Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

KBA and account takeover: what identity teams need to replace


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: Knowledge-based authentication now fails because breach-exposed personal data and generative AI remove the secrecy and recall gaps it depended on, according to Trusona. The real issue is that account recovery still assumes knowledge questions can distinguish humans from automated fraud, when those assumptions have already collapsed.

NHIMG editorial — based on content published by Trusona: Moving Beyond Knowledge-Based Authentication and protecting against account takeover in the age of generative AI

By the numbers:

Questions worth separating out

Q: How should security teams handle account recovery when knowledge-based verification is still in use?

A: Security teams should treat account recovery as a high-risk control path, not a low-friction backup.

Q: Why does KBA fail even when the answers are technically correct?

A: Because correctness is no longer the same as assurance.

Q: What do security teams get wrong about customer account recovery?

A: They often treat recovery as a convenience feature instead of a high-risk control path.

Practitioner guidance

  • Retire KBA from high-risk recovery flows Remove security questions from password reset, account recovery, and any request that can change payment details, MFA state, or contact information.
  • Classify account recovery as privileged access Treat help-desk recovery steps as a privileged workflow with stronger review, logging, and escalation than ordinary support tickets.
  • Use authoritative evidence instead of memory questions Verify the caller against government-issued identity evidence, carrier signals, device intelligence, or other authoritative sources that the caller does not control.

What's in the full article

Trusona's full blog covers the operational detail this post intentionally leaves for the source:

  • Side-by-side explanation of static KBA, dynamic KBA, and why each fails under modern identity fraud
  • Implementation detail for ATO Protect, including document verification, device intelligence, and SIM-swap checks
  • Recovery workflow examples showing how step-up verification is applied to password resets and high-risk changes
  • Passkey enrolment guidance after successful recovery verification

👉 Read Trusona's analysis of why knowledge-based authentication no longer protects account recovery →

KBA and account takeover: what identity teams need to replace?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

KBA is a retired trust model, not a weakened one. Knowledge questions depended on two assumptions: that the answer stayed secret and that humans could not retrieve it instantly under pressure. Breach data destroyed the first assumption, and generative AI destroyed the second. Practitioners should stop treating KBA as a control that can be tuned and recognise it as a legacy pattern that no longer produces meaningful assurance.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: Who is accountable when a KBA-based recovery process is abused?

A: Accountability sits with the identity owner, the support operation, and the control owner for the recovery workflow. Frameworks such as NIST SP 800-63 no longer treat knowledge questions as acceptable secrets, so organisations that keep relying on them should expect audit scrutiny over why a deprecated assurance method remains in production.

👉 Read our full editorial: Knowledge-based authentication fails under generative AI account takeover



   
ReplyQuote
Share: