Identity economics

The expensive part is not the login. It is the unauthorized action after it.

Weak, phishable, or poorly configured authentication can expose payments, administrative changes, sensitive data, and machine-operated workflows to loss.

FBI / 2024 complaints859,532

Reported internet-crime complaints received by the FBI.

FBI / 2024 losses$16.6B+

Reported losses across internet-crime categories, up 33% from 2023.

FBI / BEC exposure$55B

Global exposed losses reported for business email compromise, October 2013–December 2023.

Sources: FBI annual report release ↗ and FBI IC3 BEC alert I-091124-PSA (Sept. 11, 2024) ↗. These totals span many crime types and should not be represented as losses caused by MFA alone.

Where weak MFA breaks

More factors do not automatically mean stronger authority.

Manual one-time codes can still be phished. Configuration gaps can bypass otherwise capable controls. Stronger systems bind the authenticator, the request, and the relying party cryptographically.

Reusable or relayed proof

Password + code

  • User can be tricked into relaying the proof
  • Request details may not be bound to approval
  • Shared secrets create attractive targets
→
Cryptographically bound proof

Device key + signed request

  • Origin and verifier can be bound to the ceremony
  • Approval can include action, scope, and expiry
  • The server verifies proof instead of receiving a reusable secret

NIST states that phishing resistance requires cryptographic authentication and does not treat manual-entry OTP methods as phishing-resistant. See NIST SP 800-63B guidance ↗.

Move from account access to action authority

Protect the moment value changes hands.