Skip to main content
Infrastructure vs. identity

Another “Azure Breach”? Not Really. It Was Almost Certainly an Identity Breach.

Every few weeks another headline appears suggesting that a major cloud platform has been breached. This week, the alleged victims include household names such as McDonald’s, Vodafone, Kyndryl, Gap, Wyndham, and others, with millions of Azure and Entra directory records reportedly being offered for sale by a threat actor calling themselves “TheHatman.” But based on what has been reported so far, there is no indication that Microsoft Azure itself was compromised. The far more likely explanation is much simpler and much more important for enterprise security leaders to understand: someone obtained legitimate access and logged in.

Kevin Surace
4 minute read
The door that can't be opened from the outside

Apollo Wasn’t Hacked. They Were Authenticated.

Another major enterprise fell victim to identity-based social engineering. Here’s exactly how it happened, why legacy authentication failed, and why it’s time to rethink the front door. When Apollo Global Management recently disclosed a data breach, many headlines framed it as another sophisticated cyberattack. But if you look carefully at the publicly reported details, the story is actually much simpler. Attackers didn’t exploit an unknown software vulnerability. They didn’t bypass next generation firewalls. They didn’t crack encryption or deploy advanced malware. Instead, they convinced employees they were legitimate IT personnel, directed them to a convincing login page, and had those employees authenticate the attackers into Apollo’s own systems. The attackers didn’t break in. They logged in.

Kevin Surace
4 minute read
FIDO signature counters detect cloned credentials. Synced passkeys return zero. What enterprises should require for high-assurance access.

A Nonfunctioning FIDO Counter Is A Serious Enterprise Risk

FIDO authentication is widely described as resistant to phishing, credential theft, and replay. Those claims are broadly justified. But one important security mechanism remains inconsistently implemented across the ecosystem: the signature counter. For consumer accounts, that inconsistency may be an acceptable tradeoff for convenience. For administrators, infrastructure operators, financial systems, identity recovery, and other high assurance applications, it is a risk that should no longer be ignored.

Kevin Surace
4 minute read

The Code Was Real. The Approval Was Real. The Request Came From Ten Thousand Miles Away.

An employee received an authentication prompt. It came from the real application. It arrived exactly when expected. They approved it. Every system behaved correctly. The credential was valid. The prompt was authentic. The approval was logged. The only thing absent from the transaction was the person the account belonged to. They were ten thousand miles from the attacker holding their session. Kevin Surace puts identity attacks at roughly 90 percent of hacks. His more useful point is what those attacks are not: clever. They are cheap, repeatable, and rented as kits for around $200 a month.

Kevin Surace
2 minute read
Can MFA be Bypassed?

Can MFA be Bypassed?

Multi-factor authentication (MFA) was designed to protect organizations when passwords were stolen. Unfortunately, attackers have adapted to the methods most enterprises now use. They intercept codes, overwhelm employees with approval requests, relay authentication through convincing phishing sites, steal active sessions, manipulate help desks, and exploit account recovery processes. The problem is not the concept of using multiple factors. The problem is that most MFA systems still depend on information or actions that can be shared, intercepted, relayed, reset, or approved by the wrong person.

Kevin Surace
5 minute read
The Better Architecture Is Biometric Assured Identity

Do Not Migrate Twice. Vishing Is Coming for Your Passkeys.

The next great cyberattack may not start with malware, a zero day, or someone furiously typing commands into a terminal. It may start with your phone ringing. “Hi, this is IT. We are completing the company’s mandatory passkey migration. Microsoft is changing its authentication requirements and your account still needs to be updated. I can walk you through it. It will only take two minutes.” That call is no longer hypothetical. Attackers are already using almost exactly this script. And they are not trying to steal your old MFA code anymore. They are after something much more valuable. They want to become your new passkey.

Kevin Surace
10 minute read
Hackers Do Not Break Passkeys. They Just Trick the User.

Hackers Do Not Break Passkeys. They Just Trick the User.

Hackers are already adapting the same social engineering playbook that defeats MFA and authenticator apps. Soon, Phishing as a Service kits will handle the technical details for them. Token removes the manipulation paths that phone based passkeys leave open.

Kevin Surace
15 minute read
Passkeys Are Not Completely Secure Without Dedicated Biometric Hardware

Passkeys Are Not Completely Secure (After All) Without Dedicated Biometric Hardware

Passkeys have been promoted as the future of authentication because they replace passwords with cryptographic credentials that are resistant to traditional phishing. That is a significant improvement. A properly implemented passkey cannot simply be copied from a fake login page and replayed against the legitimate service. But a new campaign targeting Microsoft Entra users exposes an important limitation. Passkey cryptography may be strong, while the process used to enroll a new passkey can still be manipulated.

Kevin Surace
6 minute read
CISA’s New Zero Trust Guidance Makes One Thing Clear: Identity Must Be Certain

CISA’s New Zero Trust Guidance Makes One Thing Clear: Identity Must Be Certain

CISA’s new report, The Journey to Zero Trust Using Secure Access Service Edge in a Modern TIC 3.0 Solution, is an important signal for every enterprise security leader. The federal government is moving away from the old perimeter security model. The model where you route every user through a VPN, inspect traffic at a central choke point, and assume that once someone successfully logs in, they can be trusted. That model no longer matches reality.

Kevin Surace
4 minute read
iRhythm’s Breach Was Not a Device Hack. It Was an Identity Failure.

iRhythm’s Breach Was Not a Device Hack. It Was an Identity Failure.

iRhythm Technologies has disclosed a material cybersecurity incident involving patient protected health information, proprietary information, and other personal data held in certain third party hosted business applications. The company says the data was obtained through social engineering. It identified suspicious activity on June 8, received an extortion demand on June 9, and confirmed that data had been exfiltrated. iRhythm has said its clinical systems, medical devices, patient safety operations, manufacturing, and customer connections were not affected. That distinction matters.

Kevin Surace
3 minute read
A password can be reset. A fingerprint can't.

The MGM Hack Happened Three Years Ago. Why Are Companies Still Letting Phone Calls Reset Their Security?

In September 2023, MGM Resorts suffered one of the most visible cyberattacks in recent memory. Hotel guests could not use digital room keys. Slot machines and ATMs were disrupted. Websites went offline. Operations across major properties were thrown into chaos. MGM later estimated the incident cost roughly $100 million in lost revenue. According to widely reported accounts, the front door was not kicked in by a zero day exploit, nation state malware, or some impossible technical breakthrough. It was opened with a phone call.

Kevin Surace
3 minute read
Aflac was breached again

Aflac Was Breached Again. This Is What Happens When Legacy MFA Turns You Into a Honeypot.

Last year, Aflac was swept into a wave of attacks that put the insurance industry on notice. Last week, Aflac disclosed another breach, this time involving its Japan subsidiary. The reported exposure includes policy information, personal data, and bank account information affecting millions of customers. We do not yet know the precise entry point in this new incident. It would be irresponsible to claim otherwise. But we do know the larger lesson.

Kevin Surace
3 minute read
1 2 3 4 5 ... 7

Stay Identity Assured

Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.