The through-line in this cycle of breach coverage is verification, not encryption or perimeters. In each story, an attacker or a leak exploits the moment before a trusted relationship is properly established, or the moment a familiar brand is used to manufacture trust that was never earned. The breaches that matter in 2026 keep happening in the seam between identity and access, and US organizations keep underinvesting in that seam.

Zero Trust Starts Too Late

Specops, writing via BleepingComputer, argues that Zero Trust architecture has a structural blind spot at onboarding. Zero Trust verifies users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. The recommendation is that identity verification should begin before credentials, MFA methods, and access are issued.

That is a meaningful admission about a framework that has been the dominant US enterprise security model for years. Zero Trust was sold as a correction to perimeter thinking: never trust, always verify. But verification requires something to verify against. On day one, the user's identity record, device posture, and behavioral baseline do not yet exist. Most deployments default to granting provisional trust to get the employee productive, then hardening later. The gap is not a bug in the software so much as a sequencing error in the deployment.

For US technology companies, this matters commercially as much as technically. Enterprise buyers have spent heavily on identity providers and access brokers, and the onboarding seam is exactly where those investments produce the least coverage. The practical implication from the Specops argument is that verification has to move upstream, into the hiring or provisioning workflow, before credentials are minted. That shifts budget and responsibility toward HR-adjacent systems and identity proofing vendors, and it puts pressure on the assumption that a corporate email address is itself evidence of legitimacy.

Fake AI Pages and the Login Habit

BleepingComputer also reports a campaign targeting ad account managers that uses fake ChatGPT, Gemini, Claude, and Perplexity sites. The pages steal login credentials and multi-factor authentication codes through browser-in-browser attacks. The technique is not new. Browser-in-browser attacks render a convincing login window inside a page, complete with a plausible address bar, so the victim never leaves what looks like a legitimate site.

What has changed is the lure. Ad account managers are valuable targets because advertising accounts carry payment methods, spend authority, and access to business pages. Spoofing the AI tools those managers now use daily is a low-cost way to reach them. The MFA code theft is the critical part: the campaign is not just harvesting passwords, it is defeating the second factor in real time by relaying the code into a live session.

For US consumers and businesses, the lesson is that MFA is not a ceiling. Any authentication flow that can be proxied can be phished. The AI branding is incidental to the mechanism, but it is not incidental to the targeting. The tools named in the BleepingComputer report are the ones that have become default work surfaces, which makes their login pages a reliable mask.

The Brand Trust Problem

The two breach-adjacent stories share a root cause with a third that is not a breach at all. The Verge reports that new leaks revealed more details about the Fitbit Edge, including a reported price of €179 in Europe and £159 in the UK, according to leaked details shared by Dealabs. Following more images of the previously leaked device surfacing a few days ago, the leaks keep arriving ahead of any official announcement.

That story sits on this beat because it is a data exposure story, just not a credential one. Unreleased product details, pricing, and imagery are leaking out of Google's supply and retail chain before the company controls the message. The pattern is the same as in the other two stories: information is released to people who were never authorized to hold it, because access was granted earlier and more broadly than the risk warranted. A retail partner, a packaging vendor, or an internal system becomes the onboarding gap in miniature.

What the Pattern Costs US Firms

Taken together, the three items describe a consistent failure mode. Trust is extended at the point of least information. In Zero Trust, that is the new hire on day one. In the phishing campaign, that is the ad manager clicking a login page that looks like a tool they already use. In the Fitbit Edge leaks, that is every party in the distribution chain that needs the product details before launch.

The US market consequence is that security spending keeps chasing the wrong end of the timeline. Companies buy detection and response for established accounts, then treat onboarding as an administrative formality. Attackers and leakers both gravitate to the formality. The Specops argument, as relayed by BleepingComputer, is essentially that identity verification has to happen before credentials exist, which is a harder problem than deploying another MFA prompt because it requires coordination between security, HR, and IT at the moment of hire.

There is also a measurable asymmetry in the phishing campaign. The BleepingComputer report shows attackers targeting a specific job function, ad account managers, rather than a broad population. Narrow targeting raises the success rate and lowers the noise, which makes it harder for email security and browser defenses to flag. US advertisers operate in a market where account compromise translates directly into fraudulent spend and lost client trust, so the downstream cost of a single stolen session is high.

The Leak Economy Around Hardware

The Fitbit Edge reporting is a reminder that not all exposure is malicious. Dealabs' leaked details, reported by The Verge, and the earlier images are the kind of disclosure that comes from legitimate partners and channels. For US consumers, the effect is that pricing and features are known before Google announces them, which compresses the company's marketing window and cedes narrative control. For Google, it is a supply chain information governance problem, not a firewall problem. The same question applies: who needed to know this, and when?

What to Watch

Three things are worth tracking against these reports. First, whether US enterprises begin moving identity proofing into the pre-credential stage, as the Specops argument implies, and whether identity vendors ship products for the onboarding gap rather than the steady state.

Second, whether browser-in-browser defenses improve against live MFA relay, since the BleepingComputer campaign shows the technique is being applied to high-value work accounts rather than consumer logins. Phishing-resistant authentication is the obvious counter, but adoption among ad and marketing teams is uneven.

Third, whether Google can tighten the flow of Fitbit Edge information before launch, and whether the leaked €179 and £159 figures reported by The Verge and Dealabs hold up. None of these is a dramatic story on its own. Together they describe the same unresolved question: who gets trusted, and how early.

More on this beat: Cybersecurity on TechManNews.

#data breaches#zero trust#phishing#MFA#identity verification#supply chain leaks

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.