Breaking
SecurityDeveloping Story

Identity Checks Become the Weak Link

Attackers shift focus from login to onboarding and account recovery, exploiting weak identity verification.

··2 hours ago·4 min read
Man in glasses talking on phone at desk
Photo by Vitaly Gariev on Unsplash

The hardest security controls to break are often the most expensive to attack. That's why attackers are turning to the human processes around them — specifically the moments when trust is granted, not verified.

Security teams have spent years hardening authentication, with controls like multi-factor authentication (MFA) and conditional access now commonplace. While stronger authentication can make traditional credential theft less effective, it doesn’t solve every identity problem.

The weak point, increasingly, is identity verification at critical junctures: when a new employee joins, when someone loses access to their account, when a password or MFA factor needs to be reset, or when the service desk is asked to make a sensitive change to an account.

The Onboarding Vulnerability

In late July 2026, the US Department of State and allies including Japan, Canada and the UK issued a joint alert warning that North Korean IT workers were impersonating foreign nationals to secure employment.

Their tactics focus on falsifying identity documents, such as using images supplied by a third party based in another country to register accounts. The North Korean then carries out the actual work.

These workers typically target technology companies, so the important point is not that every organization should expect the same type of campaign. It is that onboarding creates a moment when trust is established for the first time.

If identity checks fail at that stage, the attacker can enter the environment with access that appears legitimate.

Recovery Offers Another In

The same issue can occur during the recovery process. Threat actor groups like Scattered Spider are proficient at social engineering, impersonating employees and calling the service desk to reset passwords that gift access to an account.

This tactic was linked to the 2025 M&S ransomware breach, which contributed to an estimated $400 million hit to the retailer’s operating profit through lost sales.

Rather than stealing credentials or bypassing MFA, an attacker can instead try to convince the service desk that they are the account holder, using social engineering to exploit legitimate processes.

Weak Checks Still Common

When someone calls the service desk claiming that they’ve forgotten their password or lost access to their authenticator, the agent needs to be able to confidently verify the person calling is the real account owner.

However, in many organizations identity checks can still rely on relatively weak signals. A service desk might ask for an employee ID or phone number. Security questions are still common, asking the caller the name of their first pet or where they went to school.

The problem is that many of these checks can be researched, stolen or manipulated. Attackers can find personal information through data breaches or social media.

Documents Can Be Faked

Even in instances where stronger checks are in place, the North Korean remote worker campaigns demonstrate how documents and other identity evidence can be altered or fabricated.

AI is making impersonation more convincing, too. Attackers can use synthetic profiles, manipulated images, cloned voices and deepfake video to support a false identity or make a social engineering attempt more believable.

A Staggering Stat

Verizon’s Data Breach Investigation Report found stolen credentials are involved in 44.7% of breaches.

That statistic underscores why attackers are shifting focus: if they can't steal credentials, they'll try to bypass the verification that protects recovery.

  • 44.7% — share of breaches involving stolen credentials (Verizon's Data Breach Investigation Report)
  • $400 million — estimated operating profit loss at M&S from the 2025 ransomware breach
  • 6+ billion — compromised passwords blocked by Specops Password Policy

Verification Tools Evolve

Solutions like Specops Verified ID add another layer of assurance and helps service desk agents confidently confirm identity before sensitive actions take place.

It does this by combining government document scanning and validation with biometric liveness detection.

Document checks help confirm that the ID being presented is legitimate, while liveness detection helps verify that a real, present person is completing the process rather than relying on a static image or other replayed evidence.

During onboarding, this gives organizations a stronger way to verify new employees before granting access to corporate systems. That can reduce the risk posed by fraudulent applicants and impersonation attempts, including tactics seen in North Korean remote worker campaigns.

The same approach can be applied when high-assurance verification is needed, such as password resets for privileged accounts.

Rather than adding complexity to every identity event, Specops Verified ID applies stronger verification where the consequences of getting it wrong are highest.

Protect Your Service Desk

Strong authentication remains essential, but attackers will continue looking for ways around the controls that are hardest to break. Increasingly, that means targeting the processes used to establish or recover identity rather than attacking the login itself.

Whether an organization is onboarding a new employee or helping an existing one recover their account, the challenge is ensuring the right person is granted access.

Specops Verified ID adds government ID validation and biometric liveness detection to these high-risk identity events, helping organizations make that decision with greater confidence.

If you’re interested in learning more about how Specops can strengthen identity verification at the service desk, contact us today to speak to an expert.

Why This Matters

As authentication hardens, the path of least resistance for attackers will be the identity verification steps that precede access. That's not a prediction — the North Korean worker scheme and Scattered Spider's service desk attacks are already happening, and the costs can be enormous, as M&S found out.

Organizations that only focus on authentication are leaving the back door open. The next breach could start with a simple phone call, not a sophisticated exploit.

#identity verification#service desk#social engineering

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories