Hackers Don’t Break In; They Log In

By Aaron Painter, CEO | Nametag [ Join Cybersecurity Insiders ]
14

Most people think of security concerns in terms of hacking. In the case of deepfakes, however, no hacking may be required. The holes in our security networks often lie in our humanity: the judgment calls made by customer service or human resources staff. To defend against AI-enabled impersonation, organizations must stop trusting what merely looks or sounds right and start requiring proof.

Helping others makes us feel good, and we are hardwired to prefer trust over mistrust. When someone tells us who they are, we want to believe them. Attackers understand this. They often come armed with a plausible story of difficulty and frustration, such as being locked out of a car with a crying child or needing to authorize payroll after a reorganization. We all know how it feels to have one of those days when everything goes wrong, so these stories spark empathy in helpdesk operators who are trained to support callers, not interrogate them.

In these situations, no agent wants to make someone’s day worse. Agents are paid to solve problems, and their performance may be graded by tickets closed, call length, or customer feedback. Even if they feel uneasy, they rarely have the time or authority to launch an investigation. Like a vampire at the threshold, attackers persuade the people tasked with gatekeeping that they are harmless and reveal their true nature only when it is too late.

Most troubling of all, agents’ systems often rely on familiarity, memory, and subjective judgment rather than proof. These factors work in the attacker’s favor.

Recognition Is No Longer Enough

When you call a helpdesk, you will be asked to verify your identity. Yet many of the methods companies use are not truly based on verification. They rely on recognition: correct answers to security questions, a correlation between a phone number on file and the number someone is calling from, or simply a story that makes sense. Recognition relies on belief. Until a few years ago, that worked most of the time. Now it is no longer enough.

As one director of security told me, “We trained our agents to follow protocol, but when a caller sounds stressed and important, they bend, because that’s what humans do.” Attackers seeking to steal identities frequently sound nice and polite. A call that results in a data breach may end with the caller saying, “Thanks so much for helping me out. Have a great day.” That very niceness can cause an operator to drop their guard.

When I lived in Brazil, crime rates were high and several friends had their cars stolen. What stood out was how friendly the thieves often seemed. They maintained a calm demeanor because they did not want the person they were robbing to panic. A similar principle applies to identity impersonation. The more normal and mundane the call, the less likely an operator is to escalate or deny the request. Many agents do not realize they have been tricked until an investigation begins.

The term cybersecurity is becoming outdated because it does not capture the full risk of an era in which hackers do not break in; they log in. Impersonation attacks exploit vulnerabilities in human psychology, even if the attack unfolds in a digital environment. The threat landscape has shifted radically, but much of our thinking has not.

Privilege Proof Over Performance

The principle that should define our response is simple: trust proof over performance. Performance looks and sounds right, but advances in AI have made it nearly impossible to know whether that performance is genuine. Proof is something that can be cryptographically, physically, or behaviorally verified in the moment and can stand up to scrutiny.

Organizations should shrink the window in which bad actors can succeed through performance alone and require proof that is straightforward for a legitimate account holder to provide but difficult for an impersonator. Technological solutions already exist. We must move from recognizing familiar signals to verifying that a signal is alive, present, and bound to a real identity at that moment.

Layered defenses can make this stronger by forcing attackers to defeat multiple independent proof points under tight time constraints. One straightforward tactic is moving verification to an additional channel. If someone calls a helpdesk, for example, the account holder might receive a confirmation through a previously verified channel. It is harder for an attacker to control multiple channels without alerting the real user or triggering a security warning. Another approach is agreeing on a private phrase that is never used online. It takes preparation, but it can keep an alarming situation from escalating.

Making the Secure Thing the Easy Thing

Security controls often fail because they make life harder for the intended user without increasing the difficulty enough for attackers. We need to reverse that equation. The advanced technology can operate behind the scenes, while verification remains straightforward for the person seeking help.

Reliable verification also removes much of the social engineering element and takes pressure off helpdesk agents. They no longer need to rely on personal judgment in emotionally charged situations or worry that following protocol will produce negative feedback. They can simply say, “I’d love to help you. I just need you to verify yourself.” When the required proof is clear and easy for a legitimate user to provide, there is less room for negotiation, maneuvering, or exceptionalism.

Technical controls alone are not enough. Organizations must also build awareness and a culture in which asking for and providing proof is expected. Detection will always lag behind generation, so prevention matters. That means privileging secure channels while continually testing systems and anticipating threats.

The goal is not to catch every hacker. It is to make impersonation costly, difficult, and hard to scale. Until we move from trusting what looks right to trusting evidence, attackers will continue to exploit the most human parts of our security systems.

_____

About Aaron Painter

 Aaron Painter is the CEO of Nametag, the identity verification company helping organizations restore trust in an era of AI-generated impersonation.  Aaron has spent his career helping people earn trust in a world transformed by technology. That journey has taken him across six countries and four continents.  He is the author of “Deepfaked: Restoring Trust in the Age of AI Impersonation” https://aaronpainter.com/

 

Join our LinkedIn group Information Security Community!

No posts to display