Research · curated 19 Jul 2026
Account Compromise in the Agentic Workspace | Proofpoint US
First reported proofpoint.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Account takeover in agentic workspaces matters because a single compromised identity now cascades into connected AI agents, integrations, and OAuth-linked workflows, dramatically widening the impact beyond the initial login.
Proofpoint threat research reviewing ATO activity across 50M+ accounts (November 2024–November 2025) found 99% of organizations were targeted by account takeover threats, 67% were successfully compromised, and 88% of impacted organizations experienced post-access abuse, with spear phishing succeeding twice as often as non-targeted attacks. The analysis argues that in agentic workspaces a compromised identity extends the blast radius into downstream AI agents, OAuth apps, and automated workflows tied to that identity, so login-only controls no longer suffice.