nice-to-have and has quickly become essential for staying secure in our rapidly changing digital landscape.”
The findings underscore an urgent need for stronger security culture and infrastructure across Australian workplaces — particularly as AI-enabled phishing continues to blur the line between legitimate and malicious communication.