Identity Security Perspective

When recovery becomes the attack path

Attackers are adapting to phishing-resistant authentication by targeting the moments when users enroll, reset, and recover their credentials.

Executive Edition
Driven | Identity Security Perspective | August 2026 | Identity Security

The ShiftAttackers no longer need to steal the credential

The identity lifecycle itself has become the target: convince a legitimate user to approve a reset or enroll an attacker-controlled authenticator.

Recent threat intelligence describes a growing pattern in which intrusion actors impersonate IT or security staff while simultaneously initiating legitimate self-service recovery. The caller manufactures urgency, guides the user through the real workflow, and persuades them to share a one-time code or approve a prompt. In the most direct variation, the attacker never deploys a credential-phishing kit; the organization's own recovery mechanism performs the sensitive change after the user supplies the required approval.

Phishing-resistant sign-in does not automatically create phishing-resistant enrollment and recovery. The attacker simply moves to the weakest point in the identity lifecycle.

1 in 5
Recent Phishing-Domain Alerts Referenced Passkeys
0
Stolen Passwords Needed in the Simplest Path
0
Critical Lifecycle Points: Enroll, Reset, Recover

The Attack PathSelf-service can become attacker-assisted service

The adversary combines reconnaissance, a live phone call, and a legitimate recovery transaction into one coordinated takeover.

The sequence is efficient. First, the actor identifies a workforce account and confirms that public self-service recovery is available. Next, they learn which verification methods the workflow offers. While impersonating the help desk on a voice call, they trigger the reset from their own device and steer the victim toward the weakest available challenge. Once the user approves the event, the attacker can reset the credential or register a factor they control, creating valid access that may survive a password change.

Reconnoiter

Find exposed recovery.

Impersonate

Pose as IT support.

Trigger

Start a real reset.

Approve

Coerce the user.

Persist

Enroll a new factor.

This is a policy problem as much as a user-awareness problem. If recovery accepts any enrolled factor, permits initiation from any network, and treats a single approval as sufficient assurance, the attacker controls the timing and selects the most phishable route. Training helps users recognize the call; architecture determines whether one mistake becomes account control.

The Control ModelMake recovery at least as strong as sign-in

Every credential and authenticator change should be governed as a privileged identity transaction.

01

Require phishing-resistant proof

Use device-bound passkeys, hardware security keys, smart cards, or equivalent factors for enrollment and recovery.

02

Bind recovery to trusted context

Require a managed device, known network, established session, or separately verified identity before changing authenticators.

03

Remove the weakest-choice problem

Do not let the requester select an SMS code, voice approval, or other weaker method when stronger assurance is required.

04

Protect help-desk exceptions

Use independent identity verification, dual control, short-lived recovery credentials, and explicit audit trails.

05

Detect lifecycle abuse

Correlate reset initiation, call-center activity, new-device enrollment, factor changes, session creation, and risky application access.

Resilience also means giving users more than one strong recovery path. Multiple phishing-resistant authenticators across separate devices reduce emergency help-desk resets and remove pressure to reintroduce a weak fallback when a laptop or phone is unavailable.

The Enterprise ResponseSecure the entire identity lifecycle

Strong authentication is incomplete if enrollment, recovery, factor replacement, and exception handling operate at a lower assurance level.

Identity teams should inventory every path that can create or restore access, remove unnecessary public recovery entry points, enforce context-aware policy, and place high-risk changes behind additional verification. Security operations should treat authenticator enrollment and recovery as detection events, with rapid revocation when a new factor is followed by unusual access. Driven helps organizations assess these end-to-end identity journeys, test social-engineering resistance, harden policy, integrate device and network trust, and connect identity telemetry to response workflows — strengthening security without making legitimate recovery unworkable.

Reduce

Minimize exposed recovery paths and eliminate weak fallback factors.

Verify

Demand strong proof and trusted context before identity state changes.

Respond

Detect factor manipulation, revoke sessions, and reverse unauthorized changes.

Recovery should never be the weakest link.

Identity assurance must survive the moment a user is under pressure. If recovery is weaker than authentication, recovery becomes the attacker's preferred login method.

Secure Your Identity Lifecycle →
🌐 www.driven.tech 📞 (646) 604-4400 ✉ security@driven.tech
Go to Top