Why passwordless authentication won't eliminate account takeovers
At a time when reaching consensus on any topic is challenging, here’s something we can all agree on: Everybody hates passwords.
Users hate passwords because they’re too hard to remember, so they default to choosing and reusing obvious ones. Cybersecurity professionals hate passwords because when they are inevitably stolen, security breaches often follow. According to Verizon’s 2026 Data Breach Investigations Report, credential abuse appeared at some point in the breach progression in 39% of cases analyzed.
Adopting passwordless authentication helps avoid many of the headaches caused by legacy access-control systems. For example, using FIDO-compliant passkeys can thwart phishing attacks and prevent credential stuffing, while implementing push notifications or time-based authenticator codes can reduce the risks from password theft or reuse.
But passwordless authentication methods won’t verify that the remote employee you just onboarded is the same person your company thinks it hired, or stop your help desk from issuing credentials to attackers impersonating employees who lost their laptops. They won’t prevent Scattered Spider and associated hacking groups from launching account takeover attacks, like the ones that targeted Caesars Entertainment, MGM Resorts, and other large enterprises.
Eliminating passwords is an important step toward shrinking your network’s attack surface, but you can’t simply issue everyone a hardware authenticator and call it a day. A Zero Trust security posture needs to also incorporate live identity verification (IDV) in key moments of enrollment and re-authentication.
What problems does passwordless authentication solve?
Every enterprise needs to ensure that its people are who they claim to be, both during onboarding and when accessing sensitive systems or data. Passwordless authentication helps prevent unauthorized access to key systems by reducing reliance on stealable credentials. But it doesn’t verify the real-world identity of the person receiving credentials or recovering access, leaving organizations vulnerable when enrolling new employees, replacing lost devices, and resetting authentication factors.
NIST’s digital identity guidelines separate the process of establishing someone’s identity from the process of authenticating them when they request access. Its Identity Assurance Levels (IAL) describe the level of confidence in someone’s claimed identity, typically established by checking identity information against authoritative sources, such as government-issued IDs. Authenticator Assurance Levels (AALs), meanwhile, describe the level of confidence that someone controls an authenticator bound to that identity.
Passwordless authentication primarily addresses authenticator assurance. It doesn’t establish who originally received the authenticator, and passwordless methods vary in security. Organizations may also fall back to less secure methods during account recovery.
What are the risks with passwordless deployment?
There are three key moments when attackers can circumvent the protections offered by passwordless authentication:
Day Zero enrollment
Even strong authentication can grant an impostor legitimate access if an organization issues credentials without first establishing their identity. If a bad actor manages to impersonate a new employee at the enrollment stage, they can use legitimate credentials to access your network — no compromise or malware required.
One emerging Day Zero compromise comes in the form of fake job candidates, often from hostile nation states, posing as US citizens. North Korean IT workers pretending to be Americans have infiltrated hundreds of US companies, using bogus work histories and AI deepfakes to fool organizations into hiring them. This puts enterprises in danger of violating US and international sanctions, as well as exposing sensitive data and systems to insider threats.
Lost or stolen device recovery
Cybercrime groups often use social engineering techniques to dupe help desk employees into issuing them legitimate credentials or temporary access keys, like temporary passwords. In this scenario, attackers gather enough information about an organization’s employees to successfully impersonate them, then contact the company’s help desk claiming to have lost their laptop or other enrolled device. At this point, many organizations fall back to less secure methods, such as email or SMS, or ask the employee’s manager to confirm their identity over a video call. These methods rely on access to a communication channel or visual recognition rather than independent identity verification.
Multifactor authentication resets
A similar form of social engineering attack convinces help desks to skip passwordless authentication entirely and issue temporary access through a less secure method, such as an SMS code or one-time email link.
This is likely the method Scattered Spider used to compromise Caesars and MGM in September 2023. Attackers impersonated a highly privileged employee, convinced IT support to issue an MFA reset to a phone number they controlled, then used those credentials to move laterally across each network. Eventually, they gained control of each company’s systems and exfiltrated multiple terabytes of data. The attack cost the company more than $100 million in lost revenue and legal costs, while Caesars reportedly paid the attackers $15 million to stop them from releasing customer data.
What are the best practices for securing employee enrollment and account recovery?
Conducting identity verification at enrollment and credential re-issuance can help stop many social engineering attacks before they start. Key best practices include:
Verifying new hires against authoritative sources. Use government-issued IDs and authoritative databases to confirm identity, and work with a background check provider to verify an applicant’s employment and education history directly with institutions.
Using selfie matching with liveness detection. Compare ID photos with live selfies. Use unscripted real-time video interactions when interviewing remote hires. To minimize the risk of being fooled by AI deepfakes, ask candidates to interact with their physical environment.
Treating credential re-issuance as a high-risk event. Implement special help desk procedures to verify user identities, and require live, visual verification for highly privileged accounts. Don’t rely on knowledge-based authentication, and use only established channels for sending authentication confirmations. Route suspicious or sensitive re-issuance requests to dedicated security staff.
Reviewing all enrollments periodically. Audit enrolled devices regularly and revoke those that are unused or show atypical usage patterns.
How identity verification reduces social engineering risk at high-risk moments
Requiring employees to submit verifiable proof of identity at key moments of enrollment and account recovery can frustrate the social engineering attacks commonly employed by organized hacking collectives.
| Moment | Without IDV | With identity-proofed enrollment |
|---|---|---|
| Day Zero device setup | Credential issued to whoever holds the laptop | Government ID + selfie verifies the new hire’s identity before any credential is issued |
| Lost/stolen device recovery | Help desk resets based on KBA or manager vouching | Self-service re-enrollment gated by reverification; can be automated or triggered by the help desk |
| MFA/authenticator reset | SMS or knowledge questions | Identity-verified reset; same assurance as initial enrollment |
What should organizations consider when implementing identity verification?
Implementing identity proofing deliberately adds friction to enrollment and account recovery. Organizations will need to introduce sufficient challenges to mitigate risk without frustrating employees who are just trying to get their work done. They’ll need procedures in place to handle adverse scenarios, such as poor lighting during selfie checks, and for responding if the IDV platform incorrectly verifies bad actors or rejects legitimate users.
IDV also adds technological complexity; any solution will need to integrate seamlessly with the organization’s existing identity and access management (IAM) systems. Global enterprises will need a platform that can handle different types of verification documents in multiple languages. Collecting data such as face scans will subject organizations to additional levels of regulatory scrutiny.
Enterprises should choose a trusted partner that can help them navigate the risk/security tradeoffs in deploying identity-proofed enrollment, as well as managing the complexity of integrating IDV into their current identity infrastructure. Close adherence to privacy best practices will be crucial.
How Persona secures critical device enrollment moments
Persona helps organizations identify fake job applicants and reduce account takeover risk by verifying identities during hiring, device enrollment, and account recovery. Using sophisticated liveness-detection techniques combined with passive signal analysis, Persona helps verify that the person on camera is the same one shown in government-issued IDs. The platform works alongside passwordless authentication systems so that employees not only have the right credentials, but are who your organization expects.
Persona is Kantara-certified as a NIST SP 800-63-3 Component Service at Identity Assurance Level 2 (IAL2) and integrates directly into the most widely used IAM platforms, including Okta, Microsoft Entra, and Cisco Duo.
Trust no one. Verify everyone.
Each day, attackers grow bolder, their techniques more sophisticated. For large enterprises, the damage inflicted by a successful account takeover attack can be catastrophic. That’s why continually verifying who’s accessing your systems has become a core component of Zero Trust frameworks.
Got questions about identity proofing or want to learn more about how Persona can strengthen your organization’s security posture? Contact our team or check out Persona’s workforce IDV solution.
The information provided is not intended to constitute legal advice; all information provided is for general informational purposes only and may not constitute the most up-to-date information. Any links to other third-party websites are only for the convenience of the reader.
