From Fake Workers to Account Recovery: The Growing Identity Verification Risk

Cybersecurity teams have made significant strides in strengthening authentication protocols, but a growing threat remains: identity verification risks during onboarding and recovery processes. Despite multi-factor authentication (MFA) and conditional access becoming increasingly common, attackers are exploiting weaknesses in these critical moments to gain unauthorized access.

When employees join or leave an organization, account access is typically established or revoked through various stages of the identity lifecycle. These include onboarding, password reset, MFA factor replacement, and sensitive changes made by the service desk. Rather than relying solely on authentication controls, attackers can deceive service desks into trusting their claims using social engineering tactics.

In July 2026, a joint alert issued by the US Department of State and its allies warned that North Korean IT workers were impersonating foreign nationals to secure employment at technology companies. These actors use fake identity documents, often supplied by third-party vendors in other countries, to register accounts and gain access to systems. The alarming aspect is not the specific campaign, but rather the fact that onboarding creates a moment of initial trust establishment – if checks fail at this stage, attackers can enter the environment with legitimate-looking access.

The same issue arises during account recovery processes. Threat groups like Scattered Spider have demonstrated proficiency in social engineering, posing as employees to call service desks and reset passwords that grant access to accounts. This tactic was linked to the 2025 M&S ransomware breach, resulting in an estimated $400 million loss for the retailer.

The common thread in these scenarios is the challenge of verifying the identity of individuals making requests. Organizations must ask themselves how confidently they can trust that the person claiming to be the account owner actually is.

Verizon’s Data Breach Investigation Report highlights a stark reality: 44.7% of breaches involve stolen credentials. While strong authentication controls are essential, they do not eliminate identity verification risks entirely.

To mitigate these risks, service desks must implement stronger measures for verifying identities during onboarding and recovery events. Traditional checks, such as asking for employee IDs or phone numbers, can be circumvented by attackers who have access to personal information through data breaches or social media. Even when more robust checks are in place, the threat posed by fabricated documents and AI-generated identity evidence remains.

Solutions like Specops Verified ID offer an additional layer of assurance, combining government document scanning and validation with biometric liveness detection to help service desk agents confidently confirm identities before sensitive actions occur. By enhancing verification during high-risk events, organizations can significantly reduce their vulnerability to these threats.

In conclusion, while cybersecurity teams have made significant strides in strengthening authentication protocols, identity verification risks remain a pressing concern. To effectively protect against these threats, it is essential for organizations to prioritize stronger measures of identity verification during onboarding and recovery processes.


Source: Bleeping Computer — 2026-08-25