Generative AI has made impersonation scalable, convincing, and dangerously effective, exposing a critical flaw: a verified credential no longer means a verified human. From deepfake video calls to exploited recovery processes, attackers are bypassing traditional defenses, forcing organizations to rethink identity with human-centric assurance.
To address this shift, organizations must move beyond traditional identity controls such as MFA and Zero Trust frameworks. By integrating human-centric identity assurance, leveraging biometric verification, and securing high-risk workflows like onboarding and account recovery, enterprises can better detect AI-driven impersonation and strengthen trust across digital interactions.
Jonathan Care, Lead Analyst at KuppingerCole will explore how AI is exposing critical assumptions in current identity architectures, highlight where Zero Trust falls short, and provide strategic guidance on evolving identity security to address AI-driven threats across workforce ecosystems.
Peter James, Chief Product Officer at iProov will examine real-world attack scenarios involving deepfakes and social engineering, explain how biometric liveness detection can verify genuine human presence, and demonstrate how organizations can embed advanced identity assurance into existing IAM, IGA, and PAM infrastructures.
Good morning, good afternoon, good day, wherever you happen to be. Welcome to this webinar, Securing Workforce Identity Against AI Driven Impersonation, where we're going to talk about closing the gap between the right credential and the right human. I'm Jonathan Care, I'm Lead Analyst for KuppingerCole Analysts, and with me is Peter James, Chief Product Officer of iProov.
Peter, thank you for joining us. Hi James, thanks very much.
Jonathan, sorry, thanks very much, very happy to be here. Excellent.
Okay, so we got some really interesting stuff to date, so let's move through it. Before we start, I'll just go through a few housekeeping features. You are muted centrally, and that's being controlled by my producer today behind the scenes, Selina, so there's no need to mute or unmute yourself. I don't think today we're running polls, but there's plenty of opportunity for you to pass your opinion if you put questions into the Q&A session.
There's a tab at the bottom saying Q&A and questions, and of course we'll be recording this webinar, and the recording and the presentation slide decks will be made available for download in the coming days. Without further ado, let's lead in.
So, the question, am I who you expected? Peter, have you got a view on this?
I think it's definitely one of the big questions of now for us, and particularly in the workforce place where traditionally we do trust to expect everyone who sort of joins video calls or who comes remotely into sessions, and generally people are who you expect them to be, but I think you may yourself have noticed, Jonathan, that perhaps I've had a little bit of work done over the weekend since we last met, because in fact I'm running a deep fake right now of my face, and so if I just switch that off, you'll notice I suddenly aged a few years and change, and I just wanted to just sort of show actually how effective these deep fakes can be, how they're something you can just do in real time now, just on a normal work laptop as I've got running here.
It really is as simple as just clicking a few buttons, no special hardware needed, obviously you need the software, but even that is readily downloadable from the internet. And it's fascinating, and we all place great emphasis on visual impression for better or for worse, possibly worse in my case, but we do, and we believe the evidence of our eyes. We have centuries of evolution telling us to do this, and so as you say, when you have nefarious people who take advantage of this in a recruitment environment, a work environment, in any kind of many situations, it can be quite serious.
And so what we're going to start off talking about is this gap in zero trust. We have credentials, and we all understand how credentials work, we understand about multi-factor authentication, we understand about not sharing credentials, avoiding being captured, avoiding captioning cookies or hashes so they cannot be reused, but we don't think much about the human, we hope, wielding those credentials. So let's talk a bit about that, and we've had now a decade of zero trust.
As I said, we've got single sign-on, we've got multi-factor authentication, we've now evolved to pass keys instead of passwords, and these are now a consumer-grade tool. And of course, we now have conditional access, where what access you have depends on how much the system believes you. So they take various risk and recognition signals, and they say, well, you're logging in from a strange device, so I'm not going to let you set up and pay a new beneficiary on your bank account.
And despite all this technology in the consumer space, but especially in the workforce, identity attacks are not slowing down, they are accelerating. In fact, I'd posit that they are the number one risk in the organization when you're looking at identity-driven attacks. And of course, the reason is, as with many things in cybersecurity, there's an inherited assumption that we've all implicitly accepted and not questioned, and it's this. If the credential is valid, the human behind it is legitimate. And of course, that assumption has always been exploitable.
In the very early days of my career, people would leave their terminal logged in, and we put a message in saying, hi, I'm not wearing any trousers today. Oh, that kind of silly workforce joke. But of course, criminals have taken these things and built them up and made them quite serious. And with generative AI, this now happens on an industrial scale. We have a systemic, scalable threat in front of us. Putting that in some numbers, this is what I've come up with, and I'd be obviously interested in your thoughts. There aren't any malware, or there are 82% of intrusions are not based on malware.
They're not based on exploits, they're not based on gaps in code, on SQL injections. Attackers are just walking in through identity, not hacking. And 62% of organizations experienced a deepfake social engineering attack in the past 12 months. Perhaps that 62% of them realized it was a deepfake attack. The other 38% didn't. Point being, of course, it's no longer a boutique threat. It's a baseline. And 17% of US hiring managers have encountered deepfake candidates during video interviews. This is the insider threat, folks. This is it. And that's a broad number across industry.
From our research, we know that in certain industries where, for example, pharmaceutical research, semiconductor foundries, this is a much higher percentage. Some organizations are saying, we have this problem every week. So on day one, before someone's even joined your organization, your workforce is under attack. I don't know about you, Peter, but that strikes me as pretty sobering thinking. Absolutely, yeah. I think all three of these stats are very sobering in their own right, but bring it all together, and that's a pretty shocking state of affairs for us all.
And the worrying thing here really is that this is today. But as you go forward, the reason that a lot of these attacks are working is because we're moving more and more to remote workforces. And so interviews are being done remotely. People are accessing systems remotely. And the AI is getting better. It's getting more and more and more accessible, more and more realistic. And so these threats are only getting more and more challenging to spot. So these stats are pretty scary now. I think they will only increase if we don't do anything about the challenge. Absolutely.
So let's have a look at what we can do. And what's the impact?
Well, identity is now the primary attack surface. And we talk about identity first security.
Well, this is where it has teeth. The incidents are defining the era we're in. They are not outliers. They're not, oh gosh, this is unusual. These are the pattern. And every one of these things that I'm going to go through involves an impersonation attack. Scattered Spider, $150 million of loss, 120 plus intrusions via impersonated IT calls. A very simple method that actually Pete's going to walk us through later on in this presentation. Arup lost 25 million to a single deepfake video conference. North Korean IT workers have infiltrated over 300, 1,400, 1,500 companies. That we know of.
MGM, as we know, had a very public loss, $100 million or more from a 10 minute call to the help desk. Marks and Spencers, Co-op, Jaguar Land Rover. That's 1.9 billion pounds of loss. UK retail impacted from coordinated attacks. And of course, LastPass, Change Healthcare, again, have had deepfake assisted breaches. These are just the tip of the iceberg that I found during a very short research cycle. There are many more. So having looked at the problem, clearly we need to devise solutions. And the question for us is, where does the identity break in the life cycle and what can we do about it?
And there are four points where identity breaks. Remote hiring, onboarding, shared device access, and account recovery. So where you have kiosks, frontline devices that are bypassed with stolen pins, that's a bad spot. Credentials hired to somebody who's actually never hired in the first place. And of course, right back to the beginning, deepfake candidates passing live video interviews. And as far as the poor help desk, well, they've got enough to do with genuine password resets. When they're then overloaded with fakes, one can feel almost sorry for them.
So let's look at at least stage one, remote hiring. Deepfake candidates pass a live video interview. So somebody like Peter's Deepfake comes on the video, impresses you with their erudition and technical knowledge. And you think, yes, there's a person I'd like to have in the company. And of course, we interview, we hire and onboard. And all this is done remote. You don't meet in person. Europe has different cultural norms. And so many parts of Europe do still prefer an in-person meeting.
However, I know of many companies where I've actually, I've been hired in my time, having never actually met my hiring manager until after I joined the company. So the liveness, we used to talk about this 10 years or so ago, the liveness of a video call, and I stopped when I had one client say, well, what about when I have a dead one? But nevertheless, the genuine presence no longer proves a human.
And again, this North Korean IT work scheme, which we are still uncovering, has at least 3,400, 4,500 infiltrated. Background checks and NDAs.
Yes, they're good and they're important and they prove the papers are legit. They do not prove the person who is presenting the papers are legit. The bottom line here is that if the candidate isn't real, then no downstream control saves you.
And Pete, I think we've got a video here. It's got a bit of sound with it. So if you want me to mute it, but otherwise, let's hear a little story of Abby.
Hi, Abby. Thanks for joining us. Just before we get started on here, I'm just going to run a quick check on my side. That's great. So I'm just wondering if maybe you're running some sort of filter or something on your side that maybe you could switch on.
Okay, let me just try that again. Perfect. That's great. Thanks very much. Let's get stuck into the interview. So quite a short and quite simple demonstration there, Jonathan, but hopefully it sort of demonstrates the challenge, right? Someone joins just as I did at the beginning of the webinar here with a deep fake Facebook already running. There's no way for you to tell on that. And because you can easily have created your own LinkedIn profile with that same face on the LinkedIn profile, everything lines up beautifully. There's no reason for you to expect it to be untrue.
But fortunately, we don't need to trust our eyes if we have a system like the one that we've demonstrated here that we at iProof have built. And what we've done is we've used all of our expertise from doing this for years in other use cases and brought that now to the video conferencing.
And this, as I'm sure you'd say, it's quite a simple demonstration. Abby, bless her heart, wanted to present herself for the best effect on the interview. So she applied the digital effect equivalent of a makeup job.
However, your system was able to pick up that this was not a genuine face. And it becomes, I would say, obviously more important when you actually find that it is, yeah, people who are perhaps masquerading as African American, where in fact they are North Korean. So it is important, I think, to do this. It's not necessarily about overcoming interviewer bias. It's not about making detracting from people. But what we are looking for here, I think, is to make sure that we can place that trust in what we see. Absolutely. Right.
So anyway, I'll stop Abby from coming back in. And let's talk about use case two, which is onboarding. And of course, we all know this. We've all done onboarding in our careers many times. And at onboarding, we bind credential to a person. So in my first day here, it was like, thank you for joining, covering a call. Here's your username and password. And if the person isn't who they claim to be, every control downstream inherits that fault. So if somebody has picked up Jonathan Kerr's username and password, all bets are off from there on.
And this can include laptops shipped to addresses no one has visited, then placed on eBay or whatever, or even used to gain access to confidential employer systems because they have credentials as well, don't forget. And on that subject, as you're enrolling someone, you'll often enroll them in your MFA scheme. So on day one, the imposter gets access to MFA.
HR, IT, both accept the video call as proof of identity. And why wouldn't they? It's the same person they've seen through the recruitment process. And so zero trust inherits that fraudulent enrollment. And then SOC alerts say, okay, this is just a legitimate user trying to find their way around the organization. And that's a problem. And I think, Pete, you've got another video to show us. And I think perhaps you can talk us through this one. But my view, and again, one of the things I want to really get through on this webinar, once provisioned, the imposter is identical to a real employee.
But Pete, here's a video I'd like you to talk us through. And so we've got somebody starting the onboarding process. And just talk us through what we're going to see here.
Yeah, thanks, Jonathan. So this is a simple demo of someone who's just about to join the company. And they've been sent a link in order to identify their verification. So they've clicked on the link. And now it's going to take them through a simple IDB process, sort of thing you'll have seen many times on other systems as well. So I'm going to confirm my email address first. So it's sent a one-time code to my email address. We'll then do the same for my phone number as well.
But the difference here now is that we're also then going to ask them to scan some sort of identity verification document. So this could be a driving license.
Ideally, it's something like a passport that's got an NFC chip in it. So we can check the validity of the document and the data because it's actually stored in the chip. We're not just reading it. But either way, we are checking the details then against the document, which we can then share and make sure it matches what they've given us. But we're also able to grab a photo from that document. So now I've got that picture of the person that I expect it to be. Now I do the face check. And so this is going to use iProof standard liveness. So this is our dynamic liveness. You'll see the flash mark.
This is our challenge response that we use to make sure it's not a replay attack and to give us additional bits of data to be able to do the liveness check. It's the sort of thing that's used by the NHS and other governments. And now it's done that check. So now we know that it was me. I was a real person. I was really there. And that I matched the identity document that I was using. Now all that data has been captured and verified. We can then share it back into the HR systems to create that biometric profile and the identity within the system.
I must say, by the way, here I am trying to control the presentation on my laptop. But that seemed pretty slick and seamless. The point like, wow, that happened before I was expecting. It wasn't high friction. It wasn't overly intrusive. It didn't demand vast amounts of personal data. Didn't have to take a swab from the inside of your cheek. It just worked. And for me, I mean, this is another feature, I think, is that at any enrollment relationship, especially workforce, we do not want to alienate those that we're enrolling.
So just an observation for me that not only is this adding a dimension of security, but it is not adding a frictional inhibitor. And we can use this process at any point as well. That's the nice thing about it. It's decoupled. So if you wanted to do this before you hired, so if you wanted to do it at the interview stage and make sure that the person you're interviewing matches their documents, then you could introduce it at that stage as well. So yeah.
Again, I'm going to take you off script a bit now since we've talked about it. But would it be possible, for example, if I was doing a step up to bring this process in so I can say, yes, I am stepping up the genuine holder of the account, not some impersonator?
Yeah, absolutely. So the idea is that we want to, this creates that validated biometric profile for that user. And so now we can use that across any point of the life cycle of that user. So if it was a, if we want to be integrated into the step up process, I've done the validation against my passport or driving license in this case, we've now got that profile. So the only thing I now need to do is just that face check, that last step in the process that you saw there. And that's equivalent to checking it against my passport again.
All right, well, thank you. Anyway, so moving on to use case three, shared device access. And there are plenty of legitimate cases where people do share devices. One that everyone talks about is a hotel front desk. But in any case, where you have kiosks, tablets, frontline terminal, you can expect that these will be shared, you can expect pins will be shared. And so effectively, we have no binding of the credential to the person. So if the attacker has captured the pin, just by observation, or by bribery and some other type of coercion, they type the pin, and they're in.
clocking fraud, which we're all familiar with. And for those, I'm, I'm old enough that my first job in a steelworks, I actually had a cardboard time card stamping.
And yeah, it was quite common, you see, oh, look, somebody's already clocked in, they haven't arrived yet. How, how, how wonderful for them.
And, but the scale of this is not just in the steelworks in Cardiff, where I grew up. But it's everywhere. It's in retail, it's in healthcare, it's in manufacturing, as I said, logistics, these are all key industries in any country. And frontline workers, the people who are on the retail floor, the people who are in the factories, the people are in the manufacturing plants, typically outnumber office staff three to one. So if we look solely at compliance logs, they show the credential, they do not show the human.
Again, we decoupled the credential from the human that should be presenting. And if you look at HIPAA, if you look at PCI BSS, which remains important, if you look at Sarbanes-Oxley, these all require explicitly need real attribution.
And we've, we've, we've skated over that, because of this implicit assumption we've all made as security designers, architects and engineers. And the compounding effect of this is that that one pin cascades across every shift. So that secret is known by everybody. Insider fraud then blends with external attack. And I've researched so many cases of this where remote facilities are rife with insider fraud, and they look at it, oh, look, there's an external agency enabling, providing infrastructure and support for theft on a grand scale.
You know, theft of expensive silicon chips in manufacturing, theft of designs, theft of patient records of key customer details. And in fact, this, there was a report of this just recently. The UK Biobank, I believe, has had a data leak. And I noticed in the news in March, they said there was no data leak. And apparently today, well, it's down to a few bad apples, isn't it always? Shared devices are invisible to endpoint detection. So all that money you spent on EDR, MFI friction blocks adoption.
So it's quickly discarded in these environments, which means that your audit trail and the evidence you're presenting to your auditors is worthless. And I think, Pete, you've got another great illustrative example to show this. So I'll let it run if you can talk it through.
Yeah, thank you again. Yeah. So this is a Windows login. So this is frontline worker logging into their system. They just hit the login with iProof. And we use that biometric profile that we created earlier, to now check that it's someone on the system. So it's recognized that it's me, and it's logged me in. But it's not logged me into my account, it's logged me into the shared account. So difference now, though, is that the system knows that it's actually me that's logged in, even though I've logged into that shared account.
But if I now click into Internet Explorer here, it now recognizes again, that it's me. And now it's logging me into my personal account, again, checking the face first, but it's logging me into my personal account for SAS. So if I need to access my timesheets, the example you were talking there about clocking in, Jonathan, then I can do that within the shared account, and then log back out to stay in the shared device. What I observed from this as well, is that it is still protecting credentials with certificates.
So again, we're not throwing passwords around, we're doing it the right way. And what we're doing is making sure those certificates are controlled by this face authentication, and this, say, deepfake evasion, or avoidance of deepfakes, which is a good way to go.
Sorry, go on. Yeah, sorry, I should say, well, so the nice thing is, is this increases the security, as you say, but it also reduces any friction, I don't need to remember my username, I don't need to remember any passwords, I don't need to have any other device, it's just working on the device that I'm using.
And, and that's unusual, right, it's unusual that you get a step up in security and a step up in in user experience. So, but that's what we have here, which is great. Cool.
So, and as you can see, it started to be late at night, my choice in photographs became somewhat erratic, but there we go. And use case four, and we all know it, we all hate it, and the help desk. And I suspect that I've been kind here, I think the help desk was for a very long time, the softest perimeter, just we're now all very painfully aware of it.
NGM, I've talked about already on this, on this webinar, $100 million loss from a 10 minute call. That's a lot. Caesars Entertainment, and I'm sure many of us have stayed in Caesars Palace, a similar vishing attack.
Clorox, maker of, you know, cleaning products for both home and industry, but again, a help desk where we gave attackers access, who cares? Well, logistic people care. These materials are actually very dangerous when put in the wrong hands, very dangerous when they are, when the chemical composition is tampered with. And of course, we know this APT group, Scattered Spider, they specialize in this area. We know that deepfake voice matched employees in seconds. Those phone calls you get where they, you know, is that, is that Peter James?
Yes, because they captured enough of the voice to create the deepfake. No callbacks, no secondary verification.
And, oh, hey, yeah, I forgot my phone. Or yeah, I went to the beach on the weekend. It was lovely. I went swimming my phone in my pocket or, you know, I was very tired when I came back from a trip and I put my phone in the wash with my trousers. That defeats every FIDO key. Why? Because the help desk got trained to be obliging, helpful and facilitate access. And so they override any FIDO keys. The human on the other end becomes a control and the human can be impersonated. So the gap, you know, the help desk asked to reset the MFA in seconds. There's a sense of urgency.
Hey, I really need this. I've got to get access to this meeting. I've got to get access to my records. I've got to be able to sign up this customer. We're going to lose this customer. And of course, what do we use? Knowledge-based verification. And I said this for so long, but it's a joke. Danger is my mother's middle maiden name.
And I, when I did presentations, I said to the audience of 2000 people, I'm going to turn you all into identity thieves. I'm going to do this to you now on the webinar. You can look at my Facebook account and you can look down the list of my Facebook friends and you can look to the one that is Eleanor Kerr. That's my mother. Yes. You then look on her account and it says her maiden name is Wiltz. There you go. You are now all identity thieves. It's that simple. Voice and video is faked in real time. So we have this terrible trifecta building up.
We know now how to get past knowledge-based questions because it really is that simple for any knowledge-based question. Voice and video. Peter has demonstrated how easy it is to fake voice and video in real time. Attackers impersonate distressed employees. They call up.
It's not, oh yeah, everything's going great. It's like, I'm in trouble. I need this. If I don't get this done, I'm going to be fired. Creating urgency, creating time pressure, which then, as I say, the help desk tried to alleviate by being helpful, cooperative and facilitating access. What's the result? Social engineering bypasses every control and the golden key, the crown jewels is the reset of the MFA. Don't worry. I'll set up a new OAuth for you. And so that recovery becomes a single point of failure.
And in time-honored nature, Peter, why don't you talk us through a video that highlights this? Thank you. Yeah. So one of the big challenges here is that at this point, no credentials are valid. That's why you're doing an account recovery. And so we need something else that covers that. So we're going to go through the account recovery process. As you see, I'm doing this remotely through a website. I've clicked into the process. You'll recognize this process from earlier.
So I'm going back in and I'm doing that check again against my valid ID that I have, checking my email and phone number again. Because what we really want to make sure is that it's the right humans that we then give the credentials to. Because the absolute worst thing is that we give away valid credentials to a bad actor, because now they've got free reign access to our systems. So we just go through that same process as we went through at the beginning. You'll see a slightly different version of it now. So we're going to check.
We started on the web, but we're going to move over to my mobile phone now seamlessly, because I want to be able to scan an NFC chip on my passport. You have to do that from a phone, from an app. You can't do it just from your web. So just wanted to show that we can do this both ways.
But again, going back into that scanning process. We'll scan. We'll make sure, of course, it's not me this time doing the video. And now we've validated that it really is me passing it back to the desktop. Now the system now is now talking on the back end to enter in this case. It's reset my account and it's given me a temporary password. So I go back and put in my password. Now it's that standard process of putting the temporary password, create the new password, and my credentials are reset. I'm back into the system.
So again, really low friction, but really high security. And I think that's fascinating. I think we're still at the point, as you say, we can trust passport issuers, whether it be UK, USA, and so on. We can trust that they will do this, especially as you point out, we're no longer relying on OCR. Having said that, I did try and blank out the passport that was presented in that video. We're no longer relying on, say, any kind of camera comparison. We've got access to the NFC chip.
And because these are certificates issued, cryptography controlled issued certificates by the passport issuing agency, then we can put some trust in that. Of course, there is the global standard, which is for mobile travel documents. So where are we? We know that, and we all now know, that credentials verify what you have, not necessarily who you are, which is the zero trust problem in one line. But I think what we've seen is that we can extend the verification process to actually strongly bind the credentials to the identity.
And it's this piece of the digital persona, and what one of my former colleagues used to call the ugly bag full of mostly water sitting behind the keyboard or the phone. We can bind the human and the credential to get the digital persona together and bind it strongly.
So that, as you say, when you have a problem, you can actually go back to that loop, as Peter just showed us then. So Peter, we're certainly coming towards the end of this, and I think we've got some questions that I'm looking forward to answering. But tell us a little bit about this identity life cycle that iProve are offering to us. Thank you. So the way that we've looked at this problem is to try and consider the entire life cycle of the user.
What we want to do is use biometric credentials to secure each of those trust moments in that life cycle, and particularly focus on trust moments where there's a particular gap in security, where if you've got fake credentials, you can gain access to genuine credentials to then allow you to access the systems from the inside. And so we've looked at these five areas. There's actually a sixth one, which is when you leave. So there's the de-binding at the end. But what we thought about is like pre-join.
It's not well catered today, because most people don't think about that as being a problem area. But with deep fakes and remote interviews, that's growing significantly. So it's pre-join. Then the remote onboarding. So as you create your initial credentials, let's make sure it's the right human. Daily access, so shared devices. How do we make sure that the credentials aren't being shared, aren't being given away? Not necessarily for bad reasons, but bad actors get access to them because they're being so freely shared about. Step up privileged access. We mentioned that a bit earlier.
We didn't have the demonstration for that. But you can use this in exactly the same way in those systems.
And then, of course, account recovery and rebinding. The real weak point in many systems today, because that's the point where you've lost all credentials. Right. Thank you. And clearly, what can I say? Too much Portuguese sunshine.
Obviously, I put the wrong or didn't manage to gather that shared access video. And so we are here. I think we're at a crossing point here. And the problem is now extant. It is real. And we have produced some research here, which if you are a company called member, you are welcome to download and read. And we're going to be producing more research in this area, because, as you say, this is a problem that needs fresh eyes and fresh attention. And at Kup & Nicole, we do analyze trends, markets, and software solutions like iProof. And our research assesses current topics.
It allows us to compare software products and products ratings. We provide research papers, blogs, videos such as this one, podcasts, and master classes. Our events and webinars include online and on-site, where we have expert talks, panels, and technical exhibitions. We provide topical webinars such as this one, and networking events with industry experts. Our advisory team support IT professionals in decision-making processes. And we evaluate and measure the maturity of IT infrastructure. I should say, I think I may be lucky enough to see you in person, Peter, at EIC in Berlin in June.
Sorry, in May. Beg your pardon.
In Berlin, Germany. That's our European Identity and Cloud Conference. If you scan the screen, you will get a ticket or go to the site where you can register for this event. And finally, I'd just like to give my thanks. It's been a pleasure to present this. Before I let you go, Peter, then, I think we're going to talk about some things. And for those of you on the webinar, I can see several discussions in the chat room, which I may shamelessly steal. But I've also got some questions of my own that my colleague Celina just put up.
So, an interesting one, Peter. Actually, let's discuss this.
Rob, thank you for sharing this. We nearly got caught with the deepfake candidate. We caught it with the reference check. The referee who I spoke to in person had never heard of the candidate. They never worked at his company.
Now, I'm just going to give my take on this. But that sounds like human intervention covering up the gaps in an automated process. That's a near miss. What do you think, Peter?
Yeah, I think you're right. I think it demonstrates that, you know, we shouldn't be relying on one way to check all of these things and have multiple processes, multiple checks in place to make sure that if you get through one, you'll get caught at another one, of course.
But say, what we've tried to focus on with ours is that you catch it at the earliest point, because if you catch it at the earliest point, you're wasting less effort. You're not allowing someone to get so much insight, so much access to your company and company details.
So, the safest route is to capture them early. And if you can get that at the interview stage, all the better.
So, I think that's interesting. Thank you for sharing that, Rob. A quick question for me, Peter. How big is this fake worker problem? It's surprisingly large. I think it's probably a lot bigger than people expect. I think it's a lot bigger than people are even reporting, because it's still going unnoticed.
So, Rob's example, obviously, he caught it there. But I'm sure there are a number of people out there who are not noticing this and are not capturing it. The hard data that we have, the stats that we have, are already scary enough. Reports show that 41% of enterprises have onboarded a fraudulent candidate at some point. That North Korean attack that you mentioned earlier, 300 plus companies, $17 million worth of fraudulent salaries being paid out. This is a significant challenge.
And as I say, the challenge with all of this stuff is that it's going to continue to get worse until we put in genuine checks to make sure that they get caught. Because the technology is getting cheaper, it's getting easier to access, it's getting more scalable to be able to do. And I think that's fascinating. One of the things, of course, I talked about in this webinar is how the North Korean problem, I called it. And I've just seen that my camera's gone off, so let me see if I can fix that. North Korean problem. From what you showed us, this is not a high-tech crime.
It uses technology, but as you said, this is available to anybody with a run-of-the-mill laptop and a modicum of technical knowledge. So it's not just state-sponsored actors that we have to include in our threat group.
It can be, and because many people say, well, why do I have to worry about this? I'm just a small organization in a supply chain. Why would the North Koreans come after me? Setting aside, of course, anything like the challenges of the infiltration of supply chain, which is, I think, a discussion all in itself, and it doesn't have to be a state-sponsored action. It can be a criminal organization.
In fact, it can be a fairly small criminal organization. It doesn't have to be a serious and organized group. And are you seeing that in your sort of when you're doing research into threat actors? We're hearing about that, but we're also just hearing about just the challenge of doing remote interviews. Interviews are scary things, right? No one really likes an interview, so it could be as simple as I ask my brother or one of my friends who's more experienced in the job than I am to just represent me in the interview and allow me to get the job, but under false pretenses, right?
So what we want to do is we just want to make sure that the slate is clean for everybody, it's fair for everybody, and then whether it's someone who is, let's say, more innocently trying to subvert the process or it's a state-sponsored actor doing something in a much more scaled and meaningful way for much less innocent means, the problem is still the same. But with this, we have one solution that can capture all of those challenges.
That's important, and I think, yes, you make a good point that it's something that can affect or can be perpetrated by people early in their career, late in their career. The job market, as I see on LinkedIn, is incredibly tough right now for people at all levels.
So, yes, the temptation to get an edge, I can see it doesn't go away and is exacerbated by the situation we find ourselves in. I guess another question that was sent to me, which is, well, why can't you just use PASKIs for these use cases? I think I know the answer to this, but you're my resident expert, tell me. It's very kind of you.
Well, PASKIs, you know, they are an excellent tool, and they're excellent for as phishing resistance replacements to things like passwords, and they do solve credential attacks. We are not suggesting that you need to use biometrics in all cases to protect you from all attacks. Choose the right tool for the right job. But the thing that PASKIs can't protect you from is these types of impersonation attacks that we're talking about. The other challenge is, of course, in some of the situations that we've referenced here today, I've lost my device, I need to reset my account.
Well, the PASKI is bound to the device, so I don't actually have the PASKI available to be able to do the things that I need to be able to do. So how do you protect once you've lost your credentials? And that's where biometrics comes in, because you can't lose your face. I was thinking about this from a different angle as well, which, as you say, PASKIs are robust. We do place a lot of trust in them, and, you know, obviously it's a great innovation in convenience, but also in security.
So it's even worse if you issue your PASKIs to an impersonator, because they've now got a robust and highly trusted way of getting into your systems that everybody believes in. And so I think, yeah, the PASKIs solve a subtly different problem here, and I think you're right. There are use cases for both, and you both should be part of your identity fabric. So we talked a lot about the hiring process, and you mentioned something which I want to bring back. You talked about the point-in-time checks at hiring, and that was a great demonstration of, you know, with Abby for, you know, realness.
You touched on ongoing verification later in the worker cycle, so I talked about possibly as part of a step up. Do you see organisations joining up the point-in-time checks at hiring with, you know, reinforcing that further down the worker lifecycle? That's certainly the intention of the platform that we're offering, in that you say we can create that single biometric that's been validated against, you know, a strong identity document.
And because our system specialises in biometric checks, we can integrate that in them with the existing stack that an organisation and enterprise already has, to be able to then feature at those trust moments that are really important, but just be able to call out and make another check on that biometric.
So trying to ensure that from a user point of view, you have a single interface for doing these sorts of high-security checks, so there's a consistency and a recognition from you about what I need to do, so the friction goes down each time it's done, because you're getting more familiar with the check, but that you can use it in one place initially, and then you can extend it out as you please, and as you see fit within your organisation. That makes sense.
So as you say, there's places you can do this, you can make this part of a regular identity health check, you could wire it into the step-up process, you could wire it into the validation of sensitive transactions, and there are a number of different ways you can do this without it necessarily being onerous in any way. So I think there will be organisations that have seen this that go, yes, we need to close the zero trust gap, but we don't want to add friction. It's as true in the workforce IM as it is in consumer IM.
At the beginning of the relationship is the point where we least want to add friction, we least want to be demanding lots of additional information because it feels very intrusive, and I think if we have those tenets in mind, what's the best place to start, and what trade-offs is the organisation or the architects, what are they going to expect? So I think the right place to start is where you as your organisation feel that you've got the biggest exposure.
So for many organisations, this will likely be the account recovery step because that's where you've got high volume, high risk exposure point, and we know that this is an area that is actively exploited. So you could introduce it in there.
Again, I think from a Again, I think from a user point of view, people know that this is a high risk point, that they know that they have lost their credentials and somehow need to prove that they are genuinely who they say they are. So from a point of view of friction of adoption, that's probably a good place to start, and it's covering you for probably the most risky area that you've got.
Having said that, though, that does mean, because you'll have that process in place already, this does mean introducing a new process to something that already exists, integration with systems that already exist. Probably the easiest place to add it, and one that then adds an awful lot of value further downstream, because you're stopping it much earlier, is to start doing it at the point of interview.
Because at the point of interview, we just need to integrate with whatever video conferencing system it is that you're using, the data is presented right there, and then you stop the bad actors coming in the front door. Hopefully then that means that you then don't have people trying to, or as many people, trying to break the system further down.
So again, it comes down to what's the biggest problem for you, but also what's your biggest challenge in terms of adopting new technologies and new processes. Interesting. I think we are, I mean, we're in the last few minutes, and we are, you know, coming to the end of what I think has been a really, for me, has been a very educational webinar. What's the one thing people should take away? If I forget everything else, what's the one thing people should remember? I think it's, as we were saying before, there are lots of systems today for protecting credentials.
Credential protection is incredibly important, but all you're doing is protecting the credentials. The credentials don't prove that the person who is behind those credentials is the person you expect it to be. And that's what biometrics is here to satisfy, that we know that you've got a genuine human that is who they say they are, that they are really there, and that they're a live person. And that's the missing gap, and that's the gap that I prove aims to fill. I think that's really valuable.
And, I mean, for me, the thing that I find myself pondering on is we've seen some fairly shocking statistics. If my time in cyber security has taught me anything, that is, you know, the tip of the iceberg. There's an awful lot that has gone undiscovered and unreported.
So, for those of you thinking, hey, well, that wouldn't happen to me, well, look at the unfortunate case of Jaguar Land Rover. Look at the unfortunate cases in pharmaceuticals, where they've had, yes, infiltration, and they didn't even realize until they saw their research data being published elsewhere.
So, this problem, I think, is, it is overdue our engineering solutions. And it's, and it is, it is very important to say, if you cannot trust the credentials on which you're basing your verification, then you have, yeah, a zero trust gap, to put it mildly.
And so, Peter, I guess, finally, yeah, what's your favorite movie? Oh, I was not expecting that question. Are you checking me for knowledge-based questions? Is this your? It does raise a point, actually. These are the type of knowledge-based questions that are out there. We joke about danger is my mother's maiden name.
But, yeah, what's your favorite movie? I've seen that in knowledge-based questions from knowledge-based question questionnaires.
And, you know, the school I went to, the university I went to, I think it's all on LinkedIn. The street I grew up on, well, that's in a database somewhere, I'm sure. It's not hard to find this information out if you are a determined and resourced attacker.
But, yeah, I'm just generally curious, actually. I'm wondering if you're going to say something insectional. It would definitely be a sci-fi movie. And I think I have a particular penchant for bad, old sci-fi movies. So I would go with Forbidden Planet. Excellent.
Well, Forbidden Planet, yes. And again, yeah, very, yeah, very apposite to this because, again, the threat that they believed they were fighting was not the threat they were actually fighting. And so on that note, Peter, thank you so much for your time. I've really enjoyed talking with you. And as I say, I'm looking forward to seeing you at EIC. And hopefully, I'll see many of our attendee to the webinar today will also join us in Berlin on the 19th of May this year.
With that, I've been, again, thank you for your time, Peter. I've been Jonathan Kerr for Cupping Your Cold. Thank you very much.
See All Locations
See All Locations