Zero Trust Architecture’s Achilles’ Heel: Human Error and Identity Verification Gaps
A disturbing trend has emerged in the world of cybersecurity: even organizations with robust Zero Trust architectures are vulnerable to attacks that exploit human error during the onboarding process. Specifically, attackers are targeting identity verification weaknesses, often using stolen or fabricated identities to gain access to corporate networks. This issue highlights a critical gap in current security measures and underscores the need for enhanced identity proofing.
The problem lies in the fact that new employees typically don’t have established authentication methods set up yet, making it challenging for organizations to verify their identities with any degree of confidence. While existing users can rely on trusted factors like enrolled authenticators or registered devices, newcomers are left vulnerable to exploitation by attackers who only need to convince one person that they’re who they claim to be.
North Korean IT workers have been using stolen or fabricated identities to secure remote jobs and gain access to corporate networks. In some cases, these attackers use false identity documents, proxy infrastructure, and US-based facilitators to make themselves appear legitimate applicants. This approach turns the usual identity security model on its head, as attackers pass the hiring process and create credentials for themselves.
The FBI has repeatedly warned about this threat and now recommends identity verification during the hiring process and throughout the employment of remote workers. The broader lesson is that organizations must apply the same level of scrutiny to creating an identity as they do to authenticating one that already exists. This means implementing robust methods to verify identities, especially for new employees who lack established authentication factors.
The issue doesn’t end there; strong Multi-Factor Authentication (MFA) has a weak point: enrollment. Once a new employee passes onboarding, the service desk is often heavily involved in setting them up. Agents may help activate accounts, issue initial credentials, enroll MFA, and configure corporate devices. If an attacker reaches this stage, they can end up with an account secured by MFA linked to a trusted device, all issued through normal processes.
Attackers that compromise the credential bootstrapping stage can interfere with enrollment and establish persistent access before stronger controls are fully in place. This vulnerability highlights the need for secure onboarding processes that prioritize identity verification from day one.
To address this issue, organizations must implement an additional layer of identity verification specifically designed for Day One. Authentication asks whether someone can prove control of a credential linked to an account, whereas identity proofing verifies whether the person in front of you is the individual intended to receive that account. For new employees, a trusted factor like an enrolled authenticator or registered device may not be available, making it essential to establish confidence in their identity before issuing trust.
Strong forms of identity proofing, such as validating government-issued identity documents paired with biometric liveness checks, can provide assurance in the absence of established authentication factors. Solutions like Specops Secure Onboarding apply this principle by making identity verification a required step in the onboarding process, rather than something left to chance.
In conclusion, human error and identity verification gaps are significant vulnerabilities that even Zero Trust architectures cannot completely mitigate. To secure their networks, organizations must prioritize robust identity proofing from day one, especially for new employees. By doing so, they can reduce the risk of onboarding attacks and ensure a more secure environment for all users.
Source: Bleeping Computer — 2026-10-01