In a world where everyone works from anywhere and every app lives in the cloud, the first checkpoint of security is no longer "which building are you connecting from." It's "who are you, and can you prove it?" — this is the business of proving identity and opening the door only to the right person: log in once and get into every app (SSO), confirm yourself in two layers (MFA), and the "issuer of digital ID cards" that every app agrees to trust. This field has one slogan that explains everything: "identity is the new perimeter."
Contains
Theme index· base 100 · USD total return
No index history for this theme yet.
News & notes movingWorkforce & Customer IAM (SSO/MFA)
Workforce & Customer IAM (SSO/MFA)
Japan's National Police Agency says North Korean IT worker applied for engineer job at bitFlyer
Japan's National Police Agency announced on September 18 that a person believed to be a North Korean IT worker applied in May 2025 for an engineer position at the domestic cryptocurrency exchange bitFlyer. The applicant attached a résumé to the recruitment form under someone else's identity and applied directly rather than through an intermediary, but the company noticed suspicious behavior and responded, so no hiring or damage resulted. According to the National Police Agency, the applicant accessed the recruitment form using multiple VPN services, listed a Gmail address as contact information, and stated in the résumé a broad range of skills in programming languages, blockchain, and cloud services, along with graduation from a European university and work experience in cities in Europe and Asia. In an online interview, the applicant said they were from Malaysia and living in Finland, but refused to relocate to Japan or work on-site, or said they would agree only if it were six months out, insisted on being paid in cryptocurrency, frequently checked another monitor during the interview, and at times another person's voice could be heard from behind. The National Police Agency and the U.S. Federal Bureau of Investigation believe that the cyberattack group WaterPlum's activities and some of the foreign-currency earning operations by North Korean IT workers are centrally linked to the Workers' Party of Korea's Bureau 313, and the IP addresses used by the group's attackers, the North Korean IT workers, and the applicant to bitFlyer matched.
GPF Joins Forces with 3 Partners to Strengthen Online Fraud Protection for 1.2 Million Members
The Government Pension Fund, or GPF, has signed a memorandum of understanding with the Deposit Protection Agency, Gogolook (Thailand) Company Limited, known as Whoscall, and National ITMX Company Limited, known as NITMX, to strengthen awareness of fraud and digital crime among GPF members and the general public. Mr. Sornphon Tulyasathien, Secretary-General of the GPF Board, said the organisation manages retirement savings for more than 1.2 million members, and that this collaboration is part of the Retirement Academy project. Under the partnership, Whoscall is providing 1.5 million Whoscall Premium Basic licences to GPF members and will jointly develop an e-learning course with its partners. Mr. Sornphon noted that in 2026, about 16,000 GPF members will retire, with average savings of 1.5 million baht per person. Mrs. Piyaporn Phoklin, Deputy Director and Acting Director of the Deposit Protection Agency, disclosed that from mid-2024 to the present, there have been 270 complaints from people deceived by scammers posing as the agency, with elderly victims accounting for 30 to 40 percent, and 24 victims who actually lost money, with losses ranging from a few hundred baht up to 400,000 baht. Mr. Manwoo Joo, Chief Executive Officer of Gogolook (Thailand) Company Limited, said a single scam phone number can make more than 800,000 calls. Mr. Chatchai Dusadeenod, Managing Director of National ITMX Company Limited, said this collaboration will help broaden the fight against digital crime and reduce the number of victims.
Microsoft Opens Government AI Suite October 1 With Features Still Pending Accreditation
Microsoft has told federal buyers that a new top government tier of its productivity suite, plus a companion agent-management product, will be available for Government Community Cloud customers to purchase on October 1, with individual capabilities lighting up in phases as each workload clears its required government security accreditation. The new suite layers Copilot, identity and security tooling, and agent-governance controls on top of the prior government tier, with the headline addition being Agent 365, which Microsoft has framed on the commercial side as providing security operations, financial operations, and observability and manageability of token spending across business processes. Microsoft has not disclosed per-seat pricing for the new tier or paid conversion rates from earlier no-cost federal Copilot deployments, leaving any government revenue forecast impossible, and the stock closed at $497.12, down 2.74% over the past year. On the commercial side, net paid seats more than doubled sequentially to over 30 million Copilot seats, while full-year capital expenditures hit $115.95 billion and free cash flow fell 23.19% in the quarter. Analysts carry an average price target of $572.92 with 38 Buy and 14 Strong Buy ratings, and the variable that decides the bull and bear cases is what Microsoft discloses in coming quarters about paid government seat counts and workload authorization progress rather than the October launch itself.
Cloudbrink Launches OnGuard to Consolidate Enterprise Security Stack
Cloudbrink introduced OnGuard technology that extends a single Cloudbrink security and connectivity policy across users, devices and machines, taking aim at complex multi-product enterprise security stacks. The expanded platform gives enterprises an alternative to deploying and managing separate Cisco products for secure access, internet security, AI security and remote connectivity, consolidating ZTNA, Internet Security, Secure Web Gateway and AI security into one offering. OnGuard allows policy enforcement to begin when a device itself comes online, even before a user logs in, and to continue independently of the user session, with features including instant OnGuard availability, admin authorization, admin session termination, centralized visibility and selective policy control. CEO Prakash Mana said a single Cloudbrink platform can eliminate a significant portion of the Cisco secure-access stack, arguing that Umbrella, AnyConnect, Secure Access and AI Defense still force enterprises to manage multiple technologies, policies and operating models. The expansion builds on existing deployments, including at one U.S. insurance company where Cloudbrink replaced an environment that included Cisco AnyConnect and Fortinet, moving 300 employees on the first day and more than 600 during the first week, after which remote-connectivity support calls "pretty much disappeared," according to its VP of IT.
Digital Economy Ministry Teams Up with Thailand Post and PDPC to Develop D/ID Digital Delivery Code
The Ministry of Digital Economy and Society, together with Thailand Post Company Limited and the Office of the Personal Data Protection Committee, is pressing ahead with the development of the Digital Post ID, or D/ID, a digital delivery code aimed at raising data security in the parcel delivery process. The system replaces the display of full names, addresses and phone numbers on envelopes or parcel boxes with a QR Code, reducing unnecessary exposure of personal data while improving convenience and accuracy in identifying delivery points. Mr. Chaichanok Chidchob, Minister of Digital Economy and Society, said D/ID is one of the key infrastructures that will raise the country's data management to be more secure and ready for future use. Dr. Danant Suphattharaphun, Chief Executive Officer and Managing Director of Thailand Post Company Limited, said Thailand Post has begun piloting D/ID with more than 24,000 of its personnel and plans to expand awareness and trial use to the general public, as well as extend linkages with government agencies, the private sector and various service providers. At present, members of the public can already download D/ID and create their own code for use. Meanwhile, Police Colonel Surapong Plengkam, Secretary-General of the Personal Data Protection Committee, said the PDPC will continue to support and advise Thailand Post, promoting the adoption of Privacy by Design principles and the use of only necessary data from the design stage of systems and services.
EU to Propose Social Media Ban for Children Under 13
European Commission President Ursula von der Leyen said the EU will push for social media restrictions for children under 13 years, with a draft proposal set to be introduced on Thursday. The draft will impose strict age restrictions and verification requirements on social media, video-sharing platforms, app stores, online games, AI companions, and conversational AI chatbots, according to Bloomberg. "No social media under the age of 13. No personal account under the age of 15," von der Leyen said in her annual address on Wednesday, adding that the proposed law would allow 13- and 14-year-olds to have accounts with limited features and parental supervision. Companies that fail to meet the requirements could face fines of up to 6% of their annual sales. The bloc's upcoming rules follow Australia's ban last year on social media for children aged under 16, while individual EU member states have also been looking at setting their own restrictions.
Gujarat Police to Seek Explanation from Google Over Case Involving More Than 510,000 Fake Gmail Accounts
Police in the western Indian state of Gujarat plan to seek an explanation from Google over gaps in its security measures, in connection with a case in which they busted a large network of fake Gmail accounts. One police official disclosed this to Reuters on the 15th. State police this week busted a wide-ranging criminal network accused of sending bomb threat emails to government agencies and others, and arrested two people. During the investigation, they identified 513,847 Gmail accounts and passwords that had been in operation since 2022. A senior official in the state police's cybercrime unit told Reuters that they would send a letter to Google seeking policy changes so that such security measures cannot be circumvented, and indicated a plan to formally designate Google as a subject of investigation. What police find particularly problematic is that two-factor authentication had been set up on each of the fraudulently created accounts, and they are also investigating how the criminal organization managed to set up and operate two-factor authentication on more than 500,000 accounts. The investigation was triggered by a bomb threat email received by the Gujarat state government on the 10th. The email was sent ahead of the BRICS summit held in New Delhi and threatened that countries cooperating with India would also be targeted, but according to police, all of the bomb threats were false.
Okta, IBM, Broadcom and Dataiku Ship Agent Governance Products as Category Decouples From Platforms
Four major infrastructure vendors have now shipped standalone agent governance products at general availability, a rush that has itself become the signal that agent governance is decoupling from individual platforms to become a category of its own. Okta pushed furthest into new territory with its July 2026 product innovations, shipping Agent-to-Agent Connections at general availability to enable secure multi-agent workflows through temporary runtime tokens that enforce which agents may invoke which others, alongside the Agent Gateway, available as a research release, which sits between agents and the systems they access without requiring code changes. IBM's Think 2026 announcement positioned next-generation watsonx Orchestrate as an agentic control plane, introduced in June on AWS and IBM Cloud, offering runtime policy management, credential health monitoring, and an Agent Access overview across an organization's entire agent estate. Broadcom embedded governance directly into the compute fabric with AgentMinder, unveiled at VMware Explore on August 31 and shipping at general availability bundled into the VMware Private AI Cloud, treating agents as enterprise-grade identities bound to a declared mission, permitted intents, approved tools, and authorized resources. Dataiku made a different architectural bet, with Dataiku Agent Management scanning agents across nine platforms including Microsoft Copilot Studio, Salesforce Agentforce, AWS Bedrock, and Google Vertex to provide a cross-platform control tower for discovery, certification, and audit-readiness. The urgency tracks to two numbers: Menlo Ventures found that 76 percent of AI applications are purchased rather than built internally, and the Cloud Security Alliance reported in February that 84 percent of organizations doubt they could pass a compliance audit focused on agent behavior or access controls.
Government races to link financial data across all agencies to block scammers, system design to be finished in 30 days
Dr. Ekniti Nitithanprapas, Deputy Prime Minister and Minister of Finance, disclosed that the government is preparing to raise the level of cyber threat prevention by linking the back-end systems of all agencies together so that tracking and problem-solving can be faster. The meeting of the subcommittee on financial data linkage, known as the Connect the Dots committee, resolved on three matters: upgrading identity verification to international standards in line with the Financial Action Task Force, on par with global financial hubs such as Singapore or the United Kingdom; linking financial data across all relevant agencies, including the Ministry of Finance, the Bank of Thailand, the Anti-Money Laundering Office, the Securities and Exchange Commission, the Thai Bankers' Association, and the Royal Thai Police; and establishing an integrated national incident-reporting management system by the Ministry of Digital Economy and Society together with the Royal Thai Police, as well as a system to freeze financial routes quickly. The data linkage between agencies must have a consent system from the data owner, and an anonymous transaction data center will be set up so that data analysts can keep pace with scammers. This follows the discovery of a loophole whereby transactions exceeding 5 million baht must be reported, so offenders shifted to making transactions below 5 million baht. The Permanent Secretary of the Ministry of Finance has been assigned to integrate all four areas of work so that the system design is completed within 30 days.
Oracle Begins New Layoffs as AI Infrastructure Debt Mounts
Oracle has begun a new round of layoffs, following job cuts earlier this year, as the company racks up billions in debt to fund AI infrastructure. The move marks the latest in a series of workforce reductions at the technology giant. Separately, a dark web marketplace is reportedly selling scans of more than 153 million drivers' licenses, a breach experts warn could increase identity theft and fraud risks because licenses are difficult to replace. Elsewhere, experts are predicting the 2026 tax brackets, which may be wider, though that does not necessarily mean taxpayers will pay less.
IDrive Adds Microsoft Entra ID Backup to Its Microsoft 365 Protection Suite
IDrive announced on September 14, 2026 that it has added Microsoft Entra ID Backup to its IDrive Microsoft Office 365 Backup solution, extending protection to the identity and access management layer. The new capability automatically backs up critical Entra ID objects and settings to the IDrive cloud, covering users, groups, roles and administrators, administrative units, app registrations, enterprise applications, devices, policies, sign-in logs, audit logs, device configurations, device compliance policies, and BitLocker recovery keys. Key features include frequent automated snapshots, change tracking with historical comparison views, granular and bulk recovery that preserves relationships, point-in-time restore, centralized management of Entra ID and Office 365 backups from a single web console, and AES-256 encrypted storage in the IDrive cloud. The addition complements existing IDrive Microsoft Office 365 Backup support for OneDrive, Outlook, SharePoint, Teams and Groups. Microsoft Entra ID Backup is available for $10 per Entra ID seat per year with unlimited storage.
Over 153 Million Driver's License Records Surface on Dark Web After IDScan Breach
More than 153 million driver's license records from the U.S. and Canada have appeared for sale on the dark web, prompting the Pentagon and the FBI to respond. Cybersecurity journalist Brian Krebs found the trove through a dark-web service called Nexus, which advertised the records and claimed to have been pulling data for more than a year; a search for Canadian licenses returned roughly 1.1 million results, suggesting the overwhelming majority of the 153 million-plus records were American. The database reportedly included scans of the front and back of licenses, customer photos and images captured under infrared and ultraviolet light, and Krebs found a license belonging to Defense Secretary Pete Hegseth, prompting the Pentagon to tell TechCrunch it is aware of the reports and is evaluating them; the license of an FBI assistant director was reportedly exposed as well. IDScan.net, the identity-verification company identified as the apparent source, has acknowledged that an unauthorized party may have accessed or copied customer information stored in its cloud, including names and government-issued ID numbers, though it has not confirmed that 153 million distinct people were affected. The company is notifying potentially affected people and offering free credit monitoring and identity-protection services, with enrollment available at 1-833-516-2980.
Trust Stamp Expands ID Dataweb Partnership Across Enterprise Customers
Trust Stamp Inc is expanding its partnership with ID Dataweb, extending the identity verification firm's use of Trust Stamp's biometric tokenization and identity fraud mitigation technology across its enterprise customer base. The expansion builds on three years of joint work serving one of the three largest life insurance providers in the United States, Trust Stamp said. ID Dataweb, a provider of identity threat detection and risk mitigation services, will now use Trust Stamp's technology more broadly across its growing roster of enterprise clients. Trust Stamp's patented Irreversibly Transformed Identity Token technology converts biometric data into tokens that can be revoked, a design meant to reduce the risks of storing raw biometric data while enabling identity verification. Trust Stamp president Andrew Gowasack said expanding the relationship represents an important next step in the company's commercial growth strategy and creates an opportunity to bring its IT2 technology to a broader range of enterprise customers, while ID Dataweb chief operating officer Matt Cochran said the partnership shows the value of combining innovative, privacy-preserving technologies to solve real-world identity challenges.
Dreamforce 2026 to Pitch Unified Agent Trust as Market Still Runs on Three Separate Layers
Salesforce is positioning its Trust Boundary as the definitive architecture for the agentic enterprise at Dreamforce 2026, but the trust stack has not coalesced into a single platform and has instead fractured into three distinct, often incompatible domains: governance specification, runtime authority, and runtime enforcement. Governance specification remains a crowded, nascent field where enterprises cobble together stacks from vendors like Okta, IBM, Broadcom, and Dataiku, a focus supported by the UC Berkeley MAST taxonomy finding that 79% of multi-agent failures trace to specification problems rather than model limitations. Runtime authority is shifting from static permissions to dynamic models, with Akeyless introducing intent-based access control and CrowdStrike pushing SPIFFE-based identities, though Akeyless CEO Oded Hareven says there is still no single place issuing, governing, and revoking that authority. Runtime enforcement, the domain of bidirectional API security and agent fabrics, was recently exemplified by the expanded integration between Akamai and MuleSoft, and matters because 87% of organizations reported an API security incident in 2025. Despite the marketing at Dreamforce, no single vendor covers all three layers, and the unified solution is in practice a multi-vendor assembly project, a fragmentation that feeds a merchant readiness paradox in which 42% of merchants are testing agentic systems while only 3% of transactions actually involve agents. Gartner warns that 40% of autonomous AI efforts will be partially derailed by governance gaps discovered only after production incidents, and with Nvidia's $12.9 billion acquisition of Hugging Face and Stripe's $7.5 billion acquisition of OpenRouter, the industry's largest acquirers are buying routing infrastructure at premium valuations, signaling that the orchestration layer's fragmentation is itself the margin risk.
UK's Revolut Mistakenly Gave Customer Data to Fake Government Emails, Including Bitcoin Transaction History
British fintech company Revolut responded to information disclosure requests impersonating government agencies and handed over some customers' personal and financial information to third parties, it has emerged. The Crypto Times, a crypto-focused media outlet based in Dubai, UAE, and India, reported the matter on September 12. The information provided reportedly included copies of passports and Bitcoin transaction histories. The emails requesting the disclosure came from unauthorized accounts created within domains actually used by government agencies and carried legitimate domain authentication credentials, leading Revolut to judge them as formal requests and provide customer information. The company said that after providing the information it contacted the government agencies directly to confirm the legitimacy of the requests, and after discovering the existence of the fraudulent email accounts, it blocked the addresses in question on its internal systems and reported the matter to the relevant regulators. Mark Karpelès, former CEO of Mt.Gox, was reportedly one of the customers who received a notification on September 12. The number of affected customers and the name of the government agency that was impersonated have not been disclosed, nor is it clear when the information was handed to third parties or whether it has since been misused.
ManageEngine warns of Synthetic Identity as AI and Deepfake accelerate financial fraud
ManageEngine has revealed that the financial world is on heightened alert against fraud using fake identities, or Synthetic Identity, after cybercriminals upgraded their tactics to use Deepfake to create virtual identities that pass facial-scan verification. Nattawich Wongsirojn, Regional Technical Head of ManageEngine, stated that detecting synthetic identities has become harder because of the use of AI tools and automated financial systems, combined with rising data leaks, causing massive damage to organisations across banking, fintech, telecommunications and other businesses. Meanwhile, the Electronic Transactions Development Agency, or ETDA, warns that Deepfake technology could weaken Digital ID and e-KYC systems that rely on facial recognition, opening a channel for criminals to verify false identities. In Thailand, as of December 2025, banks had suspended services for more than 223,000 individuals suspected of fraudulent behaviour and frozen more than 3.47 million mule accounts, while the time taken to identify and close mule accounts fell from about 3 days in January 2025 to just 10 hours in July. ManageEngine proposes five points for tackling this threat, from using AI to detect anomalies and multi-level identity verification to cooperation between the public and private sectors and a legal framework that keeps pace with advancing fraud techniques.
Okta Shares Outpace S&P 500 as Earnings Estimates Rise
Okta shares have returned +10.4% over the past month, outpacing the Zacks S&P 500 composite's -2% change, while the Zacks Security industry, to which Okta belongs, lost 7.8% over the same period. The cloud identity management company is expected to post earnings of $0.93 per share for the current quarter, a year-over-year change of +13.4%, and the Zacks Consensus Estimate has moved +6.2% over the last 30 days. For the current fiscal year, the consensus earnings estimate of $3.93 indicates a year-over-year change of +12.3% and has changed +9.8% over the last 30 days, while the next fiscal year's consensus estimate of $4.44 indicates a change of +13% and has changed +3.5% over the past month. Okta's consensus sales estimate of $815.52 million for the current quarter points to a year-over-year change of +9.9%, with the $3.22 billion and $3.55 billion estimates for the current and next fiscal years indicating changes of +10.4% and +10.1%, respectively. In the last reported quarter, Okta reported revenues of $805 million, up +10.6% year over year, and EPS of $1.05 versus $0.91 a year ago, beating the Zacks Consensus Estimate of $792.14 million by +1.62% on revenue and by +9.38% on EPS; the company is rated Zacks Rank #3 (Hold) and graded F on the Zacks Value Style Score.
Yod Chinsupakul elected President of TEPA, pushing to raise electronic payment standards
Yod Chinsupakul, Chief Executive Officer of LINE MAN Wongnai and LINE Pay Thailand, has taken up the post of President of the Thai E-Payment Trade Association, or TEPA, which has more than 30 member service providers. He announced a direction to raise the security of Thailand's electronic payment systems under a cooperation framework to prevent illegal transactions in the financial sector of the Bank of Thailand, of which TEPA is one of 11 participating agencies. The work will be driven through three key principles: elevate, make difficult, and act quickly, covering the raising of screening standards, making it harder to exploit the system for wrongdoing, and speeding up information exchange and system adjustments to keep pace with new forms of threats. TEPA's role in the framework includes raising the screening of both major and sub-merchants, strengthening identity verification of e-money users and electronic fund transferors, linking proactive surveillance data to regulators, and joining forces with the Bank of Thailand and member networks through operational-level working groups and coordinators.
Trezor Users Hit by Convincing Phishing Attack After Third-Party Email Breach
Trezor users have been targeted by an unusually convincing phishing campaign after attackers compromised a third-party email provider used by the hardware wallet manufacturer. The breach occurred at the third-party email provider rather than at Trezor itself, and the attackers leveraged that access to send fraudulent messages to the company's user base. The campaign is being described as unusually convincing, raising concerns that recipients could be tricked into compromising their wallet credentials or funds. No further details on the number of users affected or the specific contents of the phishing messages were provided.
Ransomware Attacks Hit Record 123 Cases in First Half, NPA Releases Threat Assessment
The National Police Agency on the 10th released its assessment of the cyber threat landscape, revealing that 123 cases of ransomware, malware that encrypts data for ransom, were confirmed in the first half of this year from January to June, the highest for any half-year period since statistics began being kept in 2020. Reports of damage rose by 7 cases compared with the same period last year, with 31 of them involving large companies. More than half of all victims took a month or longer to recover, nine companies saw all operations halted, and in 60 percent of cases the damage exceeded 10 million yen. Suspicious accesses detected by the agency surged to about 13,700 per day in the first half, 1.5 times the level of a year earlier, and the agency said the sources of ransomware and other attacks may be probing devices for vulnerabilities. Losses from internet fraud rose 45 percent year on year to 175.5 billion yen, the worst pace on record, while reports of phishing, in which fake emails lure users into giving up passwords and other information, totaled about 730,000, with analysis estimating that 45 percent of the servers sending them were located in China, followed by Japan at 14 percent and Brazil at 10 percent.
SailPoint raises FY2027 ARR target to $1.38B, outlines FY2029 goals
SailPoint reported fiscal Q2 2027 ARR of $1.231 billion, up 25% year-over-year, and raised its full-year ARR guidance to $1.38 billion while reiterating long-term targets of at least $2.1 billion ARR and at least $800 million in AI-driven ARR by fiscal 2029. The company's AI-driven ARR has already crossed $70 million, and SaaS ARR grew 36% to $847 million, representing 97% of net new ARR. Management highlighted the launch of SailPoint Identity Security with generally available Agentic Fabric, the acquisition of Entro Security, and new connectors for Snowflake, Databricks, and Cursor. CFO Brian Carolan guided Q3 ARR to $1.29 billion, revenue to $328 million, and adjusted EPS of $0.07 to $0.08, while noting that a higher SaaS mix creates a temporary revenue timing headwind of approximately $5 million.
Visa Unveils Singapore Security Roadmap 2026 to Combat AI-Driven Fraud
Visa has unveiled its Singapore Security Roadmap 2026 and Beyond, a comprehensive strategy to strengthen the resilience of Singapore's digital payments ecosystem against evolving fraud, scams, and cyber threats. The roadmap outlines six strategic priorities, including strengthening cybersecurity, advancing authentication, enabling safer transactions through tokenisation, transforming eCommerce checkout experiences, leveraging foundational standards and risk programs, and building a resilient payments ecosystem to combat fraud and scams in the AI era. Visa's study shows that close to seven in 10 Singapore residents trust digital payments, but 42 per cent have encountered scams, with only 8 per cent losing money. To address these threats, Visa is investing in AI-powered fraud detection, tokenisation, and authentication innovations like passkeys and biometrics, deploying over 150 AI and machine learning models globally. The roadmap emphasizes ecosystem-wide collaboration with regulators, financial institutions, merchants, and fintechs to enhance cyber resilience and intelligence sharing.
Trust Stamp integrates ID verification with Jack Henry's Banno platform
Trust Stamp Inc has integrated its driver's license verification technology with Jack Henry's digital banking platform, making it available to community and regional financial institutions. The AI-powered identity solutions provider embedded its AAMVA Driver's License Data Verification solution using the Banno Digital Toolkit, which is the API framework of the Banno Digital Platform. This integration adds Trust Stamp to Jack Henry's ecosystem of over 1,000 fintechs serving more than 7,200 financial institutions, addressing rising identity fraud driven by generative AI. The AAMVA DLDV system queries official DMV records in real time to confirm that driver's license data matches active government records, shifting from document authentication to data verification without adding user friction. Trust Stamp's president, Andrew Gowasack, said the collaboration brings high-assurance protection directly into native banking experiences, enabling community banks and credit unions to deploy the 'gold standard' of identity trust.
eMazzanti's Messaging Architects Partners with miniOrange for Unified IAM
eMazzanti Technologies' Messaging Architects division has formed a strategic partnership with miniOrange to deliver unified identity and access management for legacy and hybrid IT environments. The alliance brings enterprise Single Sign-On, Multi-Factor Authentication, Privileged Access Management, and Unified Endpoint Management to organizations running on-premises systems, Novell GroupWise, and mixed SaaS environments. The collaboration, developed by eMazzanti President Carl Mazzanti and miniOrange's Gaurav Bansod under CEO Anirban Mukherji, aims to serve businesses underserved by cloud-only identity platforms. The solution consolidates identity management across disconnected platforms like Oracle, Slack, and Zoom without requiring a full cloud migration, extending the life of existing investments for SMBs in sectors such as healthcare, legal, and education.
Okta Shares Surge 20% on AI-Driven Beat-and-Raise Quarter
Okta, Inc. shares surged as much as 29% after the identity security company beat fiscal second-quarter estimates, driven by AI-related security demand. Adjusted earnings per share came in at $1.05 versus $0.97 expected, and revenue rose 11% to $805 million versus $795 million expected. Net income totaled $116 million, up from $67 million a year earlier, and remaining performance obligations, a measure of backlog, climbed 17% to $4.86 billion, beating the $4.70 billion analysts anticipated. Okta made its "Okta for AI Agents" tool available to all customers during the quarter, with new products accounting for 30% of total bookings and "dozens" of AI-related deals closed, including a multi-million-dollar healthcare contract. The company raised full-year revenue guidance to $3.22 billion to $3.23 billion, and CEO Todd McKinnon said, "As AI agents transform every layer of technology, every agent needs a trusted identity."
Apple faces $2.7 billion U.K. lawsuit over app tracking rules
Apple faces a £2 billion ($2.7 billion) lawsuit filed on Thursday at London's Competition Appeal Tribunal on behalf of thousands of app developers, with the company accused of abusing its market position through its App Tracking Transparency framework. The claim, brought by ATT Collective Action Limited, centers on Apple's App Tracking Transparency feature, which launched in April 2021. According to the suit, Apple held third-party apps to a double-consent standard before they could track users across apps and websites, yet imposed comparatively lighter obligations on its own advertising and data-collection operations. Ann Pope, a former senior director for antitrust at the U.K.'s Competition and Markets Authority and director of ATT Collective Action Limited, is leading the claim, stating that the policy resulted in significant harm to businesses dependent on Apple as a gatekeeper. The U.K. case follows regulatory action in several European countries, including a €98.6 million fine by Italian regulators in December and a €150 million penalty by French authorities in April 2025, as well as a German order to redesign the prompts. This lawsuit is one of several collective actions at the tribunal, which recently saw Alphabet's Google reach a £260 million settlement over similar allegations.
BOT Sets New Standards for Thai Financial System to Curb Illegal Money Throughout the System
The Bank of Thailand (BOT) has announced an upgrade to the standards of the Thai financial system to curb illegal money throughout the system. Mr. Witai Rattanakorn, Governor of the BOT, stated at The Bangkok Business Summit 2026 that the BOT will collaborate with the financial sector under the theme "One Intent, United Power, Protecting the Thai Financial Sector" on September 10th to declare its intention not to let the financial sector become a tool for illegal transactions. Key measures include limiting high-value cash withdrawals, which has reduced withdrawals of 5 million baht or more by 52%; regulating online gold trading; and enhancing KYC measures in currency exchange businesses, bringing over 2,000 operators into the same standard. Losses from transfer fraud decreased from 8.6 billion baht in Q2 2024 to 1.5 billion baht in Q2 of this year, a reduction of 80%. The BOT also plans to announce the Bangkok Blueprint framework with the IMF at the October meeting to address digital fraud.
Nokia and BeeHealthy Partner for Network-Based Healthcare Verification
Nokia has announced a commercial agreement with BeeHealthy, a digital healthcare platform owned by Mehiläinen, to integrate its Network as Code technology into BeeHealthy's consumer-facing applications, replacing SMS one-time passcodes with network-based verification for secure patient access. This makes BeeHealthy the first healthcare-sector commercial customer for Nokia's Network as Code platform, which aggregates operator networks into a developer-friendly platform for embedding trusted network capabilities. The collaboration introduces a new monetizable enterprise use case for operators and builds on Nokia's momentum from MWC26, where it announced expanded partnerships. BeeHealthy's white-label SaaS platform serves healthcare and veterinary providers, social-care organizations, and insurers across Finland, Sweden, Germany, Estonia, the Netherlands, and the United Arab Emirates. Additional APIs being integrated include SIM Swap/Number Recycling to prevent fraud, Location Verification to reduce missed appointments, and KYC Match for identity validation, with future exploration of Quality on Demand for latency-sensitive services like video consultations.
CrowdStrike Launches Agentic Identity Provider for AI Agents
CrowdStrike has introduced the CrowdStrike Agentic Identity Provider, a new solution that establishes trusted identities for AI agents, positioning Falcon Next-Gen Identity Security as the identity control plane for the agentic enterprise. The Agentic IdP automatically registers every AI agent discovered by Falcon Guardian, issues cryptographically verifiable identities, brokers short-lived and tightly-scoped tokens, and attributes every action to the human or workload behind it. This foundation enables Continuous Identity, which replaces static policies with real-time, risk-aware enforcement. Scott Kriz, GM of Continuous Identity at CrowdStrike, emphasized that traditional identity providers are not built for agents that act autonomously. The announcement was made at Fal.Con 2026 in Austin and Las Vegas.
Epson and STOPware Partner for Full-Color Visitor Badge Printing
Epson and STOPware have announced a partnership to integrate Epson's ColorWorks on-demand color label printing technology with STOPware's PassagePoint visitor management platform, enabling organizations to produce full-color, photo-ready visitor badges in real time. The solution, which includes the ColorWorks CW-C4000 and CW-C6000 printers, supports color-coded access levels, department identifiers, logos, and QR codes to enhance security and operational efficiency at visitor sign-in locations. Michael Weitz, product manager for ColorWorks at Epson America, noted the benefits for high-traffic environments such as hospitals, schools, corporate campuses, and government facilities, while STOPware COO Debbie Pendleton emphasized the importance of visual clarity without slowing visitor flow. The partnership aims to replace traditional monochrome or pre-printed badges, which are harder to read and easier to replicate, with a more secure and efficient on-demand printing solution.
Lookout Integrates Android Device Trust and Joins Partner Program
Lookout, Inc., a leader in AI security for the mobile workforce, has integrated Android Device Trust APIs into its Mobile AI Security Platform and joined the Android Enterprise Partner Program. The integration provides hardware-verified patch telemetry directly from Google, enabling Lookout to strengthen its exposure management capabilities. This data feeds Lookout's Mobile Software Exposure Center engines, which correlate OS patch levels, firmware variances, and app binary compositions against Known Exploited Vulnerabilities to help security teams identify and remediate mobile software risks. The integration also enhances Lookout's existing partnerships with Google Cloud BeyondCorp Enterprise, Google SecOps, and Cloud Identity, allowing for automated risk-based enforcement and unified SOC intelligence. The updated Device Trust signals are available immediately for all Lookout Mobile AI Security Platform customers running Android 10 and above.
Dropbox says about 5,000 accounts hacked in August
Cloud storage service Dropbox said on Tuesday that about 5,000 accounts were compromised in August, with hackers viewing and downloading content stored on the platform. The company said hackers accessed files in less than a third of the affected accounts. It identified that the unauthorized access occurred in accounts linked to Lenovo IDs that did not have two-factor authentication enabled, and terminated all sessions authenticated through Lenovo IDs. It also said it reported the incident to data protection authorities. Lenovo said it identified a "legacy integration" between Lenovo IDs and Dropbox that could have been used to improperly authenticate certain Dropbox accounts, and that its customers were not affected and the investigation is ongoing. Dropbox shares fell about 2.4% in after-hours trading on Tuesday.
Global Digital Identity Market Report Reveals 75% Consumer Passkey Adoption
A new report from ResearchAndMarkets.com, titled "Global Digital Identity & Trust Infrastructure Market 2026," reveals that 75% of surveyed consumers have enabled passkeys on at least some digital accounts, with 40% using them across most apps and accounts. The report, which profiles key players including Microsoft, Okta, Apple, Google, and 10 others, highlights that over 50% of surveyed organizations still rely primarily on password-based workforce sign-ins, indicating ongoing enterprise migration to passwordless authentication. Opportunities identified include enterprise migration to passkeys and biometrics, integrated identity platforms, interoperable digital IDs for commerce and public services, and stronger identity verification and fraud prevention against deepfakes and synthetic identities. The report also covers trends in identity governance, digital public infrastructure, and regional developments across the UK, Europe, GCC, United States, Brazil, China, India, and Singapore.
Okta Stock Surges 29% on Strong Q2 Results and AI Security Demand
Okta shares jumped 28.63% after the company reported better-than-expected second-quarter fiscal 2027 results, with revenues up 11% year over year to $805 million and adjusted earnings of $1.05 per share beating estimates. Forward-looking demand metrics strengthened as remaining performance obligations rose 17% to $4.86 billion and current RPO grew 14% to $2.59 billion, while free cash flow margin expanded 580 basis points to 28.1%. The company highlighted strong enterprise demand, with customers generating over $1 million in annual contract value up more than 20% to over 600, and new products accounting for roughly 30% of quarterly bookings. Okta also noted expanding partnerships with AWS, Cisco, OpenAI, Databricks, and Snowflake, and the selection by Anthropic as its first identity provider for AI-agent security. For fiscal 2027, Okta expects revenues between $3.216 billion and $3.226 billion and non-GAAP earnings between $3.90 and $3.94 per share, while the Zacks Rank #2 (Buy) rating reflects optimism despite a premium valuation.
authID Selected to Secure Workforce for Global Manufacturing Automation Company
authID, a biometric authentication provider, announced it has been selected by a global leader in industrial automation to secure its Microsoft Entra ID and ServiceNow environments, protecting tens of thousands of employees and contractors. The customer, whose identity was not disclosed, chose authID's Proof identity verification and Verified + PrivacyKey biometric authentication solutions after a proof of concept covering password reset, authentication, and biometric enrollment. authID's platform offers fraud and deepfake detection, support for 16,000 document types across more than 240 countries, and a privacy design that never stores biometric templates, with a false non-match rate of about 0.3% and a false match rate of 1 in 1 billion. The selection was also influenced by pre-built integrations, no professional-services costs during the proof of concept, and authID's quantum-resistant architecture upgrade. According to IBM X-Force, manufacturing has been the most targeted industry for cyber attacks for five consecutive years, accounting for over a quarter of global attacks.
LastPass announced a series of strategic product innovations and enhancements to strengthen identity security in the age of AI, including new tools for access management and customer experience improvements. The company cited IBM's 2026 Cost of a Data Breach Report, which found the average data breach now costs $4.99 million, a record high and 12% increase over last year, with AI-driven attacks up 56% and adding an average of $1 million to breach costs. Among the highlights, LastPass expanded its SaaS Monitoring and SaaS Protect within its Business Max offering, introducing always-on monitoring and more flexible controls. It also launched the industry's first Mobile Smart Scanner, which lets users scan passwords from printed lists and handwritten notes into editable credentials. Additionally, LastPass completed its transition to a Unified Admin Console, began auto-enrolling all consumer accounts in Dark Web Monitoring, and achieved zero-findings SOC 2 and ISO 27001/27701 audits for the second consecutive year. The company also introduced a company-wide sign-up link for business customers and was named a finalist for Best SaaS Product in the 2026 SaaS Awards.
CrowdStrike Stock Surges 20% on Record ARR, Analysts See More Upside
CrowdStrike shares surged 20.5% on August 27 after the company reported record new annual recurring revenue (ARR) and strong quarterly results, raising the question of whether the stock still has room to run. In its fiscal second quarter, CrowdStrike's total ARR increased 25% to $5.84 billion, with new ARR hitting a record $332.8 million, up 51% year over year. Revenue climbed 26% to $1.47 billion, and adjusted earnings per share rose 35% to $0.31, beating consensus estimates. The company's next-generation security offerings, including AIDR, Identity, and Next-Gen SIEM, saw significant ARR growth, with Identity and Next-Gen SIEM ARR rising 39% to $2.1 billion and Cloud and Runtime Security ARR jumping 29% to $905 million. Falcon Flex, its flexible licensing model, saw ARR double to $2.3 billion, and new customers are increasingly starting with Flex, accounting for 34% of new Flex ARR. With the stock nearly doubling this year, investors are weighing whether the strong growth can continue.
Okta Raises 2027 Outlook on AI-Agent Security Demand
Okta, Inc. reported second-quarter 2026 revenue of US$805 million and net income of US$116 million, and raised its fiscal 2027 guidance to full-year revenue of about US$3.22 billion, citing stronger-than-expected demand for its identity security platform. The company highlighted growing interest in tools securing autonomous AI agents, with new AI-focused products contributing meaningfully to bookings and helping define a new identity security category. The updated outlook, which projects revenue between US$3.216 billion and US$3.226 billion, is tied directly to the AI-agent security theme that lifted bookings this quarter. However, the decision to shift professional services to partners introduces a small growth headwind but could focus the business more tightly on higher-value identity products. Okta's narrative projects US$3.9 billion revenue and US$536.4 million earnings by 2029, requiring 9.6% yearly revenue growth and about a US$289.4 million earnings increase from US$247.0 million today, while some analysts expect even higher figures of US$4.2 billion revenue and US$795 million earnings by 2029.
Okta's RPO Growth Accelerates to 17% as Revenue Rises 11%
Okta reported fiscal second-quarter 2027 results that showed a bookings recovery, with revenue rising 11% year over year to $805 million and non-GAAP diluted earnings up 15% to $1.05 per share, beating consensus estimates of $793 million and $0.97 per share. The company's remaining performance obligations, or subscription backlog, grew 17% to $4.858 billion, outpacing revenue growth by six percentage points, while current RPO increased 14% to $2.585 billion, both accelerating from the first quarter. New products contributed about 30% of bookings, up from 25% in the prior quarter, and customers with at least $1 million in annual contract value grew 22% to 605, representing over $1 billion in aggregate ACV. GAAP operating income rose to $107 million from $41 million, lifting the operating margin to 13%, and free cash flow increased to $227 million from $162 million. However, the company guided third-quarter cRPO growth of 11% to 12%, a slowdown from the second quarter's 14%, though it raised its full-year revenue outlook to $3.216 billion to $3.226 billion and free-cash-flow forecast to $910 million to $930 million.
Okta Jumps 29% on Earnings Beat, AI Agents Seen as New Bottleneck
Okta, Inc. jumped 28.6% on August 27 to close at $172.91 after reporting better-than-expected quarterly results, reaching a four-year high. The company's revenue rose 11% to $805 million, subscription revenue climbed 12% to $793 million, and current remaining performance obligations increased 14% to $2.585 billion, with free cash flow at $227 million. Okta also raised its full-year guidance, and analysts highlighted large-customer momentum and stronger performance in core identity products. CEO Todd McKinnon emphasized that every AI agent needs a trusted identity and clear controls, and Okta is building products to discover agents, secure their connections, govern their actions, and respond to incidents. However, management did not break out a standalone AI-agent revenue stream, and the quarter was still driven by familiar businesses such as workforce identity, customer identity, and Identity Governance. Insider Monkey's database showed 58 hedge funds holding OKTA as of Q2, up from 49 in Q1, and short interest stood near 6.45 million shares, about 3.89% of the public float.