From Fake Workers to Account Recovery: The Growing Identity Verification Risk
Security teams have spent years hardening authentication, but attackers are now targeting the processes used to establish or recover identity, making it harder to verify users during onboarding and recovery events.
Intelligence analysis by Llama

Attackers are exploiting legitimate processes to gain access to corporate systems, and organizations need stronger measures to deliver identity verification during high-risk events. Solutions like Specops Verified ID can help service desk agents confidently confirm identity before sensitive actions take place.
Imagine you're trying to get into a building, but the guard needs to make sure you're really who you say you are. That's what's happening with identity verification - attackers are trying to trick the guard into letting them in. To stop this, we need to make sure the guard has stronger tools to verify who's really there.
Analysis
The Growing Identity Verification Risk
Security teams have spent years hardening authentication, with controls like multi-factor authentication (MFA) and conditional access now commonplace. While stronger authentication can make traditional credential theft less effective, it doesn’t solve every identity problem. There are several points in the identity lifecycle where trust is established or re-established: When a new employee joins. When someone loses access to their account. When a password or MFA factor needs to be reset. When the service desk is asked to make a sensitive change to an account.
Rather than stealing credentials or bypassing MFA, an attacker can instead try to convince the service desk that they are the account holder, using social engineering to exploit legitimate processes. That puts greater pressure on organizations to secure both the login as well as the processes around account creation and recovery.
How Attackers Exploit Identity at Onboarding and Recovery
In late July 2026, the US Department of State and allies including Japan, Canada and the UK issued a joint alert warning that North Korean IT workers were impersonating foreign nationals to secure employment. Their tactics focus on falsifying identity documents, such as using images supplied by a third party based in another country to register accounts. The North Korean then carries out the actual work. These workers typically target technology companies, so the important point is not that every organization should expect the same type of campaign. It is that onboarding creates a moment when trust is established for the first time. If identity checks fail at that stage, the attacker can enter the environment with access that appears legitimate.
The same issue can occur during the recovery process. Threat actor groups like Scattered Spider are proficient at social engineering, impersonating employees and calling the service desk to reset passwords that gift access to an account. This tactic was linked to the 2025 M&S ransomware breach , which contributed to an estimated $400 million hit to the retailer’s operating profit through lost sales.
Secure Your Active Directory Passwords
Verizon’s Data Breach Investigation Report found stolen credentials are involved in 44.7% of breaches. Effortlessly secure Active Directory with compliant password policies, blocking 6+ billion compromised passwords, boosting security, and slashing support hassles! Try it for free
Strong Authentication Still Depends on Strong Identity Checks
When someone calls the service desk claiming that they’ve forgotten their password or lost access to their authenticator, the agent needs to be able to confidently verify the person calling is the real account owner. However, in many organizations identity checks can still rely on relatively weak signals. A service desk might ask for an employee ID or phone number. Security questions are still common, asking the caller the name of their first pet or where they went to school. The problem is that many of these checks can be researched, stolen or manipulated.
Attackers can find personal information through data breaches or social media. Even in instances where stronger checks are in place, the North Korean remote worker campaigns demonstrate how documents and other identity evidence can be altered or fabricated. AI is making impersonation more convincing, too. Attackers can use synthetic profiles, manipulated images, cloned voices and deepfake video to support a false identity or make a social engineering attempt more believable.
Strengthen Verification During High-Risk Identity Events
Solutions like Specops Verified ID add another layer of assurance and helps service desk agents confidently confirm identity before sensitive actions take place. It does this by combining government document scanning and validation with biometric liveness detection. Document checks help confirm that the ID being presented is legitimate, while liveness detection helps verify that a real, present person is completing the process rather than relying on a static image or other replayed evidence.
During onboarding, this gives organizations a stronger way to verify new employees before granting access to corporate systems. That can reduce the risk posed by fraudulent applicants and impersonation attempts, including tactics seen in North Korean remote worker campaigns. The same approach can be applied when high-assurance verification is needed, such as password resets for privileged accounts.
Rather than adding complexity to every identity event, Specops Verified ID applies stronger verification where the consequences of getting it wrong are highest.
Key points
- Attackers are targeting the processes used to establish or recover identity, making it harder to verify users during onboarding and recovery events.
- Organizations need stronger measures to deliver identity verification during high-risk events.
- Solutions like Specops Verified ID can help service desk agents confidently confirm identity before sensitive actions take place.
- Stronger identity verification measures can reduce the risk of attackers gaining access to corporate systems.
If organizations implement stronger identity verification measures, such as Specops Verified ID, they can reduce the risk of attackers gaining access to corporate systems. This can lead to a more secure and trustworthy environment for employees and customers alike.
If organizations fail to implement stronger identity verification measures, they may be vulnerable to attacks that exploit legitimate processes. This can lead to significant financial losses and damage to their reputation.


