
AI is transforming our reality. It’s scary to think that we may not know whether anything we see is real or fake. An email message. Phone call. Security alert. Social media post. If technology does not keep up with safeguards and authentication, we’ll be living in a state of distrust paralysis.
Consider with the addition of AI, identity theft and fraud data breaches are occurring at record levels, fraud losses continue to rise, and cybercriminals have access to decades of stolen personal information. In the first half of 2026 alone, the Identity Theft Resource Center recorded 1,803 data compromises affecting more than 471 million victim notices. Meanwhile, consumer fraud losses reached nearly $16 billion in 2025, up from $12.5 billion just one year earlier.Â
As companies navigate this new era, the focus of cybersecurity is not only how to protect data, but how to authenticate people, communications and transactions and maintain consumer trust.
Based on the trends we’re seeing today, four developments outlined in our annual Data Breach Industry Forecast: Consumers at Risk are likely to shape the cybersecurity landscape in 2027 and beyond.
1. Verification Will Become the Fastest-Growing Security Investment
AI is making it easier than ever to create convincing text, images, audio and video. The result is an environment where digital interactions can no longer be taken at face value. Consumers, employees and businesses will increasingly need assurance that the people and communications they’re interacting with are legitimate.
This is especially critical for security alerts and data breach notices. Organizations face a growing challenge: ensuring consumers view these communications as trustworthy enough to engage with rather than dismissing them as another scam.
In response, the market for identity verification, authentication and trust-building technologies is poised for significant growth. Juniper Research projects the digital identity verification market will expand from $18.8 billion in 2026 to $29 billion by 2030, a nearly 55% increase in just four years.Â
We’ll soon see digital identity solutions, behavioral analytics, passkeys, liveness detection and content verification tools become strategic priorities rather than niche security controls.
The challenge will be balancing security with customer experience. Organizations that create trusted, low-friction verification experiences will gain a competitive advantage. Those that add excessive friction risk driving customers away. We also predict this will become an internal battleground as security teams push for stronger controls while other parts of the business push back over concerns about customer engagement and user experience.
2. Cybercriminals Will Build Digital DoppelgängersÂ
Traditional identity theft is evolving. Today’s criminals are increasingly able to combine data from multiple breaches, public records, social media platforms and other sources into detailed profiles of individuals. AI will allow them to connect and maintain that information at unprecedented scale.Â
As a result, we may see the emergence of what I call the “digital doppelgänger” problem. Instead of using stolen information for a single fraudulent transaction, cybercriminals will maintain continuously updated profiles that can be leveraged across multiple fraud schemes over time. These digital replicas may possess enough information to convincingly impersonate consumers, answer authentication questions and support highly targeted social engineering attacks.Â
Statistics vary, but according to the Apex Data Breach Observatory, hackers have leaked over 300 million private records across 794 breaches in 2025 alone. This has major implications for organizations that still rely heavily on knowledge-based authentication. If criminals already know the answers, organizations will need new ways to validate identity.
In the future, consumers may find themselves competing with AI-powered versions of themselves to prove they are the legitimate account holder.Â
3. Consumers Will Start Fighting Back with Data Obfuscation
For decades, organizations encouraged consumers to share more information in exchange for convenience and personalization.
As consumers grow more aware of data breaches and privacy risks, many are beginning to question the value of providing accurate personal information everywhere they go online. We expect more people to use alternate email addresses, temporary phone numbers, privacy services and other tools designed to limit exposure to their real identities and throw criminals off track.Â
Some may even deliberately create fragmented or incomplete online profiles to make it harder for cybercriminals to build accurate pictures of their lives.Â
While this may help protect consumers, it creates challenges for organizations that rely on high-quality customer data for analytics, personalization and fraud detection.Â
4. Breach Notifications Are Headed for a Breaking Point
The breach notification model hasn’t changed much in over two decades, but consumer behavior has.
People have spent years learning not to trust unsolicited emails, text messages and phone calls. At the same time, AI is making scams increasingly difficult to distinguish from legitimate communications.Â
This creates a growing problem: consumers may begin ignoring or distrusting legitimate breach notifications and fraud alerts.
We are already seeing signs of what could be described as “trust fatigue.” Consumers face a constant stream of warnings, notifications and security messages while also becoming increasingly aware of AI-generated scams and impersonation attacks. A 2025 Jumio Online Identity Study among 8,000 consumers across four countries found that 70% said they are more skeptical of content they see online because of AI-generated fraud, while only 36% said they trust online news content. A U.S. News survey this year shows that almost 80% say AI has made it harder to detect a scam. The struggle is real.
As trust in digital communications declines, regulators and organizations will come under pressure to rethink how breach events are disclosed and how authenticity is established. Sending a notification may no longer be enough. Organizations will need to ensure consumers believe the message is real and know exactly what action to take.
The Bigger Risk Ahead
The cybersecurity industry has spent years preparing for larger breaches and more sophisticated threat actors. Those risks aren’t going away.
But by 2027, the defining issue may not be the theft of data itself. It may be the erosion of trust caused by AI-generated deception, identity impersonation and an overwhelming volume of compromised information.Â
The organizations that succeed will be those that move beyond data protection alone and focus on something equally important: helping customers confidently answer the question, “How do I know this is real?”Â
Â
Join our LinkedIn group Information Security Community!











