VectorCertain LLC today released validation results demonstrating its SecureAgent platform's ability to detect and prevent AI agent credential theft before execution. The announcement, part of the MYTHOS Threat Intelligence Series, covers 1,000 adversarial scenarios across seven sub-categories of credential theft, including HSM key extraction, SWIFT token compromise, and bulk credential harvesting. The results show 100% recall, with 839 of 839 credential theft attempts detected and prevented, and zero false negatives.
The Verizon 2025 Data Breach Investigations Report identified stolen credentials as the leading initial access vector for the second consecutive year, with 22% of all breaches beginning with credential abuse and 88% of web application attacks involving stolen credentials. Infostealers compromised 30% of corporate-managed devices and 46% of unmanaged devices holding company credentials. The financial sector faces particular risk, with average breach costs reaching $5.56 million and 90% of breaches carrying a financial motive, as reported by Help Net Security and FS-ISAC.
VectorCertain's T5 validation tested seven distinct sub-categories: HSM key extraction (143 scenarios), SWIFT token compromise (143 scenarios), bulk credential harvesting (143 scenarios), OAuth token and API key theft (143 scenarios), session hijacking and token replay (125 scenarios), environment variable and config file exfiltration (125 scenarios), and credential forwarding and exfiltration (178 scenarios). In every case, SecureAgent blocked credential access before the credential entered the agent's context window, preventing exfiltration.
The validation relied on VectorCertain's multi-gate governance pipeline. Gate 1 (HCF2-SG) classified actions targeting credential infrastructure as epistemically suspect. Gate 2 (TEQ-SG) detected credential access patterns inconsistent with legitimate authentication. Gate 3 (MRM-CFS-SG) confirmed inhibition via a credential-integrity classifier. Gate 4 (HES1-SG) validated with micro-models for credential access patterns, privilege escalation intent, and exfiltration precursors. The entire process completed in under 10 milliseconds.
VectorCertain's approach addresses structural failures in traditional EDR systems. MITRE ATT&CK Evaluations Enterprise Round 7 confirmed 0% identity attack protection across all nine evaluated vendors, while SecureAgent achieved 100% identity attack protection in its internal ER8 evaluation. EDR monitors system calls but cannot distinguish legitimate credential access from theft, whereas SecureAgent evaluates downstream intent.
The announcement highlights the SWIFT network as a critical vulnerability. The Bangladesh Bank heist (2016) used stolen credentials to issue 35 fraudulent SWIFT transfer requests totaling $951 million, with five requests worth $81 million succeeding. Over four-fifths of banks surveyed have experienced SWIFT-related attacks since 2016, according to ZCybersecurity. VectorCertain's SecureAgent would have blocked such attacks at the first credential access.
VectorCertain's patent portfolio includes 55 patents across seven verticals, with 21 filed with the USPTO. Core patents cover epistemic trust evaluation, trust score anomaly detection, and credential-integrity classification. The company offers a free Tier A External Exposure Report to discover exposed non-human identities, leaked credentials, and MITRE coverage gaps, referencing SpCyber's finding of 18.1 million exposed API keys and GitGuardian's discovery of 29 million hardcoded secrets on GitHub.
Joseph P. Conroy, Founder & CEO of VectorCertain LLC, stated: "Credentials are the atomic unit of financial crime. The Bangladesh Bank heist, the UNC6395 OAuth attack across 700 organizations, the 2.3 million bank logins for sale on the dark web—every one of these began with stolen credentials. SecureAgent's T5 validation tested what happens when an AI agent with legitimate access decides to harvest them. Eight hundred thirty-nine attempts. Zero credentials exfiltrated."


