Why account recovery is now the weakest link in security
The call came in on a Tuesday morning. A senior finance executive at a large enterprise couldn't access her account. She'd been locked out after a routine system update, and she needed in fast. Payroll was running that afternoon.
The helpdesk agent, under pressure and working through a queue of tickets, asked a few verification questions. Confirmed her name. Her department. Her manager's name. All information that, as it turned out, was readily available on the company's own LinkedIn page.
Within twenty minutes, her account was reset, her MFA methods cleared and re-registered under the attacker's control, and access was restored, effectively bypassing the very controls the organization had spent years putting in place.
The only problem? It wasn't her.
By the time anyone realized what had happened, the attacker had spent three weeks inside the company's financial systems, had rerouted two vendor payments, and had moved on.
The breach...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE