Security1 distinct publisher3 min readPublished
A July 2026 joint alert on North Korean IT workers and the 2025 M&S breach sit at opposite ends of the identity lifecycle: hiring and recovery. Neither required breaking authentication.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The awkward part of the recovery problem is that a support agent is being asked to do identity forensics with the tools of a call centre. The checks that remain common, according to the same write-up, are an employee ID, a phone number, or the name of a first pet [9]. Every one of those exists in writing somewhere an attacker can reach through breach data or social media [10]. None of them establishes that the voice on the line belongs to the person named in the record.
The joint alert describes the enrollment version of the same failure, and the mechanism is worth reading closely. It is not simply a stolen passport being replayed. Images are supplied by a third party based in another country to register the accounts, and the North Korean worker then performs the job [4]. The identity presented at the gate is partly real. The person who ends up holding the access is not the person who passed the check.
That distinction matters because of what the article recommends. Its remedy pairs government document scanning with biometric liveness detection, which by its own description confirms that a real, present person is completing the process rather than a static image or replayed evidence [12]. A cooperating accomplice in front of a camera is real and present. Liveness answers whether a live human completed the enrollment; it does not answer whether that human will be the one doing the work afterwards. The control offered is aimed at the narrower attack, and the article also carries a product pitch and a free trial for the vendor's password tooling, which is worth knowing before treating it as a threat assessment [13].
The numbers underneath are less flattering to authentication than they first look. The source cites Verizon's breach report finding stolen credentials involved in 44.7% of breaches [8]. Read the other way, 55.3% of breaches involve no stolen credential at all [14], and the process paths sit in that majority: the new joiner, the lost account, the factor reset, the sensitive change made on request [2].
Price the two ends against each other. The recovery call is cheap to attempt and Scattered Spider is described as proficient at exactly that, impersonating employees to get passwords reset [6]. The tactic was linked to the 2025 M&S ransomware breach, which contributed to an estimated $400 million hit to operating profit through lost sales [7]. The mitigation, whatever form it takes, is measured in minutes of agent time and caller friction.
The structural asymmetry is the thing to take away. Authentication is re-checked at every login. Identity is checked once, at hire, and then only under pressure, when someone is locked out and wants it fixed now. Both of the moments in this material are moments when the record is being written rather than read, and the technology companies the alert names as typical targets [5] are the ones most likely to have automated the reading and left the writing to people [3].
Ranked by verification strength, evidence, and original report placement.
Verizon's Data Breach Investigation Report found stolen credentials are involved in 44.7% of breaches.
The article recommends Specops Verified ID, which combines government document scanning and validation with biometric liveness detection; document checks confirm the ID presented is legitimate and liveness detection verifies that a real, present person is completing the process rather than a static image or other replayed evidence.
Security teams have spent years hardening authentication, with MFA and conditional access now commonplace, but stronger authentication does not solve every identity problem.
Trust is established or re-established at several points in the identity lifecycle: when a new employee joins, when someone loses access, when a password or MFA factor needs resetting, and when the service desk is asked to make a sensitive account change.
In late July 2026 the US Department of State and allies including Japan, Canada and the UK issued a joint alert warning that North Korean IT workers were impersonating foreign nationals to secure employment.
Their tactics focus on falsifying identity documents, such as using images supplied by a third party based in another country to register accounts, after which the North Korean carries out the actual work.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Two checkable anchors inside a vendor-authored piece
The cluster has a single source, sponsored and written by the vendor it recommends. Two elements are externally anchorable: the dated multi-government joint alert on North Korean IT workers and an attributed Verizon DBIR statistic (though no edition or methodology is named). The rest -- the M&S causal link and $400M estimate, the AI-impersonation trend, the sector-targeting caveat, and the product's effectiveness -- rests on uncited assertion, with no independent testing, incident report or measurement supplied.
No adoption data supplied
The supplied material discloses no customers, deployments, seat counts, pricing or usage figures for Specops Verified ID, and no data on how widely document-plus-liveness verification is used at service desks. The one dated observation in this payload is a government threat advisory, which evidences attacker activity rather than adoption of the recommended control, so adoption cannot be scored.
Threat framing outruns the supplied proof
The framing -- attackers routing around MFA and a product that restores assurance -- is broader than what the single sponsored source proves. The vendor's own statistic implies most breaches involve no stolen credentials at all, the M&S causal chain and $400M figure are hedged and uncited, the AI-impersonation escalation is asserted without data, and no efficacy or adoption evidence supports the recommended control. The underlying operational point (onboarding and recovery are weakly verified) is real and modestly evidenced, which keeps the gap moderate rather than extreme.
Sponsored content authored by the recommended vendor
The article discloses that it is sponsored and written by Specops Software, the maker of the single product it recommends; it also embeds a free-trial promotion for the vendor's Active Directory password product and closes with a contact-the-vendor call to action. Threat selection, framing and the absence of alternative mitigations or competing approaches all align with the sponsor's commercial interest. Disclosure is present but placed at the foot of the piece.
Confident on incentives, weak on substance
Confidence in reading the incentive structure is high because sponsorship is explicitly disclosed and the promotional mechanics are visible in the text. Confidence in the substantive claims is low: one publisher, one sponsored source, no primary documents (the joint alert, the DBIR edition, any M&S disclosure) and no independent efficacy or adoption data, leaving several claims marked insufficient.
security
Certighost turns a domain user into a Domain Controller, and the patch is only step one1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
security
A staging password went into a Google Doc, and Google's autocomplete found it first1 distinct publisher
invest
Designation day: your cloud vendor now answers to three regulators, and you still answer for it1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026