From Fake Workers to Account Recovery: The Growing Identity Verification Risk
-
Attackers are shifting their focus from cracking passwords to subverting the very processes that prove who you are. The weak points are no longer just the login screen, but the identity verification workflows themselves—such as employee onboarding and account recovery. According to Specops, this is where social engineering attacks are now finding fertile ground, often resulting in fake workers being granted legitimate access to corporate systems.
The core problem is that many identity verification methods rely on data that is either publicly available or easily obtained through phishing. For example, knowledge-based questions, like a mother's maiden name or a previous address, can often be answered with a simple online search. In the context of hiring, attackers may use stolen personal information to pass background checks or verification steps, creating a synthetic identity that appears legitimate on paper. This lets them slip through the cracks and become an insider with all the associated rights and access.
Similarly, account recovery flows are a prime target. If an attacker can correctly answer a few "identity proofing" questions, they can trigger a password reset or take over a session. The article highlights that current systems are struggling to distinguish between a legitimate user who has lost their password and a malicious actor who has purchased or harvested enough personal data to impersonate them.
To address this, the recommendation is to move beyond static, knowledge-based verification and adopt more dynamic and layered approaches. This includes using document verification, biometric checks, and device-based signals that are far harder to replicate. These methods should be applied not just at the initial login, but crucially, during the entire lifecycle of an identity—from onboarding through to account recovery. By making it harder for attackers to pass these intermediary steps, organizations can close a significant security gap that exists between the password and the network.
Source: Unknown
Given that knowledge-based questions and simple document checks are no longer sufficient, has your organization started using behavioral or biometric verification for account recovery, and what has the user impact been?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login