The Password Reset Problem Nobody Is Talking About

In this exclusive webinar, Madhu Madhusudhanan, Co-founder & CTO of OLOID, explores how AI-powered impersonation is changing the risk around password resets, account recovery, and other sensitive workforce requests. Watch to learn why traditional help-desk verification is becoming easier to defeat, and how stronger identity assurance can help organizations respond.

Password resets have always been a security-sensitive workflow. But AI-generated voices, sophisticated social engineering, and readily available personal information are making it increasingly difficult for help-desk teams to know whether the person requesting access is really who they claim to be.

The challenge is especially acute for frontline workers, who may not have corporate email addresses, personal work devices, or access to conventional mobile MFA. Madhu discusses why organizations need to verify identity before approving sensitive requests - and how biometrics, identity proofing, contextual signals, AI, and human oversight can work together to strengthen the process.

Key Insights from the Webinar

  • Password resets are becoming an identity assurance problem: Attackers increasingly target help desks because resetting a credential can give them legitimate access without having to defeat authentication directly.
  • Traditional verification is easier to bypass: Employee IDs, birthdates, security questions, and SMS-based codes can be discovered, intercepted, or socially engineered. Knowing information about an employee is no longer enough to prove identity.
  • AI is raising the impersonation stakes: Synthetic voices, deepfakes, automated research, and geo-spoofing allow attackers to create more convincing requests and attempt social-engineering attacks at greater scale.
  • Higher-risk requests need stronger proof: Biometrics, government-issued ID verification, liveness detection, registered-number callbacks, and phishing-resistant authentication can provide greater assurance before a password or MFA factor is reset.
  • Verification should adapt to the request: A routine support question should not require the same level of assurance as an account recovery or privileged-access request. Risk-based workflows can apply stronger verification when the potential impact is higher.
  • AI can support, not just replace, the help desk: AI-driven identity assurance can gather context, assess confidence, flag higher-risk users, and give human agents additional information before they approve a sensitive request.

What This Means for Security Teams

  • Reassess your reset process: Review how employees are currently verified before passwords, MFA factors, or accounts are recovered, particularly for frontline and shared-device users.
  • Move beyond knowledge-based verification: Build identity checks around stronger signals rather than information an attacker could discover through social media, data brokers, or previous breaches.
  • Match verification to risk: Apply additional identity checks for privileged users, unusual requests, account recovery, and other actions with a higher potential impact.
  • Give help-desk agents better context: Identity confidence, device signals, location information, and verification history can help agents distinguish legitimate requests from suspicious ones without relying solely on caller judgment.
  • Monitor what happens after the reset: A successful identity check should not be the end of the process. Post-reset monitoring can help detect unusual activity if credentials or sessions are subsequently abused.
  • Work toward phishing-resistant, passwordless access: Reducing dependence on passwords and other phishable credentials removes much of the reset attack surface altogether while creating a stronger long-term authentication model.