Passwords Are the Problem. The Fix Is Passwordless.

Attackers Are Not Hacking In. They Are Logging In. Ransomware, phishing, and credential-based attacks are hitting small and midsize businesses every day because attackers have learned the easiest trick in the book. They do not need to hack in. They simply log in with stolen credentials. The moment an employee enters a password or approves a code, the attacker has everything.

Kevin Surace
2 minute read

Your MFA Is Costing You Millions. It Doesn't Have To.

Most organizations still think of authentication as a cost of doing business.

Kevin Surace
1 minute read

AI Deepfakes Are Fueling Identity Fraud

Device-based biometrics are the Only Way to Restore It.

Kevin Surace
2 minute read

How Phishing Relay Attacks Bypass MFA

How a Phishing Relay Attack Works Phishing relay attacks do not break authentication. They sit in the middle of it. A phishing relay attack inserts an attacker-controlled proxy between the victim and the legitimate login portal. The victim believes they are on the real site. Every credential they enter goes to the attacker first. The sequence is predictable. The victim receives a phishing email linking to a page that looks identical to the real login portal. They enter their username and password. The attacker’s proxy forwards these to the real site immediately. The real site triggers an MFA challenge. The proxy mirrors that challenge back to the victim. The victim enters their six-digit code or approves a push notification. The attacker forwards the response. The real site authenticates the session. The exchange takes seconds. The victim has logged in. The attacker has the session.

Kevin Surace
2 minute read

The DoorDash Data Breach and the Legacy MFA Failure

Another Preventable Breach Another week. Another preventable breach. This time it is DoorDash, confirming that a social engineering scam gave attackers access to sensitive customer and driver information. But the real story is not the scam. The real story is the failure behind it.

Kevin Surace
2 minute read

What CISA, NSA, and NIST Say About Phishing-Resistant MFA

What do CISA, NSA, NIST, OMB, DHS, the Department of Defense, Gartner, Microsoft, Google, the FIDO Alliance, and the entire cyber insurance industry know that so many organizations are still ignoring?

Kevin Surace
2 minute read

The Tycoon 2FA Phishing Kit and the Failure of Legacy MFA

As seen in Bleeping Computer The Tycoon 2FA phishing kit signals a turning point in the battle against account takeover. This is not a tool built for elite attackers. It is a plug-and-play phishing kit that anyone can deploy, with zero coding skills required. Tycoon automates everything: setup, fake login pages, reverse proxy servers, real-time credential capture, and full MFA relay.

Kevin Surace
1 minute read

Breaking the Ransomware Kill Chain

Ransomware attacks are rising faster than ever, and most share a common weakness — authentication that trusts too much. In his session from the recent Security Buzz webinar, Kevin Surace, Chairman of Token, explains why MFA apps and codes have become attackers’ favorite weapon instead of a defense.

Kevin Surace
1 minute read
PixSnapping - steals screen pixels from Android devices

PixSnapping: The Android Exploit That Breaks 2FA

A newly published academic paper introduces a new hacker tool called PixSnapping (download PDF), an advanced attack that can steal screen pixels from Android devices and reconstruct sensitive data like 2FA codes in real time. The research demonstrates that an attacker-controlled app can capture or infer the digits displayed by authenticator apps such as Google Authenticator in under thirty seconds.

Kevin Surace
2 minute read
Cybersecurity training fails

Why Phishing Training Fails to Stop Modern Attacks

A new study from UC San Diego Health should make every security leader stop and think. Researchers ran nearly 20,000 employees through ten simulated phishing campaigns over eight months. The result? Training made almost no difference. Employees who had recently completed mandatory cyber awareness courses failed phishing tests at virtually the same rate as those who hadn’t. The average gap was a sickly 1.7% improvement — effectively zero.

Kevin Surace
3 minute read

Microsoft ADFS Redirect Exploit Proves Legacy MFA Is Broken

Last week, BleepingComputer reported on a clever new phishing campaign targeting Microsoft users. Instead of pixel-perfect fake sites or smishing lures, attackers are now abusing legitimate Microsoft ADFS redirect endpoints to steal logins.

Kevin Surace
3 minute read
Pixel-Perfect Phishing

Pixel-Perfect Phishing Attacks and How They Bypass Legacy MFA

Phishing attacks no longer rely on obvious tells. Misspelled words, generic greetings, and suspicious domains are yesterday’s problem. Today, the most effective phishing campaigns use Unicode characters that look identical to the characters they replace. The fake URL looks real. The fake site looks real. There is nothing for the human eye or most security tools to catch. The deception happens at a level most people never inspect.

Kevin Surace
3 minute read

Stay Identity Assured

Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.