Account takeover (ATO) attacks are shifting from credential stuffing to targeting identity verification and recovery layers as passkeys become mainstream. According to the FIDO Alliance, 75% of global consumers have enabled a passkey on at least one account, and 68% of companies are using or testing passkeys for employee sign-ins. This has forced attackers to focus on weaker links such as magic-link interception, account recovery, and step-up verification. Veriff’s Fraud Industry Pulse Survey 2026 reports a broad rise in online fraud, with impersonation fraud, malware, authorized fraud, and document fraud among the most common categories. Generative AI has made impersonation cheap and convincing; Veriff’s Identity Fraud Report 2026 found that 4.18% of verification attempts were fraudulent, and digitally presented media was 300% more likely to be AI-generated or altered. Impersonation now accounts for over 85% of all fraud attacks observed by Veriff. The article outlines three key shifts for ATO defense over the next 12-18 months: intent binding to cryptographically link verified actions to specific transactions, network-effect data to detect fraud patterns across millions of sessions, and regulatory pressure from frameworks like eIDAS 2.0, the Anti-Money Laundering Regulation, and DORA. Practical recommendations include making passwordless authentication and biometric liveness detection baseline requirements, treating re-verification and magic-link flows as high-stakes events, applying risk-based reverification, and planning for AI-resistant verification. The article was contributed by Anton Volkov, Senior Product Manager at Veriff.
CVEs: CVE-2026-55200, CVE-2026-46817
Companies: FIDO Alliance, Veriff
Original source: thehackernews.com