Account Recovery

Account recovery is an identity decision.

When someone loses access to their account, your help desk receives a call from a person claiming to be your customer or employee. That caller may know every answer on your recovery checklist.

Proof verifies who they actually are using government-issued identity verification and biometric confirmation before any access is restored.

The Problem

The infiltration playbook is fine tuned

MGM ResortsA 10-minute help desk call that cost the company $100M in Q3 losses.
Caesars EntertainmentThe same attacker group used the same playbook and reportedly received $15M to stop the damage.
OktaAttackers compromised a support engineer's credentials to access Okta's customer support system, exposing data from 134 organizations.
UberA contractor was social engineered via WhatsApp with MFA push fatigue, exposing Uber's internal systems and AWS environment.
TwilioSMS phishing compromised employee credentials and exposed customer data, with downstream impact on Authy and Signal users.
Twitter/XAttackers posed as IT staff over the phone and hijacked accounts belonging to Barack Obama, Joe Biden, and Elon Musk.
RobinhoodOne social engineering call to customer support exposed data for 5 million users.
MGM ResortsA 10-minute help desk call that cost the company $100M in Q3 losses.
Caesars EntertainmentThe same attacker group used the same playbook and reportedly received $15M to stop the damage.
OktaAttackers compromised a support engineer's credentials to access Okta's customer support system, exposing data from 134 organizations.
UberA contractor was social engineered via WhatsApp with MFA push fatigue, exposing Uber's internal systems and AWS environment.
TwilioSMS phishing compromised employee credentials and exposed customer data, with downstream impact on Authy and Signal users.
Twitter/XAttackers posed as IT staff over the phone and hijacked accounts belonging to Barack Obama, Joe Biden, and Elon Musk.
RobinhoodOne social engineering call to customer support exposed data for 5 million users.
442%

Surge in help desk vishing attacks, H1 to H2 2024

CrowdStrike 2025 Global Threat Report

$16B

Account takeover fraud losses in 2025

Javelin Strategy & Research 2025 Identity Fraud Study

Less than $1

Cost of personal data on the dark web, making security questions useless

DIRO

The Solution

Identity verification does what authentication cannot

Authentication confirms you have a credential, but at recovery that credential is gone and the question changes: is this person actually who they say they are?

Proof verifies identity through government-issued ID verification, liveness detection, and fraud signals, producing a tamper-evident record of every recovery decision.

How It Works

How identity-first recovery works

When a recovery request comes in, Proof takes the identity determination off your help desk's plate, so your agents route requests while Proof handles the determination.

01

Route request

When a user exhausts standard credentials, they receive a secure, branded link to Proof's verification flow, with no agent making an identity call and no opening for a social engineer.

02

Verify identity

Identify validates a government-issued ID, runs liveness detection, and applies fraud signals from Defend, powered by OmniTrust. Most users complete in under two minutes.

03

Human-in-the-loop, if needed

For inconclusive sessions, Verify routes the case to a trained human reviewer, ensuring edge cases are resolved consistently.

04

Issue credential

Every verification event produces a tamper-evident, cryptographically secured record: a defensible audit trail for every recovery decision.

05

Restore access

Verified users get back in quickly, fraudsters are stopped, and your help desk team receives the outcome without handling any PII.

Proof Identify verification flow
Proof in Practice

Zero fraudulent resets, at any scale.

Proof's IT team

Proof integrated Identify directly into our Okta account recovery flow. Any employee locked out of their machine goes through identity verification before anything is reset. They extended the same flow to device enrollment, so new hires verify before the process can proceed.

<2 min

Verification time

0

Edge case failures

Explore Proof + Okta →
A global digital platform

One of the world's largest digital platforms needed a recovery solution that worked at scale without creating a new attack surface. When users exhausted standard options, they were routed to a Proof-powered flow: government ID, liveness check, fraud signal review. Every legitimate user who completed verification got their account back.

150M+

Users served

~12 min

Full recovery time

See recovery at scale →
Frequently Asked Questions

FAQ

How is Proof different from what we are already doing?

Most recovery processes rely on knowledge-based questions, callback verification, or agent judgment, all of which are increasingly easy for attackers to defeat. Proof verifies identity directly using government-issued credentials and biometric confirmation, and produces a cryptographic record of every decision.

What does the user experience look like?

When a user exhausts standard recovery options, they receive a secure link to a Proof-powered verification flow. They submit a government-issued ID and complete a liveness check. Most users complete the process in under two minutes.

Does our help desk handle any PII through this process?

PII never enters your support systems. Your team receives the verification outcome without handling identity data directly.

How long does it take to implement Proof for account recovery?

Most teams are operational in under a week. Proof integrates directly into existing identity infrastructure, including Okta and other identity providers, without replacing what is already working.