Kevin Surace
2 minute read
Device Based Biometrics Are the Only Way to Restore It.
Newsweek just published one of the clearest warnings yet about the identity crisis businesses are walking into. The article, “AI Deepfakes Are Forcing Companies to Rebuild Trust,” lays out the problem with uncomfortable precision.
According to Newsweek, AI generated deepfakes have increased by more than 3,000 percent in the last year alone. That number should terrify every company that still relies on voice verification, phone calls, or human judgment to approve identity. Even worse, the article notes that criminals are using AI to mimic voices, mannerisms, accents, and even emotional tone with near perfect accuracy. Fraudsters no longer need to know you. They just need 10 seconds of audio.
This line from the article says it all.
“Deepfake fraud losses are expected to exceed 25 billion dollars by 2026.”
There is no training that can keep up with that. No call center script. No help desk workflow. No security awareness module. When AI can clone a person instantly and convincingly, trust collapses. Newsweek puts it plainly.
“Companies can no longer assume the person on the other end of the line is who they claim to be.”
That is the problem behind every breach you read about today.
Attackers are not breaking in. They are impersonating real people.
They are taking advantage of systems that still ask human beings to determine whether someone is legitimate.
SMS codes.
Push approvals.
Authenticator apps.
Recovery emails.
Help desk resets.
All of these trust the human.
All of these can be manipulated by a fake voice or a deepfake video.
All of these fail under the exact conditions Newsweek is warning about.
So if a voice can no longer be trusted, and a video can no longer be trusted, and a phone call can no longer be trusted, what is left?
Only one thing.
A device bound biometric that cannot be faked, forwarded, cloned, or relayed.
Token Ring and Token BioStick do exactly that.
They authenticate the real person by requiring a live fingerprint match on a physical device.
They authenticate the real device by requiring proximity to the machine logging in.
They authenticate the real destination by cryptographically verifying the domain
A deepfake cannot produce a fingerprint.
A cloned voice cannot produce a hardware bound cryptographic key.
A spoofed site cannot receive a signature tied to the correct domain.
Only a device based biometric proves you are talking to the actual person.
Not a recording. Not a simulation. Not an AI copy.
Newsweek is right. Companies must rebuild trust. But you cannot rebuild trust with legacy MFA or human judgment. You can only rebuild it with technology that defines identity in a way AI cannot imitate.
The world is shifting to biometric, device bound, phishing proof identity.
That is the future.
And it is the only future that makes sense.
Token products are available online now at store.TokenRing.com
Cyber incidents and losses escalate every year and the impact on every organization can range from significant to crippling. With the average cost from a data breach in the U.S. now approaching $10 million and losses in market value for victim companies sometimes exceeding $100 million, it was time for the U.S. Securities and Exchange Commission (SEC) to introduce robust cybersecurity rules for public companies. This was an obvious necessity to protect investors and the integrity of U.S. securities markets. As a C-level executive or person with responsibility for cybersecurity, understanding these rules is crucial for remining in compliance with the new regulations, maintaining a strong security posture, and the financial health of your organization.
The most important lesson in Vercel’s April 2026 security bulletin is not simply that internal systems were accessed. It is the likely path the attacker took to get there. According to Vercel, the incident originated with a compromise of Context.ai, a third-party AI tool used by a Vercel employee. The attacker then used that access to take over the employee’s Vercel Google Workspace account, which in turn enabled access to some Vercel environments and non sensitive environment variables.
Grafana recently disclosed that an unauthorized party obtained a token granting access to the company’s GitHub environment and used it to download portions of its codebase. Grafana confirmed that no customer data or personal information was accessed, invalidated the compromised credentials, and applied additional controls. The response was fast, and the containment was effective.
Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.