Password resets authenticate a story, not a person.
The attack moved to the recovery path
Attackers stopped fighting strong authentication head on. As each credential control hardened, the working attack moved to the paths that restore access when authentication fails: recovery, resets, and the support call. Under every rung of that ladder sits the same fallback, a human being deciding whether to let someone back in.
Two public incidents bracket the trend. One phone call to an IT helpdesk preceded an approximately $100M hit at MGM Resorts in 2023. One deepfaked video call moved about US$25M out of the engineering firm Arup in 2024. No cryptography was broken in either chain.
What the paper establishes
The failure is structural, not a training gap. Everything a helpdesk agent is able to check is a fact that some breach has already leaked, and generative voice and video now let a caller look and sound like the person on the account. More training buys you a slower agent, not a harder one to fool.
So the paper does not argue for a better interview. It argues that the agent's confidence is the wrong control to improve, and that it should stop being the control at all.
- The escalation ladder, control by control, and why each hardening step created the next soft target
- Why an agent's judgment is recruited rather than defeated, and why callbacks and supervisor escalation restate the problem
- How a backchannel (CIBA) verification puts a cryptographic check of the live person inside the call
- The design detail that keeps what the caller approves identical to what the agent requested
- How a caller with no app yet is brought into the same ceremony mid-call
- Three concrete changes for the fraud team, including what a disputed action looks like afterward
Who it is for
Fraud teams, contact-center owners, and the security leads who inherit the recovery flow. If your strongest authentication has a helpdesk sitting behind it, this is the paper about the part of the estate that actually gets attacked.
What it does not offer is a way around enrollment. The check works because the caller's own device is already bound to them, so a caller with nothing bound is a different problem. The paper covers that case mid-call rather than pretending it does not arise.
Frequently asked questions
How is this different from voice biometrics on the call?
Voice verification happens inside the channel the attacker already controls, and generative voice defeats it there. The check described in the paper leaves the call and returns over cryptography the caller cannot touch. The paper explains why that distinction is the whole argument.
Does this only cover password resets?
No. The same verification gates whatever the organization decides deserves it: re-binding a phone number, raising a transfer limit, adding a payee, or authorizing any change the caller requested. Wherever the current control is an agent's confidence, the replacement is identical.
How long is it?
Seven pages, with two diagrams and cited incident figures from company disclosures and contemporaneous reporting.
Related reading






