Kevin Surace
2 minute read
An employee received an authentication prompt. It came from the real application. It arrived exactly when expected. They approved it. Every system behaved correctly. The credential was valid. The prompt was authentic. The approval was logged. The only thing absent from the transaction was the person the account belonged to. They were ten thousand miles from the attacker holding their session.
Kevin Surace puts identity attacks at roughly 90 percent of hacks. His more useful point is what those attacks are not: clever. They are cheap, repeatable, and rented as kits for around $200 a month.
Walk the sequence he describes. A PDF with no links in it, so it clears the filters. Written for one person, assembled from what sits on the dark web and on LinkedIn. It points to a domain one character off from the real one. A pixel-perfect page is waiting there.
Credentials are entered and relayed in real time. The real application, seeing a valid login, sends an authentication prompt. The employee is expecting that prompt. They approve it.
Everything worked as designed. That is the problem.
Authenticator apps and passkeys travel over cellular and Wi-Fi. They work anywhere on the planet. An approval granted in one city is indistinguishable from the same approval granted on another continent. Geography proves nothing about who acted.
The underlying constraint is simpler. Anything a person can read out, forward, or hand over can be shared. A six-digit code can be spoken aloud on a phone call. A push approval can be granted under pressure. A synced passkey follows the account, not the human being.
Surace describes a control many organizations already have in place: transactions above a million dollars require human approval. It was written when a human was the only thing that could be on the other side of the request.
An agent working through a task list can satisfy that control as easily as the CFO can. The approval step is a signal, and a signal can be produced. Nothing in the flow asks whether a person is present.
Token's approach is narrow on purpose.
Dedicated hardware. No apps and no screen. Nothing to phish, and no interface through which to socially engineer the wearer.
A fingerprint matched on the device in roughly 100 milliseconds, and kept off the network.
Secure Bluetooth that holds the device within three feet of the machine being signed into.
The credential is hardware-bound and phishing-resistant. The private key stays on the device. The biometric never leaves it. The authorized individual has to be standing there.
There is no code to relay, no prompt to approve from a distance, and no software path to a signature. This is identity assurance rather than authentication: proof that the individual — not the credential, not the device, not an agent acting on their behalf — was physically present and acting.
Sean Martin closed the briefing with the sharpest line in it: we have to go back to the physical world to protect ourselves.
Identity is the last control that cannot fail. Bind it to hardware, verify it with a live fingerprint, and confine it to three feet, and the attacker ten thousand miles away has nothing left to relay.
Watch the full brand briefing on YouTube or listen on ITSPradio. Part of ITSPmagazine's Black Hat USA 2026 coverage.
For years, MFA was treated as a timing problem. Add enough friction, the thinking went, and attackers would be exposed before they could act. Real-time phishing relay attacks dismantle that assumption. They do not wait for friction. They route around it.
The MGM Resorts and Caesars breaches were not anomalies. They were demonstrations of a structural fact: identity that can be reset remotely will eventually be reset by someone who should not have access. What made those incidents significant was not the sophistication of the attack. It was its simplicity. Attackers did not exploit code vulnerabilities. They impersonated employees, contacted help desks, and had authentication reset. Legitimate access followed. Everything else — ransomware, data theft, operational disruption — was a consequence of that first failure.
Grafana recently disclosed that an unauthorized party obtained a token granting access to the company’s GitHub environment and used it to download portions of its codebase. Grafana confirmed that no customer data or personal information was accessed, invalidated the compromised credentials, and applied additional controls. The response was fast, and the containment was effective.
Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.