Security Experts Urge FIDO2 Keys, Passphrases After $25 Million Deepfake Fraud
Updated
Updated · ZDNet · Aug 21
Security Experts Urge FIDO2 Keys, Passphrases After $25 Million Deepfake Fraud
3 articles · Updated · ZDNet · Aug 21
Summary
$25 million in fraudulent wire transfers at Arup has become a cautionary example for experts arguing that companies need low-tech checks such as hardware keys, verbal passphrases and out-of-band callbacks.
73% detection accuracy in one UCL study — improving just 3.84% with training — underscores why face and voice recognition no longer reliably authenticate callers, while later research found human detection closer to chance.
Experts say the bigger risk now extends beyond one-off scams to long-term infiltration, citing a 2024 KnowBe4 case in which a fake hire linked to North Korea received a company workstation before being caught uploading malware.
CISA-backed FIDO2 or PIV credentials, no-exception passphrase rules, dual authorization and role-based secret phrases are being recommended for high-risk workflows, with resets triggered by compromise or role changes rather than fixed 90-day cycles.