Cybersecurity Risks Extend Beyond Passwords to Identity Verification
A growing threat is emerging in the cybersecurity landscape, one that targets not just passwords or multi-factor authentication (MFA), but the very foundation of identity verification. While traditional security measures have become increasingly robust, attackers are now exploiting legitimate processes such as onboarding and account recovery to gain unauthorized access to sensitive systems.
This issue arises at several points in the identity lifecycle where trust is established or re-established. When a new employee joins an organization, when someone loses access to their account, or when a password or MFA factor needs to be reset, there’s a moment of vulnerability that can be exploited by attackers using social engineering tactics. Rather than attempting to bypass MFA or steal credentials directly, they’ll try to convince service desk personnel that they are the legitimate account holder.
The recent joint alert issued by the US Department of State and its allies, including Japan, Canada, and the UK, highlighted North Korean IT workers impersonating foreign nationals to secure employment. These attackers use falsified identity documents, often sourced from third-party suppliers in other countries, to register accounts. This tactic targets technology companies but serves as a warning that onboarding processes can create an initial moment of trust that may not be thoroughly verified.
The same vulnerability exists during the recovery process. Threat actor groups like Scattered Spider are proficient at social engineering, impersonating employees and calling the service desk to reset passwords that grant access to an account. This tactic was linked to the 2025 M&S ransomware breach, which cost the retailer an estimated $400 million through lost sales.
In both scenarios, the question remains: how confidently can an organization verify that the person making the request is who they claim to be? The key to mitigating these risks lies in implementing stronger identity checks, moving beyond relatively weak signals such as service desk asking for employee IDs or phone numbers. These checks can often be researched or manipulated by attackers.
Moreover, the rise of AI has made impersonation more convincing, allowing attackers to use synthetic profiles, manipulated images, cloned voices, and deepfake video to support false identities or make social engineering attempts more believable. All these factors combined create a challenging environment for agents to act with confidence during high-risk identity events.
Solutions that add an extra layer of assurance are crucial in addressing this issue. Tools like Specops Verified ID combine government document scanning and validation with biometric liveness detection, helping service desk agents confidently confirm identities before sensitive actions take place. This approach strengthens verification during onboarding and recovery events, a critical step in preventing unauthorized access to sensitive systems.
For organizations to secure both the login process and the processes around account creation and recovery, it’s essential to implement stronger measures of identity verification. By doing so, they can mitigate the growing threat posed by attackers exploiting legitimate processes for their advantage.
Source: Bleeping Computer — 2026-08-25