TrueID

Beyond the Login: Why Session Security Needs Continuous Identity Assurance and Defence in Depth 

Get An Enquiry

Get an Enquiry

Summary: Attackers bypassed passwords and MFA by hijacking authenticated session tokens through a fake Microsoft login page. The incident exposes a key weakness: systems verify users at login, but often fail to continuously verify who is using the session.


In September 2026, security researchers reported a phishing campaign aimed at directors and vice presidents at US companies in finance, healthcare, and real estate. Attackers phoned the executives posing as internal IT support and asked them to register a new passkey or MFA method on a website that looked like Microsoft’s sign-in page. 

That website was an attacker-controlled proxy sitting between each executive and the real Microsoft 365 service. When an executive entered their password and approved the MFA prompt, the proxy relayed both to Microsoft, which signed them in and issued an authenticated session token. 

This is the moment the session was taken over: the proxy copied that token as Microsoft sent it back. The attackers then replayed the token from their own machines, routed through IP addresses near each victim’s location, and downloaded corporate files from SharePoint, OneDrive, Exchange, and Box. 

The executives had followed every step of their security training. The attackers never needed to crack a password, because they took something more valuable: the authenticated session itself. 

This is the blind spot in most digital systems today. They verify identity once, at the start of the session, and then trust whoever holds that session until it ends. 

This article argues that point-in-time authentication can no longer protect a modern system on its own. Continuous identity assurance is now essential, but it only works as one layer of a defence-in-depth strategy that starts at onboarding and ends at every high-risk transaction. 

Specifically, we recommend three layers working together: biometric onboarding with liveness and deepfake detection to confirm a genuine identity, continuous in-session assurance using device binding, behavioural biometrics, and risk scoring, and biometric step-up checks that confirm intent before every high-risk transaction. 

To understand why all three layers are needed, it helps to start with where most organisations still invest their security budget today: the login screen. 

A stronger front door does not secure the house 

Most organisations respond to identity threats by hardening the login. They add a second factor, then a third, then move from SMS codes to authenticator apps and passkeys. 

Each upgrade makes the moment of entry harder to fake. None of them protects against what may follow in the session: a stolen session token, a device that changes hands, or a payment approved under false pretences. 

A session typically lasts minutes to hours, and in enterprise tools it can last days. Throughout that window, the system keeps granting access to data, approvals, and payments based on a single check made at the start. 

This design made sense when attackers targeted credentials. It fails when attackers target the session, because the session carries all the trust the login created, with none of the scrutiny. 

Attackers now steal the session, not just the password 

The evidence from the past year points in one direction. Attackers are no longer trying to defeat authentication; they are harvesting its output. 

The FBI’s Internet Crime Complaint Center (IC3) received more than 5,100 account takeover complaints, with losses exceeding $262 million, between January and November 2025. In its advisory, the FBI notes that criminals specifically target MFA codes and one-time passcodes, then move funds out quickly to accounts and crypto wallets they control. 

Three incidents from 2026 show how this plays out across sectors: 

  • Corporate cloud accounts: In the September 2026 campaign, attackers posed as IT support and routed executives through fake Microsoft 365 login pages. They captured authenticated session tokens and replayed them through proxies with IP addresses close to each victim’s location, so the logins looked local. 
  • Financial platforms: On 31 January 2026, attackers compromised devices belonging to Step Finance’s executive team and drained about $40 million from its treasury. The platform shut down within a month. 

In each case, the OTP arrived, the MFA prompt was approved, or the action came from a device the system already trusted. The failure came later: each system kept trusting the session without checking whether the real user was still the one using it. 

Continuous identity assurance closes the gap after login 

Continuous identity assurance replaces a single yes-or-no decision with an ongoing one. It keeps asking “Is this still you?” for as long as the session lasts. 

It does this by reading signals that a stolen token or OTP cannot fake: 

  • Device and session binding: It ties a session to the device and browser that created it, so a token replayed from another machine stands out. 
  • Behavioural biometrics: It learns how a user types, scrolls, and navigates, and flags a session when that rhythm changes. 
  • Context and risk signals: It watches for a recent SIM change, a new network, an unfamiliar payee, or a sudden bulk download. 
  • Step-up verification: When risk rises, it asks for a live biometric check with liveness detection, which a remote attacker cannot pass. 

Apply this to the 2026 incidents and the outcome changes. A replayed Microsoft 365 token shows up on the wrong device, and a bank transfer made soon after a SIM swap triggers a face check that only the real account holder can clear. 

This is why continuous assurance is necessary. It protects the part of the session that point-in-time authentication was never designed to see. 

Continuous assurance is necessary, but not sufficient 

Continuous assurance confirms that the session still belongs to the person who started it. It cannot confirm that the person was genuine to begin with, or that they are acting of their own free will. 

Three gaps remain: 

  • A compromised starting point: Continuous assurance compares every action against the profile created at onboarding. If a deepfake or synthetic identity passed that first check, the system will faithfully keep confirming the fraudster. 
  • Manipulated intent: When a real user, on their own device, is persuaded to approve a payment or sign a transaction, every behavioural signal looks normal. The system correctly confirms who the user is, but it cannot tell that a scammer is directing them. 
  • Trusted insiders: An employee who misuses their own access matches their own baseline. Slow, deliberate misuse can stay within normal patterns for a long time. 

These gaps explain why no single control can carry the load. The answer is to layer controls so that each one covers what the others miss. 

Defence in depth: three layers, three questions 

A resilient identity strategy verifies different things at different moments. Each layer answers one question and covers a gap the other two leave open. 

Strong onboarding establishes a genuine starting identity. Liveness detection and deepfake-resistant document checks confirm that a real, present person is enrolling, and every later check depends on this baseline. 

Continuous assurance protects the session. Device binding, behavioural signals, and contextual risk scoring confirm that the verified person is still in control, which stops token replay, SIM-swap takeovers, and mid-session handovers. 

Transaction-level intent checks protect the moments that matter most. Before a large transfer, a new payee, a treasury approval, or an admin change, the system asks for fresh biometric confirmation and shows the user exactly what they are approving. 

No layer is complete on its own. Together, they make an attacker defeat three independent controls instead of one. 

Why this is every software system’s problem 

Banking, insurance, and government services feel the losses first, but the exposure is universal. Any system that holds data, moves money, or grants access is a target. 

Two shifts make this urgent: 

  • Attacks are now AI-assisted. Attackers use AI to write convincing phishing, clone voices, generate deepfake faces, and mimic human behaviour at scale, so a one-time check can be rehearsed and bypassed. 
  • Systems are deeply connected. A single compromised session in a cloud workspace, a vendor portal, or an API can open doors across an entire supply chain. Attackers find and exploit these weak links faster than organisations can patch them. 

The result is a threat model in which the attack is continuous. The defence has to be continuous too. 

Choosing an identity partner is a strategic decision 

Identity has always been the foundation of security architecture, and its role now extends beyond the login to every action a user takes. The partner an organisation chooses determines how many of the three layers it can actually deploy. 

Four questions separate a capable partner from a login vendor: 

  1. Does it cover the full lifecycle? Look for onboarding, in-session assurance, and transaction-level verification from one platform, so signals flow between layers instead of sitting in silos. 
  1. Can its liveness detection resist AI-generated attacks? Ask how it detects deepfakes, replayed video, and injected camera feeds, not just printed photos and masks. 
  1. Does it adjust friction to risk? Strong assurance should stay invisible for routine actions and step up only when the risk score rises. 
  1. Does it fit the regulatory context? Check alignment with standards such as ISO 27001, PCI DSS, and GDPR, along with local data protection law such as India’s DPDP Act. 

Organisations that treat identity as a checkbox buy a login screen. Organisations that treat it as infrastructure buy resilience. 

Identity must be verified for the whole journey 

The argument comes down to five points: 

  • Point-in-time authentication verifies the moment, not the person. Once the login succeeds, most systems trust whoever holds the session. 
  • Attackers have shifted from credentials to sessions. The FBI recorded more than $262 million in account takeover losses between January and November 2025, and the 2026 incidents show token replay, SIM-swap OTP interception, and compromised devices doing the damage. 
  • Continuous identity assurance is essential. It keeps asking “Is this still you?” and catches what a single login check cannot see. 
  • It works best as one layer of three. Strong onboarding, continuous in-session assurance, and transaction-level intent checks together cover gaps that any one layer leaves open. 
  • This applies to every connected system. AI-assisted attacks and deeply linked platforms mean every organisation that grants access is a target. 

Continuous assurance and identity management matter more than the industry currently acknowledges. For organisations facing an increasingly hostile digital future, they are the most reliable defence available. 

How TrueID builds defence in depth 

TrueID delivers all three layers from a single biometric identity platform. Its face liveness detection verifies that a real, present person is enrolling during remote onboarding and KYC, confirms presence before high-value transactions, and supports continuous authentication for remote workforces. 

Its multi-factor authentication combines face, fingerprint, and iris biometrics with AI-powered risk assessment that analyses login behaviour, device trust, and geographic anomalies to adjust security in real time. With a ready-to-use SDK and alignment with PCI DSS, GDPR, and ISO 27001, TrueID helps banks, insurers, government services, and enterprises verify identity from the first sign-up to the last transaction. 

Talk to TrueID about building identity assurance that lasts the entire session. 

Sources 

Recent Blog

Beyond the Login: Why Session Security Needs Continuous Identity Assurance and Defence in Depth 

Beyond the Login: Why Session Security Needs Continuous Identity Assurance and Defence in Depth 

Summary: Attackers bypassed passwords and MFA by hijacking authenticated session tokens through a fake Microsoft login page. The incident…

Account Takeover Attacks Explained: How Modern Identity Platforms Prevent Them 

Account Takeover Attacks Explained: How Modern Identity Platforms Prevent Them 

Summary: Account takeover occurs when attackers use stolen credentials or AI tools to quietly hijack a legitimate account, locking…

How Digital Identity Can Accelerate Financial Inclusion Across Emerging Economies 

How Digital Identity Can Accelerate Financial Inclusion Across Emerging Economies 

Summary: Financial inclusion provides vulnerable households and small businesses with formal banking, credit, and insurance, acting as a crucial…