Identity verification gaps exploited in onboarding and recovery processes
Security teams have focused on hardening authentication, but attackers are now exploiting the processes for account creation and recovery. Recent incidents include North Korean IT workers using falsified documents and groups like Scattered Spider impersonating employees to reset passwords. Organizations must strengthen identity verification at these trust-establishment points.
The July 2026 joint alert from the US State Department, Japan, Canada, and the UK detailed North Korean operatives using third-party-supplied images to register accounts while performing remote work. Verizon's breach report attributes 44.7% of incidents to stolen credentials, explaining why attackers increasingly pivot to trust-establishment moments rather than direct authentication bypass.
Scattered Spider's service desk impersonation contributed to the 2025 M&S ransomware incident, which cost the retailer an estimated $400 million in operating profit. Common verification methods—employee IDs, phone numbers, and security questions—remain vulnerable to research or fabrication, while AI-generated deepfakes and cloned voices further undermine agent confidence during identity checks.
This story could affect anyone whose personal data appears in breach