Many organizations have been actively strengthening their identity security efforts this year, but attackers are keeping up. They’re growing savvier and more advanced, often diverting new safeguards with ease. A multi-factor authentication (MFA) prompt, conditional access policy or device compliance check may all be working exactly as configured. Yet an attacker can still bypass these measures by targeting the processes behind account resets and recovery, using tactics that often go unnoticed to the naked eye.
The most common is deepfakes. Gartner reports that over a 12-month period, 62% of organizations experienced a deepfake attack, and financial losses from deepfake fraud are estimated at roughly $1.1 billion annually.
Unfortunately, these attacks aren’t a future worry; they are here, and they can have significant business consequences. Security leaders must reevaluate their current authentication tech stack and determine if they can truly verify their employees and customers in ways that can’t be easily imitated or faked by cybercriminals.
The overlooked layer of identity security
Most identity security programs focus on the primary login path, and that path has improved a lot. What doesn’t get the same scrutiny are account backup and recovery systems that can step in when primary access methods fail – whether that be a lost phone, new laptop, locked account, or customer who can’t receive a one-time code.
These fallback routes are usually owned by different internal teams, designed around availability rather than assurance, and measured by user satisfaction and time-to-recovery. They are the operational pressure valve for an identity security system, making them a prime target for attackers.
An organization may require thorough authentication for primary login access, only to rely on insecure processes like a one-time password (OTP) via SMS or a phone call for account recovery. These methods are now easily exploitable and don’t provide sufficient evidence that someone is who they claim to be.
Traditional verification methods don’t hold up to advanced threats
Traditional verification methods like SMS and OTP often rely on two things. The first is knowledge: a date of birth, the last four digits of an identifier, a recent transaction, an employee number or other personal information. Years of breaches, data brokerage, and public social media accounts have made that information increasingly unreliable. An attacker who has spent time researching a target may know those details even better than the actual user.
The second is human judgment. An agent may listen to a caller, consider the context, and determine whether the person sounds like who they claim to be. Until recently, that was an imperfect but semi-reliable safeguard. Deepfakes have changed this whole system. A few minutes of audio from a conference talk, podcast or recorded webinar can provide enough material to create a convincing synthetic voice. Video and images can be manipulated in similar ways. As these tools become easier to access, organizations cannot assume that audio and video recordings provide sufficient identity verification.
Rebuilding the authentication path around stronger evidence
A recovery path should not accept weaker evidence than the path it is recovering. Organizations need to level up their log in methods with more reliable authenticators to ensure that only verified users are granted access.
The only way for organizations to mitigate their risk of deepfake fraud is by transitioning to hardware-based authentication that ties a user’s identity to a cryptographic element in physical hardware, like a SIM card that is verified via the device’s mobile carrier to confirm that a login request was made honestly, by the legitimate user. This approach is nearly impossible for fraudsters to compromise, eliminating the need for organizations to gamble on verification by voice, personal information, or login methods like SMS-OTP or MFA.
Cyberattacks and deepfakes will continue to evolve, and security teams cannot rely on their ability to spot a fake every time. Instead, the stronger approach is to build an authentication strategy on hardware, that can establish trust without having to determine whether someone is legitimate.
Join our LinkedIn group Information Security Community!
