Threats

Identity Verification Risk Grows

August 26, 2026 04:06 · 12 min read
Identity Verification Risk Grows

Introduction to Identity Verification Risks

Security teams have spent years hardening authentication, with controls like multi-factor authentication (MFA) and conditional access now commonplace. However, stronger authentication does not solve every identity problem, as there are several points in the identity lifecycle where trust is established or re-established.

These points include when a new employee joins, when someone loses access to their account, when a password or MFA factor needs to be reset, and when the service desk is asked to make a sensitive change to an account. Rather than stealing credentials or bypassing MFA, an attacker can try to convince the service desk that they are the account holder, using social engineering to exploit legitimate processes.

Exploiting Identity at Onboarding and Recovery

In late July 2026, the US Department of State and allies, including Japan, Canada, and the UK, issued a joint alert warning that North Korean IT workers were impersonating foreign nationals to secure employment. Their tactics focus on falsifying identity documents, such as using images supplied by a third party based in another country to register accounts.

The North Korean workers typically target technology companies, highlighting that onboarding creates a moment when trust is established for the first time. If identity checks fail at that stage, the attacker can enter the environment with access that appears legitimate. The same issue can occur during the recovery process, with threat actor groups like Scattered Spider proficient at social engineering and impersonating employees to reset passwords.

Strong Authentication Still Depends on Strong Identity Checks

When someone calls the service desk claiming that they’ve forgotten their password or lost access to their authenticator, the agent needs to be able to confidently verify the person calling is the real account owner. However, in many organizations, identity checks can still rely on relatively weak signals, such as employee IDs or phone numbers, which can be researched, stolen, or manipulated.

Attackers can find personal information through data breaches or social media, and even in instances where stronger checks are in place, documents and other identity evidence can be altered or fabricated. AI is making impersonation more convincing, with synthetic profiles, manipulated images, cloned voices, and deepfake video supporting false identities.

Solutions for Strengthening Verification

Solutions like Specops Verified ID add another layer of assurance, helping service desk agents confidently confirm identity before sensitive actions take place. This is achieved by combining government document scanning and validation with biometric liveness detection, confirming that the ID being presented is legitimate and that a real, present person is completing the process.

During onboarding, this gives organizations a stronger way to verify new employees before granting access to corporate systems, reducing the risk posed by fraudulent applicants and impersonation attempts. The same approach can be applied when high-assurance verification is needed, such as password resets for privileged accounts.

Specops Verified ID applies stronger verification where the consequences of getting it wrong are highest, rather than adding complexity to every identity event. This helps organizations make decisions with greater confidence, whether they are onboarding a new employee or helping an existing one recover their account.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free