Token Blog: Phishing and Ransomware Articles

The Code Was Real. The Approval Was Real. The Request Came From Ten Thousand Miles Away.

Written by Kevin Surace | Aug 31, 2026, 3:21:01 PM

An employee received an authentication prompt. It came from the real application. It arrived exactly when expected. They approved it. Every system behaved correctly. The credential was valid. The prompt was authentic. The approval was logged. The only thing absent from the transaction was the person the account belonged to. They were ten thousand miles from the attacker holding their session.

Kevin Surace puts identity attacks at roughly 90 percent of hacks. His more useful point is what those attacks are not: clever. They are cheap, repeatable, and rented as kits for around $200 a month.

Nothing In the Chain Is Exotic

Walk the sequence he describes. A PDF with no links in it, so it clears the filters. Written for one person, assembled from what sits on the dark web and on LinkedIn. It points to a domain one character off from the real one. A pixel-perfect page is waiting there.

Credentials are entered and relayed in real time. The real application, seeing a valid login, sends an authentication prompt. The employee is expecting that prompt. They approve it.

Everything worked as designed. That is the problem.

Location Is Not Proof

Authenticator apps and passkeys travel over cellular and Wi-Fi. They work anywhere on the planet. An approval granted in one city is indistinguishable from the same approval granted on another continent. Geography proves nothing about who acted.

The underlying constraint is simpler. Anything a person can read out, forward, or hand over can be shared. A six-digit code can be spoken aloud on a phone call. A push approval can be granted under pressure. A synced passkey follows the account, not the human being.

Agents Inherit the Same Gap

Surace describes a control many organizations already have in place: transactions above a million dollars require human approval. It was written when a human was the only thing that could be on the other side of the request.

An agent working through a task list can satisfy that control as easily as the CFO can. The approval step is a signal, and a signal can be produced. Nothing in the flow asks whether a person is present.

What We Require Instead

Token's approach is narrow on purpose.

Dedicated hardware. No apps and no screen. Nothing to phish, and no interface through which to socially engineer the wearer.

A fingerprint matched on the device in roughly 100 milliseconds, and kept off the network.

Secure Bluetooth that holds the device within three feet of the machine being signed into.

The credential is hardware-bound and phishing-resistant. The private key stays on the device. The biometric never leaves it. The authorized individual has to be standing there.

There is no code to relay, no prompt to approve from a distance, and no software path to a signature. This is identity assurance rather than authentication: proof that the individual — not the credential, not the device, not an agent acting on their behalf — was physically present and acting.

Back To the Physical World

Sean Martin closed the briefing with the sharpest line in it: we have to go back to the physical world to protect ourselves.

Identity is the last control that cannot fail. Bind it to hardware, verify it with a live fingerprint, and confine it to three feet, and the attacker ten thousand miles away has nothing left to relay.

Watch the full brand briefing on YouTube or listen on ITSPradio. Part of ITSPmagazine's Black Hat USA 2026 coverage.