Kevin Surace
2 minute read
Another week. Another preventable breach. This time it is DoorDash, confirming that a social engineering scam gave attackers access to sensitive customer and driver information. But the real story is not the scam. The real story is the failure behind it.
The weak link was legacy MFA. Again.
DoorDash’s statement reads like every breach disclosure of the past two years. Attackers tricked an employee. Credentials were obtained. A login was approved. And suddenly, the attacker had access to internal tools. The company emphasizes that no passwords were exposed. But that misses the point. The problem is that passwords no longer matter. Phishers do not need them. They only need a moment of human error and an MFA method that trusts the user too much.
This is why attackers keep winning. Legacy MFA still allows them to.
SMS codes. Authenticator apps. Push notifications. Time-based OTP. These methods were not built for a world where AI can generate perfect phishing sites in 30 seconds and spoofed help desk calls are indistinguishable from the real thing. They cannot validate who is authenticating. They cannot validate where the request is coming from. And they cannot prevent a real-time relay attack when the victim truly believes they are logging into the legitimate site.
This is exactly how attackers keep getting in at DoorDash, MGM, Caesars, Aflac, Qantas, Hawaiian Airlines, UnitedHealth, and hundreds more. They are not breaking in. They are logging in. With your unsuspecting employee’s MFA or authorization.
The solution is not more training. The solution is not more warnings. The solution is not asking employees to stare longer at URLs. The solution is replacing the authentication system that keeps failing.
This is where Token changes everything.
TokenCore™ Wearable and TokenCore™ Portable eliminate the entire attack path that brought down DoorDash. They work differently than every legacy MFA method that attackers love.
They require a live biometric fingerprint match. No fingerprint means no login.
They require the device to be physically near the machine logging in. Remote attackers cannot authenticate from anywhere.
They cryptographically bind every credential to the real domain. A fake site cannot obtain a signature. The Token device simply refuses to respond.
They never send a push. They never generate a code. They never ask the user to approve anything. There is nothing to phish, nothing to relay, nothing to intercept.
If DoorDash had deployed Token, the attacker’s entire playbook would have collapsed instantly. The phishing email would have been irrelevant. The spoofed request would have failed. No fingerprint means no signature. No proximity means no authentication. No domain match means no access.
This is the difference between legacy MFA and phishing-resistant biometric FIDO2 authentication. One trusts the user and gets breached. The other trusts cryptography and stops the breach cold.
DoorDash is not alone. Every enterprise still running legacy MFA is heading toward the same headline.
It does not matter how large the company is. It does not matter how trained the users are. Modern attackers only need a moment. Legacy MFA gives them everything else.
If you want to shut down real-time phishing, relay attacks, help desk exploitation, and social engineering completely, there is only one answer.
Use Token. Or wait for your version of the DoorDash breach.
Get Token products online now at store.tokecore.com
From the perspective of someone responsible for securing an enterprise organization, the inclusion of biometric recognition capabilities in PCs and phones has been a positive development. The draw of using biometrics for recognition is that most are suitably unique and entropic, such that the biometric will more secure than a short passcode or easily-remembered password. Furthermore, biometric verification systems are viewed by most as being intuitive and convenient to use. In this way, biometric verification as the way users authenticate themselves to their devices has reduced a large attack surface for organizations whose employees work remotely or in hybrid environments. At first glance, one biometric authenticator may seem as secure as another. Users might feel secure using the fingerprint scanner on their Windows laptop, and the experience may be similar across different devices. However, the security and effectiveness of biometric systems vary significantly. This blog will explore the differences between fingerprint authentication built into popular PCs and next-generation biometric multifactor authenticators, highlighting vulnerabilities and how advanced solutions, such as these, provide the expected security and convenience.
In September 2023, MGM Resorts suffered one of the most visible cyberattacks in recent memory. Hotel guests could not use digital room keys. Slot machines and ATMs were disrupted. Websites went offline. Operations across major properties were thrown into chaos. MGM later estimated the incident cost roughly $100 million in lost revenue. According to widely reported accounts, the front door was not kicked in by a zero day exploit, nation state malware, or some impossible technical breakthrough. It was opened with a phone call.
Enterprise cybersecurity is a war zone. Today, organizations face an ever-increasing number of cyber threats, from system intrusions and phishing scams, to ransomware attacks, web application attacks, and more – any of which can result in serious damage to enterprise assets and irreversible loss of data and intellectual property.
Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.