Skip to main content

Scattered Spider Exploits the Weakest Passkey Door: Account Recovery

The Scattered Spider playbook starts with a phone call. As a recent Infosecurity Magazine article explains, attackers research an employee, call the help desk, and persuade someone to reset a password or replace an authentication factor by authorizing a new passkey on any device including a bad actors own phone. The business may have strong security at login, but the attacker never needs to defeat it. The attacker convinces the business to enroll their device instead. The FBI and its international partners have documented that pattern. Scattered Spider actors have persuaded support staff to transfer multifactor authentication to devices they control, then used those devices to enter single sign on environments. If an attacker can replace your authenticator through a convincing conversation, your strongest login method becomes optional.

Kevin Surace
3 minute read
Scattered Spider Is Not Beating MFA

Scattered Spider Is Not Beating MFA. It Is Beating the Reset Button.

For years, cybersecurity leaders have been told that multifactor authentication is the answer to stolen passwords. Deploy a second factor, train employees to recognize suspicious requests, monitor the network, and the organization will be safer. That advice was reasonable when attackers were primarily trying to guess passwords or deliver malware. It is far less effective against an adversary that understands a more uncomfortable truth: the easiest way around authentication is often to persuade an authorized person to replace it. That is the central lesson of Scattered Spider. The group is known for voice phishing, impersonation, and carefully researched calls to employees and help desk personnel. Its operators do not always need to discover a software vulnerability. They can call support, claim to be a stranded employee, and ask for a password reset or a new authentication factor. If the story is convincing and the recovery process is weak, the attacker receives legitimate access without ever defeating the technology protecting the original account.

Kevin Surace
4 minute read

Cyber Belongs in the Boardroom. So Does Identity.

Boards have accepted responsibility for cyber risk. Now they must focus on the place where so many breaches actually begin: identity. Kim Stewart Smith’s recent article makes an important argument. Cybersecurity and artificial intelligence are no longer operational IT concerns. They are governance issues. Boards are accountable for enterprise risk, and cyber now sits alongside financial, legal, regulatory, and operational risk as one of the most significant threats facing an organization. That is an important and overdue shift. But there is another question boards should now be asking. It is not simply whether cyber belongs in the boardroom. It is whether the board is spending enough time on the part of cyber that determines whether an attacker gets into the organization in the first place.

Kevin Surace
5 minute read
The Relay That Goes Nowhere

Adversary in the Middle Is Winning. Here’s How to Finally Shut the Door.

The team at Stingrai recently published one of the better explanations I’ve seen of Adversary in the Middle (AiTM) phishing attacks and why they’ve become one of the fastest-growing threats facing enterprises today. Their article explains not only how these attacks work, but why organizations that have already deployed multi factor authentication are still finding themselves compromised. It’s well worth reading because it highlights a difficult truth many security teams are just beginning to accept: successful authentication no longer means the right person logged in.

Kevin Surace
2 minute read
Indistinguishable pair

Phishing Doesn’t Look Fake Anymore. That’s Why Legacy MFA Is Finished.

For years, cybersecurity awareness training taught employees to recognize phishing by looking for obvious warning signs. Poor grammar, strange formatting, suspicious links, awkward branding and clumsy language were all supposed to help users separate legitimate communications from fraudulent ones. That model is rapidly becoming obsolete. As PCWorld recently pointed out, generative AI has fundamentally changed the quality of phishing. Attackers can now create emails that are polished, grammatically correct and extremely convincing. They can closely mimic the language, tone and structure of communications from Microsoft, banks, delivery companies and other trusted brands. The visual presentation has improved as well. In many cases, there is simply nothing obviously “fake” about the message anymore.

Kevin Surace
4 minute read
Infrastructure vs. identity

Another “Azure Breach”? Not Really. It Was Almost Certainly an Identity Breach.

Every few weeks another headline appears suggesting that a major cloud platform has been breached. This week, the alleged victims include household names such as McDonald’s, Vodafone, Kyndryl, Gap, Wyndham, and others, with millions of Azure and Entra directory records reportedly being offered for sale by a threat actor calling themselves “TheHatman.” But based on what has been reported so far, there is no indication that Microsoft Azure itself was compromised. The far more likely explanation is much simpler and much more important for enterprise security leaders to understand: someone obtained legitimate access and logged in.

Kevin Surace
4 minute read
The door that can't be opened from the outside

Apollo Wasn’t Hacked. They Were Authenticated.

Another major enterprise fell victim to identity-based social engineering. Here’s exactly how it happened, why legacy authentication failed, and why it’s time to rethink the front door. When Apollo Global Management recently disclosed a data breach, many headlines framed it as another sophisticated cyberattack. But if you look carefully at the publicly reported details, the story is actually much simpler. Attackers didn’t exploit an unknown software vulnerability. They didn’t bypass next generation firewalls. They didn’t crack encryption or deploy advanced malware. Instead, they convinced employees they were legitimate IT personnel, directed them to a convincing login page, and had those employees authenticate the attackers into Apollo’s own systems. The attackers didn’t break in. They logged in.

Kevin Surace
4 minute read
FIDO signature counters detect cloned credentials. Synced passkeys return zero. What enterprises should require for high-assurance access.

A Nonfunctioning FIDO Counter Is A Serious Enterprise Risk

FIDO authentication is widely described as resistant to phishing, credential theft, and replay. Those claims are broadly justified. But one important security mechanism remains inconsistently implemented across the ecosystem: the signature counter. For consumer accounts, that inconsistency may be an acceptable tradeoff for convenience. For administrators, infrastructure operators, financial systems, identity recovery, and other high assurance applications, it is a risk that should no longer be ignored.

Kevin Surace
4 minute read

The Code Was Real. The Approval Was Real. The Request Came From Ten Thousand Miles Away.

An employee received an authentication prompt. It came from the real application. It arrived exactly when expected. They approved it. Every system behaved correctly. The credential was valid. The prompt was authentic. The approval was logged. The only thing absent from the transaction was the person the account belonged to. They were ten thousand miles from the attacker holding their session. Kevin Surace puts identity attacks at roughly 90 percent of hacks. His more useful point is what those attacks are not: clever. They are cheap, repeatable, and rented as kits for around $200 a month.

Kevin Surace
2 minute read
Can MFA be Bypassed?

Can MFA be Bypassed?

Multi-factor authentication (MFA) was designed to protect organizations when passwords were stolen. Unfortunately, attackers have adapted to the methods most enterprises now use. They intercept codes, overwhelm employees with approval requests, relay authentication through convincing phishing sites, steal active sessions, manipulate help desks, and exploit account recovery processes. The problem is not the concept of using multiple factors. The problem is that most MFA systems still depend on information or actions that can be shared, intercepted, relayed, reset, or approved by the wrong person.

Kevin Surace
5 minute read
The Better Architecture Is Biometric Assured Identity

Do Not Migrate Twice. Vishing Is Coming for Your Passkeys.

The next great cyberattack may not start with malware, a zero day, or someone furiously typing commands into a terminal. It may start with your phone ringing. “Hi, this is IT. We are completing the company’s mandatory passkey migration. Microsoft is changing its authentication requirements and your account still needs to be updated. I can walk you through it. It will only take two minutes.” That call is no longer hypothetical. Attackers are already using almost exactly this script. And they are not trying to steal your old MFA code anymore. They are after something much more valuable. They want to become your new passkey.

Kevin Surace
10 minute read
Hackers Do Not Break Passkeys. They Just Trick the User.

Hackers Do Not Break Passkeys. They Just Trick the User.

Hackers are already adapting the same social engineering playbook that defeats MFA and authenticator apps. Soon, Phishing as a Service kits will handle the technical details for them. Token removes the manipulation paths that phone based passkeys leave open.

Kevin Surace
15 minute read
1 2 3 4

Stay Identity Assured

Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.