01
Attackers increasingly target account recovery
Nobody attacks the strong path when a weaker one reaches the same account. Every hardening step of the last decade pushed effort somewhere else, and the destination it kept arriving at was the set of flows that exist to restore access after authentication has already failed. Security questions went first, once breaches and social media turned private answers into lookups. One-time codes moved the problem onto a phone number, and numbers turn out to be transferable. Push approval moved it onto a tap and met fatigue. The current rung is the session itself, relayed whole by adversary-in-the-middle kits, which is the category the Microsoft Digital Defense Report measured growing 146 percent year over year in 2024.
Under every rung is the same fallback. When someone cannot get in, a person on a support line decides whether to let them, working from a script, whatever the account record shows, and an instinct to be helpful. That fallback is now attacked deliberately rather than opportunistically. In 2023, attackers impersonated an employee to the MGM Resorts IT helpdesk by telephone, and the company reported an about $100M impact. No cryptography failed anywhere in that chain.
Then came the escalation that recognition cannot survive. In February 2024, a finance employee at the engineering firm Arup joined a video call with what appeared to be colleagues, including the chief financial officer, and authorized transfers of about US$25M on their instruction. Every face and voice on that call was synthetic. Once a caller can present the right face and the right voice on demand, recognition stops being weak evidence and stops being evidence.
Recovery questions can rely on exposed information
The account record offers an employee number, a maiden name, the branch that opened the account, the value of the last transaction. None of those changes, and things that never change eventually circulate. Verizon's 2026 Data Breach Investigations Report found credentials in 28 percent of breaches, and the same dumps carry the personal detail a recovery interview runs on.
Attackers exploit the support agent's role
Support staff are hired for empathy and scored on how quickly a call ends, and a prepared caller uses both properties at once. One side improvises cold inside a handle-time target; the other rehearsed the script and chose the hour.
Escalation can repeat the same weak checks
A callback trusts the number in the record, which the same caller may have changed an hour earlier. A supervisor brings a second opinion to an identical file. Neither alters what is actually happening, which is an account being edited because a story was convincing.
02
What the paper argues
Since the failure is built into the shape of the flow, the remedy on offer is not a sharper script or a longer interview. Making an agent feel more confident is the wrong project. The position taken here is that agent confidence should stop functioning as a control at all, replaced by a question no rehearsed story can answer.
That question is one the caller's own phone can answer while the call is still in progress. SenseCrypt exposes it as a backchannel verification built on FAPI-CIBA / CIBA, the OpenID standard written for flows that begin on one channel and finish on another. The check consults the person rather than the record, so nothing is read out of the account notes and nothing is asked of the caller.
The paper is careful about why the direction of the check matters. Anything verified inside the call is verified over a channel the caller controls, which is exactly why synthetic audio defeats voice matching where voice matching is deployed. A check that leaves the call, completes on hardware the caller cannot influence, and returns as a signature does not inherit the compromise of the conversation.
- Each control on the escalation ladder and the attack that retired it, ending at the fallback everything else rests on
- What the FAPI-CIBA / CIBA exchange looks like from the agent's side, from one click to a result on screen, and how long it takes
- Why the description of the action being approved travels only inside the signed payload, and what that prevents
- The route for a caller who has never set up the app, and why the mailbox in that route is a bootstrap rather than a substitute
- What deprovisioning does to a departing employee's ability to pass the check, and at what moment it binds
- Three things a fraud team should expect to change, among them how a disputed action reads once an investigation opens
03
Who this paper is for
Fraud teams, the people who own a contact center, and whoever ended up holding recovery once the authentication program was signed off. The premise is uncomfortable and worth sitting with: the strongest control in the estate is not the one an attacker will choose to meet.
It is also written for the people who have to explain an incident afterward. Every verification, passed or failed, lands in a read-only person-level activity stream that investigators can export to CSV, which turns a reset from a line in a ticketing system into a record of which identity was checked, with what outcome, and when.
04
How to test it on a real call
Seven pages and two diagrams, with incident figures taken from what the companies themselves disclosed and from reporting at the time rather than from vendor modeling. The section on what changes for the fraud team is the one to take into an operations review.
The gated download sits on sensecrypt.com, and a copy of the PDF is available on request. The more useful next step is a live walkthrough: trigger a check against a test identity, watch it complete on a phone in the room, and see what reaches the agent's screen when it fails.
05
Frequently asked questions
How is this different from voice biometrics on the call?
Voice matching is evaluated over the audio an attacker is generating, so the better the generator, the better it scores. The check in this paper never touches the audio. It goes out to the caller's enrolled phone, requires a live face there, and returns a device-signed result to the agent's screen.
Does this only apply to password resets?
No. Anything the organization decides warrants it can sit behind the same check: rebinding a phone number, lifting a transfer limit, registering a new payee, signing off whatever change the caller has asked for. The rule is short. Where an agent's judgment is currently the control, this is what takes its place.
What if the caller has not set up the companion app yet?
They can be brought into the same ceremony during the call. The challenge arrives as a code in the mailbox on record, which adds possession of that mailbox to the proof, and once the app is installed on the caller's phone the verification finishes as the same face ceremony. The mailbox gets the caller to the ceremony; it does not stand in for it.
What does the agent see of the caller's face?
Nothing. The check runs on the caller's own enrolled phone and what returns to the console is a signed outcome: approved, declined, or expired. No image, no template and no score crosses onto the agent's screen, which also means an agent cannot be talked into overriding a face they were never shown.