Proof Puts Itself To The Test For Account Recovery
Proof's IT team identified a critical security flaw in their password reset process via Slack, and addressed it by integrating identity verification through Okta and SMS/email links into account recovery and device enrollment flows, ensuring employees must verify their identity before resets or provisioning, thereby significantly reducing the risk of unauthorized access.
IT teams live at the intersection of access and urgency. When an employee is locked out, the pressure is to get them back in fast, and the path of least resistance has always been a direct message. For Proof's IT team, that path turned out to have a significant flaw.
The security hole hidden in plain sight
The old process was familiar to anyone who has worked in IT: an employee locked out of their machine would post in the IT Slack channel requesting a password reset, and the team would help. Fast, easy, and almost entirely unverifiable. As Felicia Carnell, Director of Information Technology, put it: "In today's world of malicious actors, how do you know that the person on the other end of that is that person? That could be somebody who just has their phone that's logged into Slack."
A misplaced device, a distracted moment, or a bad actor with access to someone's Slack account was all it would take to trigger a credential reset for an account they had no right to access.
What looked like routine IT support was actually a low-cost attack surface.
Replacing the channel with verified identity
Proof's IT team changed the model. They integrated Identify directly into the account recovery flow via Okta, so any employee locked out of their machine, or receiving a replacement device, goes through identity verification before anything is reset or provisioned. The process checks the employee's identity against their existing Okta profile attributes, sends a secure verification link via SMS or their personal email, and completes in under two minutes.
If someone cannot pass IDV, the request routes to a trusted referee.
Then the team took it further, in partnership with the security team. Together, they built what they now call inline IDV, embedding identity verification directly into the device enrollment flow. When a new hire logs in for the first time, or when a replacement machine ships out, the enrollment screen prompts identity verification before the process can proceed. It reads like a natural extension of onboarding rather than a security checkpoint dropped on top of it.
Employees, including Proof's summer interns whose college addresses sometimes differ from what is on their government IDs, moved through it without friction. Felicia and the team braced for edge cases with the interns. There were none.
The ROI is the breach that doesn't happen
Felicia lived through a breach at a previous company, so her case for the ROI is blunt: "If that person was not who they said they were, the cost of a breach, the cost of something happening and the data loss that could happen, if you think of it in that regard, then it's a huge timesaver."
The scenario she is describing does not require a sophisticated attack. "Even something as small as impersonating someone on Slack to get their laptop password changed, it can cost a company everything: dollars, manpower, all sorts of things."
According to IBM's 2025 Cost of a Data Breach Report, the average breach costs $4.44 million globally and $10.22 million in the United States. Two minutes of identity verification looks very different against that number.
What Felicia wants other IT leaders to take from it is simpler than a product pitch. Account recovery is a moment of high trust and low verification, and most teams have not reckoned with that yet. As she puts it: "If not now, then when a breach does happen, they'll realize they need this, and it’s something they should get ahead of."
The question is whether you build that foundation before the incident or after it.
Most IT help desks still run on good faith at account recovery. That is exactly what makes them a target.
Related
Introducing Persistent Identity: The Foundation of Repeatable Trust
Persistent Identity is a secure digital ID system that enables individuals to verify their identity once to a high-assurance standard, store it on the Proof platform, and reuse it across multiple online transactions and organizations via the Identity Authorization Network, thereby reducing inefficiency, abandonment rates, and trust erosion caused by repeated identity verifications in an increasingly digital and threat-prone environment.
The Hidden Threat in Your Hiring Process: Why Traditional Background Checks Are No Longer Enough
The article highlights that traditional background checks and ATS platforms are increasingly ineffective against sophisticated hiring fraud, including AI-generated resumes and identity theft exploited by state-sponsored operatives, emphasizing the urgent need for biometric identity verification with liveness detection to secure the modern, automated hiring process.
Introducing Identify: Securing the Entire Customer Journey
Proof has launched Identify, a no-code, plug-and-play customer verification solution that integrates identity verification, fraud prevention, and evidence collection throughout the entire customer journey—addressing risks in industries like real estate, property management, and financial services by enabling businesses to verify identities early and continuously, capture sealed identity reports, and seamlessly combine with their Defend fraud detection technology for enhanced security without complex IT integration.
Multi-Signal Fraud Detection Benchmarks
Proof has developed a layered fraud detection model that combines passive signals, active checks, and collective telemetry from its Identity Authorization Network to outperform traditional passive-only methods by 600-1,300% in detecting sophisticated fraud without increasing user friction, addressing the shortcomings of standard approaches like MFA and KBA that are increasingly ineffective against targeted attacks.
Tackling Healthcare Fraud With Medical Licensing
Healthcare fraud, a costly industry-wide crisis driven by identity impersonation of doctors, patients, and insurers, can be effectively countered by strengthening identity verification during medical licensing through automated biometric and ID scanning technologies that provide licensing boards with verifiable digital identity reports and fraud-risk scoring.
Understanding Persistent Identity: How Trust Becomes Something You Can Reuse
The article explains how Proof's new persistent identity system enables a single, high-assurance verified identity to be securely saved and reused across multiple workflows on the platform, reducing repetitive verification steps for users, providing consistent identity signals for organizations, and streamlining operational processes by maintaining a durable, reusable trust rather than isolated, one-time identity checks.