Working notes on account takeover, help desk social engineering, deepfake fraud and identity verification, written for the security and IT teams who handle account recovery.
75
piecesLatest September 16, 2026
Blog
TfL made 28,000 employees show up in person to reset a password
When TfL's network was compromised, the way out was 28,000 employees showing up at an office in person. ATO Protect Account Recovery+ for Entra…
September 16, 2026
Blog
Verifying people who don’t have a Social Security number
The SSN sits in most US verification scripts as the fallback question. For a sizeable part of your user base there is no answer…
September 1, 2026
Blog
Your AI agent is about to act for someone. Who checked that someone?
An agent acting on someone's behalf inherits their authority without inheriting any way to confirm they are who they say they are.
September 1, 2026
Blog
The fake employee problem: North Korean IT workers and deepfaked interviews
Nothing is breached. Someone is onboarded and paid through the normal process, and the failure happened at hiring.
August 21, 2026
Blog
SIM swap protection for enterprises: how to check, detect, and block it
The first sign is usually the phone going quiet. By then the one-time passcodes have been arriving somewhere else for a while.
August 21, 2026
Blog
CEO fraud and executive impersonation: verify the person behind the wire
The target is rarely the executive. It is the person who processes the request, and the approval chain assumes someone else already checked who…
August 21, 2026
Blog
Account recovery in Microsoft Entra ID: the complete playbook
Entra ID has five ways back into an account. Two run automatically, and the other three end with a person deciding who is on…
August 21, 2026
Blog
Agent verification: proving your help desk is really your help desk
Agent verification runs the help desk check backwards: the employee confirms the agent is genuine before sharing a code or approving a prompt.
August 21, 2026
Blog
How to verify users without pre-registration
Most identity verification assumes the user enrolled something first. The never-enrolled users are the ones attackers call about.
Ori EisenAugust 21, 2026
Blog
MFA fatigue, MFA bypass, and the reset desk: three ways MFA actually fails
Teams that have deployed phishing-resistant MFA often still leave the reset path wide open.
August 21, 2026
Nothing on this page matches that filter. Clear the search or choose All.