“Stolen credentials are involved in 44.7% of breaches,” a stark figure from Verizon’s Data Breach Investigation Report that frames a shifting problem: defenders have hardened logins, but attackers are pivoting to the human moments where identity is first created or later re-established.
July 2026 joint alert: North Korean remote workers impersonate foreign nationals
In late July 2026 the US Department of State and allies including Japan, Canada and the UK issued a joint alert describing a coordinated campaign in which North Korean IT workers impersonated foreign nationals to gain employment. Their method, as described in the advisory, centers on falsifying identity documents and using images supplied by a third party based in another country to register accounts while the North Korean conducts the actual work.
The alert highlights a fundamental vulnerability: onboarding is the moment trust is set. If checks at that entry point are weak or can be manipulated, an attacker can enter an environment with apparently legitimate credentials and permissions.
Service desk and recovery attacks: Scattered Spider and M&S, 2025
Attackers also exploit recovery and help-desk workflows. The threat actor group Scattered Spider is proficient at social engineering, impersonating employees and calling service desks to obtain password resets. That same tactic was linked to the 2025 M&S ransomware breach, which the source ties to an estimated $400 million hit to the retailer’s operating profit through lost sales.
These incidents show that a successful break need not come through a cracked password or bypassed MFA; it can arrive when an agent is persuaded to hand over access during a support interaction.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildWhy strong authentication still depends on strong identity checks
Security teams have invested heavily in controls such as multi-factor authentication and conditional access, and those measures have reduced the impact of traditional credential theft. Yet the source stresses that “strong authentication still depends on strong identity checks.” Several stages of the identity lifecycle are singled out as high-risk: initial hiring/onboarding, account recovery, factor resets, and service-desk changes to sensitive accounts.
Service-desk verification often rests on weak signals—employee ID, phone number or knowledge-based security questions like a first pet’s name or school attended—that the source says can be researched, stolen or manipulated. Document fabrication and alteration are already in play in the remote-worker campaigns, and the source adds that AI is amplifying impersonation through synthetic profiles, manipulated images, cloned voices and deepfake video. Together, these make it harder for agents to act with confidence when a caller claims an identity.
Specops Verified ID: document validation plus biometric liveness
The source offers a concrete mitigation: Specops Verified ID. According to the material, the product combines government document scanning and validation with biometric liveness detection. Document checks aim to confirm the legitimacy of an ID, while liveness detection verifies that a real, present person is completing the process rather than a static image or replayed evidence.
Applied during onboarding, the product is presented as a way to reduce risk from fraudulent applicants and impersonation attempts like those described in the North Korean campaigns. The same controls can be used selectively—for example, during high-assurance password resets for privileged accounts—so stronger verification is applied where the consequences of error are highest rather than adding friction to every identity event.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: Review high-risk identity events—onboarding, recovery, privileged resets—and consider adding document validation and liveness checks where staff currently rely on knowledge-based or low-assurance signals.
- Procurement and enterprise leaders: Factor in solutions that apply stronger verification selectively to sensitive account events, and weigh offerings that pair government ID validation with biometric liveness rather than blanket increases in friction for all users.
- End users and employees: Be aware that attackers now target help-desk and onboarding workflows as an alternative to credential theft; organizations may introduce stronger identity checks at those moments, including document scans and liveness steps.
Defenders have made meaningful gains at the login, but the record presented here shows attackers shifting their focus to the permit-issuing moments around identities: onboarding and account recovery. The interplay is clear—stolen credentials remain a major factor in breaches, yet the weakest link increasingly is the human and process layer that grants or re-establishes access. Solutions combining document validation with biometric liveness are offered as one path to raise assurance where mistakes are most costly.




