A relay kit rented for $200 a month, a phishing PDF with no links, and one approved auth prompt is all it takes to hand a session to an attacker. This Brand Briefing from Black Hat USA 2026 gets into what identity looks like when access depends on a live fingerprint within three feet of the machine.
Kevin Surace, Chief Executive Officer at TokenCore, opens with the attack path he says is doing the most damage right now. A phishing email carries a PDF and no links, so it clears the filters. The domain is one character off from the real one, the site is pixel perfect because AI built both the page and the message, and the employee approves an auth prompt they were already expecting.
The code was real and the approval was real. Kevin Surace points out that auth apps and passkeys run over cellular and Wi-Fi, so the prompt has no way to know the request came from ten thousand miles away. Anything a person can read or hand over can be shared, and by his account an attacker needs about thirty seconds of trust to get it.
Passkeys moved the target rather than removing it. Kevin Surace counts 39 separate passkey attacks in the wild within two weeks of Microsoft telling customers to migrate, and points to Michael Grafnetter of SpecterOps, who presented passkey and Entra research at Black Hat. He walks through the FIDO2 counter that WebAuthn treats as optional so shared passkeys can move between devices.
What changes with TokenCore in the mix is where the proof sits. Kevin Surace describes signing into Entra in under two seconds, both passwordless and ID-less, over secure Bluetooth, with the device carrying no apps and no screen. Proximity holds it within three feet of the computer being logged into, the credential stays bound to the original domain, and fingerprints stay off the network.
Agents raise the same question in a new place. Kevin Surace describes a policy where an agent action above a million-dollar check needs a person to approve it, and notes that another agent, a hacked one, or a bad actor can clear that approval just as easily. A biometric gate is what tells you the CFO was actually in the room, which is a governance answer as much as a security one.
For CISOs, identity architects, and risk owners, the question worth asking is what an identity program looks like when the proof of a person becomes the control, and how much residual risk that removes from privileged access, financial approvals, and agent workflows.
This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing
GUEST
Kevin Surace, Chief Executive Officer at TokenCore
LinkedIn: https://www.linkedin.com/in/ksurace/
RESOURCES
Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas
Learn more about TokenCore: https://www.tokencore.com
TokenCore products: https://www.tokencore.com/products
Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings
KEYWORDS
Kevin Surace, TokenCore, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, biometric identity, identity assurance, passkey attacks, MFA relay attack, phishing resistant authentication, auth app compromise, FIDO2, WebAuthn, Microsoft Entra, passwordless authentication, agent authorization, privileged access
Attackers Relay Codes and Approvals. TokenCore Requires a Live Fingerprint Within Three Feet | A Brand Briefing at Black Hat USA 2026 with Kevin Surace, Chief Executive Officer at TokenCore | Hosted by Sean Martin
[00:00:00] Sean Martin: And hello, everybody. You're very welcome to this Brand Briefing. I'm thrilled to have Kevin Surace on from TokenCore. We're gonna be talking a bit about, uh, stuff we saw and heard at Black Hat and, uh, all the good things that, uh, that the team at TokenCore are working on to help us, uh, secure and leverage our identities in all the ways that, uh, being built and delivered these days.
Kevin, good to have you on.
[00:00:27] Kevin Surace: Thanks for having me, Sean
[00:00:29] Sean Martin: And, um, yeah, I just want to get started with let's start with this. And you've been on the show before,
[00:00:37] Kevin Surace: Mm-hmm.
[00:00:38] Sean Martin: just in the off chance folks haven't, haven't
[00:00:41] Kevin Surace: If they haven't watched your show with me on it, that they should go back and watch it and we get... This is, this is session two.
[00:00:48] Sean Martin: Exactly. Exactly. Well, I'm thrilled to have you on, but maybe a brief overview of role at TokenCore and, uh, what's going on there
[00:00:55] Kevin Surace: Sure. Token is a, uh, is-- it's tokencore.com, but, uh, Token is... Because token.com was taken. Token is a, uh, is a, uh, is a company focused on biometric identity and, uh, and specifically wireless, easy-to-use biometric identity. The, uh, the vision, uh, is turning out to be right, but the vision from 14 years ago was that if you didn't tie everything in the future to biometrics, AI was going to eat your lunch.
Um, in 2021 when I was telling people that just five years ago, they'd still look at me and go, "What do you mean? Uh, we've got MFA, we've got auth apps, everything's fine." And, uh, you know, everything has come to pass. Every single thing that, that you could lay out has come to pass, and AI is making identity hacks, uh, not only the top hack, about 90% according to, to, uh, Palo Alto Networks, but, um, but easy.
Easy. En masse. They're just kits. You-- Teens push the button and they get access to really any company's goods and then they're, they're, uh, you know, they, they initiate a ransomware, uh, request and, uh, much of the time they're, they're getting, they're getting that money. So, um, it's a bad situation, and it is being fully stopped by our products.
But when you don't use our products, not fully stopped. That's the... That is actual- unfortunately true and it sounds like a marketing thing, and I'm not in marketing, but you know what I mean.
[00:02:17] Sean Martin: I do know what you mean. And I mean, we've-- I've been in this space far too long to, uh, to claim the number of years, but I've seen identity kind of cycle. important, gets off the radar, gets important, off the radar. It's important again, and I, I think we're gonna get into some interesting things here that...
I SMS was a way for second factor and, and that was said, it was said to rely on that, and so we moved to MFA with other
[00:02:47] Kevin Surace: Mm-hmm.
[00:02:48] Sean Martin: ways to get access to things. What, what's the reality?
[00:02:51] Kevin Surace: Yeah. Well, the, the good, you know, f- uh, for several years we were out there saying, "Get off of MFA and auth apps." And what we would hear from companies that were, uh, not thoughtful about it was, "I don't know, I'm using this auth app from Microsoft," or from Google, or from Cisco, or from... It doesn't matter who, right?
Uh, Oracle, or from Salesforce, so it must be secure. Well, they are very, very easy to relay attack. That's just one of 15 attacks on MFA and auth apps.
[00:03:21] Sean Martin: De- describe that for
[00:03:22] Kevin Surace: sure, sure, I will. It's incredibly, stupidly simple, actually. You don't have to be technical to do it. You have to just borrow a kit at $200 a month on the dark web.
Here's how a, a, a, a, a real-time relay, uh, works. Um, so, uh, you get a phishing email. You're one of 10,000 employees at this company. Uh, you're one of, uh, who knows, a thousand who have access to interesting data that could be ransomed, right? Um, you get a phishing email. You don't realize it's phishing. It came from DocuSign, or it came from some other source, including internal in the company that you think is proper, right?
Um, there are no links in the email, but there's an attached document. It's a PDF. That already gets through all of the phishing filters. Now, another reason it gets through the phishing filters is every email is different and literally targeted to you, and they do that by gathering information from the dark web and gathering information from LinkedIn and Facebook and other places.
So your email is targeted to you. It looks like it's for you, and it says, for example, you need to log... You get this PDF, it says, "Please log into the company employee portal to, uh, uh, update some record or something you got." And, and, and by the way, I might not do that, and Sean, you might not do that. If I've got 10,000 employees, I guarantee...
And by the way, I only need one person to do it, but I can guarantee you about 35% will do it, no matter how much training they have, and the data are clear on that. So I click on the, the link in the PDF. Instead of employee.amazon.com, it takes me to employee.amazon.con. I, I don't see the N. Now, it's a pixel perfect site.
Pixel perfect. Why? AI created the email and also created the site. But this is a spoofed site, and it's a spoofed relay site. So I go there, I type in my login ID and password. It's unclear whether they needed that or not, but those login ID and password get relayed to the real hacker who... Maybe they're in Russia, it doesn't matter where they are Gets relayed to them.
Now, some people would say, "Well, I'll see this IP address logging in from Russia. I'm gonna block it." They're not logging in from Russia. They've tunneled to a s- a server in the US, so forget that. It looks like it's coming from down the street. They type in their ID and password. The real application comes up and says...
What does it say? It says, um, "Enter your auth. Use your auth app to authorize yourself." Okay, that comes over cellular or Wi-Fi and comes to the person's phone. The poor person at the actual company gets an auth app request, which they expect, and it says, "Is this you?" And you say, "Yes, it's me." Or it says, "Here's your four-digit code."
Or it's a... Well, it does- doesn't actually matter. They literally authorize it. Now, they may authorize it literally with their face or with anything or just doesn't matter. They authorize it. Who did they let in? They let in the hacker because the... Your, all your authorizer, all your authorization devices for these kinds of, um, uh, auth apps work over cellular and Wi-Fi, so they work around the world.
It doesn't know that that request came from 10,000 miles away, so you let in the hacker. It's literally that simple. Now, there are social engineering attacks that, um, someone pretends they're from IT, and they call you, and they also get you to log in, and they get you to hand them their MFA. And we've all been, or many of us have been on with IT, and I...
Real IT, and IT says, "Look," or the bank says, "Look, we've got a problem. We're worried about your account," blah, blah, blah. "We're gonna send you a code. Never share this code except with us, the bank, or us, IT," and you share it. So you share it because they only have to develop 30 seconds of trust to get you to do that, so anything that a human can read or do can be shared, and that's the trick with that.
So that was the end of M- MFA and auth apps and, uh, and, and, and, uh, Microsoft, uh, shut down one, one of the biggest, the servers that was doing this, and they found 96,000 successful hacks of the Microsoft auth app. After that, they sent an email to all their customers that says, "By February 17th, 2027, no more auth app, no more MFA.
You can't use it. Move to pass keys." So this was some weeks ago, right? It took two weeks- Passkeys. Everyone who's listening to this is going, "Passkeys are secure." It took two weeks for 39 separate, uh, uh, hacks of passkeys to be in the wild. Now, they are not... To be clear, they're not hacking the encryption of a passkey.
They're playing social engineering tricks similar to the one I said, but quite different. A whole bunch of social engineering tricks to get you to log them in, or to get you to literally add them as a passkey, or to steal your shared passkey, because passkeys are shared between devices, they're stored in the cloud, um, or to actually spoof a service that says, uh, "I am that person with this passkey," but they've actually stolen the encrypted package and pushed it up, and they did it in a way that shouldn't be legal, but many of the services, including Entra, don't implement the entire FIDO2 spec.
So of course, it took hackers five minutes to figure out, "Oh, you didn't implement what's called a counter." So I'll give you a little bit more background on this one in passkeys.
[00:08:45] Sean Martin: be good
[00:08:46] Kevin Surace: So, um, in passkeys, there's this thing called a, a counter, and a counter is if my thing logs into Microsoft Entra for the 888th time, the next time I do it is 889, and, and both of us increment, and they must match from the first time.
Make sense? Well, unfortunately, free passkeys that are passed around in the cloud don't have a way to increment the counter because they don't know if another device did this, right? They don't have that back-and-forth communication. They're not sure. So Microsoft said, "Well, we'll just ignore the counter.
We'll just let it set at zero and leave it." So our devices, for example, send the counter information. Microsoft sees it, but doesn't stop you if the counter's wrong. So they're exploiting this by going, "I'll just steal this passkey package, push it back up, it'll let me in, and it'll think I'm that person, and it'll basically allow me to share that session ID, basically."
This is, um, this is a really bad thing. Now, it's stopped if there's a counter because I'd have to increment the counter and I can't decrypt the package, therefore, I wouldn't be able to increment the counter properly because that's part of the encryption That's why it was added. FIDO2 says you must use the counter on both sides.
But WebAuthn says optional because we want to allow free passkeys to move around, therefore there's no counter. And so everybody's hacking the counter. It's, it's... There's nothing... It's so easy. So, you know, the message is that passkeys are, uh, uh, you know, today as I sit here, are probably getting an F like MFA and auth apps are.
There are th- 39 ways in the wild right now, and, and, and in fact, we've published a lot on this, but Michael, uh, Grafnetter at Black Hat actually, um, from SpecterOps, actually went through 15 ways that are already seen in the wild to, um, to essentially, you know, hack passkey and Entra. Um, so that's not good, right?
[00:10:45] Sean Martin: Not good. good. And help me, 'cause I'm a little bit ignorant in this space, but the, the passkey, is it connected and tied to a specific app, or
[00:10:55] Kevin Surace: No, that's the thing. So, um, well, yes it is in that way. Like, like when you create a passkey for an application, it is bound to that application. So nobody's changed that bounding. They're playing with the social implications of either getting you to do it or stealing the whole thing and doing it themselves, or taking over your cloud and then using it, right?
There's lots of ways to get access to a shared passkey as opposed to, as, as you know, what we do is biometric hard-coded device. So, um, you, you can't... By the way, one of the ways they're, they're thwarting passkeys is they put a, a fake application on your phone, and then you think that is the real application.
You go to the wrong application. Again, you're sharing something. They take it and relay it right in. Like, everything goes wrong, uh, when you've got something shared. Um, so, um, there you go. So there's two things. And then the third... Look, third thing at Black Hat real quickly, and we can talk about Token for a second, is, um, is agents and securing agents.
And, uh, at, at Token, we think the only way in the end you absolutely secure agents, just like you're securing humans, the only way we can ser-secure you, Sean, or 10,000 employees at that company is, um, is dedicated biometric hardware, period. That has no apps on it. It has no screen. There's nothing to relay.
The human can't do anything but put in their fingerprint. That's... And, and it authorizes you. Um, and that works with every major service. So it's true with agents also. If you have an auth for an agent to say anything above a million-dollar check, I want this human to approve it. So it goes to someone's desktop.
It comes in a Slack. It comes in an email. It pops up as a po- whatever. Another agent on their desktop just cleaning up stuff to do could authorize it, or a bad actor can authorize
[00:12:43] Sean Martin: that's the instruction. Get this done
[00:12:45] Kevin Surace: it, or a hacker, right? Y-yeah, anyone can authorize it. Like it can be... So if you don't have a biometric gate, I don't... Not only don't I know who exactly authorized it, any agent, a rogue agent, a good agent, a hacked agent can also do it.
So y- without a biometric gate, I can't guarantee that the actual approver, say the CFO, is even in the room. I have no idea. You put a biometric gate, not face, not voice, 'cause I think everyone knows they're hacked, right? They're like easy to hack any, like in the next five minutes. So, um, fingerprints we don't store on the network.
That's why they're still secure. Uh, it's probably all we have that's secure, that and DNA. I mean, we start to run out of things after a while, right? But DNA is hard to process in 100 milliseconds, but fingerprint I can.
[00:13:29] Sean Martin: Wow. So interesting and troubling
[00:13:34] Kevin Surace: Interesting and troubling. But that's, that, that's all the talk at Black... I mean, that's a lot of the talk at Black Hat. There's these three things and, and you know, at Token this is what we have foc- I mean, this is a Token ring. There's a bunch of Token different devices. That's a portable. Uh, there we go.
[00:13:48] Sean Martin: There we go. De- describe the scenario
[00:13:49] Kevin Surace: uh, you know
[00:13:51] Sean Martin: and then, then use, use the ring example 'cause the ring is cool, by
[00:13:55] Kevin Surace: Oh, here, here, the ring is cool. Here's what happens. If I wanna sign in, in fact, we got customers doing this. If I wanna sign into Entra with this, not only can I sign in under two seconds, I can sign in both passwordless and ID-less. Literally, I can wa- this is Bluetooth, so I can walk... a secure Bluetooth. I can walk up to a machine, I can just do this, and it says, "Welcome, Kevin."
Not the machine, just Entra. It could be the machine also. But Entra itself, or Okta, or, uh, Oracle, or Google, or Salesforce, doesn't matter, right? All SSOs we're compatible with, all major applications compatible with, major banks compatible with. So if you want no user ID, no password, logged in in under two seconds, there's nothing to steal, there's nothing to share.
It's immune right now, knock on wood, from all 39 passkey attacks. All 39. They go after passkeys, they don't work with this. They don't work with any of our products. There, there's, there's no known hack of our products currently, provided you, you, you, you set up your systems correctly. So, so for example, a way to hack it would be, um, I, I...
oh, I can't think, I can't think of a social engineering way, but like someone pretends they're IT. See, if someone pretends they're IT, you still can't log in that other person 'cause you have to be within three feet of the logging-on computer. And the reason is, is we only work over Bluetooth. So
[00:15:17] Sean Martin: Right.
[00:15:17] Kevin Surace: if y-
[00:15:17] Sean Martin: And you have the, you have the step off option for the, the fingerprint there as well
[00:15:22] Kevin Surace: Uh, we, we only have, yes, it's fingerprint. It is within three feet, so you've got proximity. You've got bound to the original domain. Um, but there's no way around the fingerprint. So there's no code that you could put in that says, "I'm gonna get around the fingerprint." There's, there's a device out there that you tap it three times, it says, "Oh, just enter your code instead."
Well, that's, that's not biometric anymore. That's fake, right? So we d- we don't, we don't allow that. It-- biometric is biometric. Um, and in this AI world, uh, whether it's today or it's a year from now, everybody's gonna be biometric. There, there isn't a question about it because, uh, AI is just too good at compromising everything else.
[00:16:05] Sean Martin: Look at that. We have, we have to go back to the physical world to, uh, to protect ourselves. Kevin, it's great to chat with you. Thanks for bringing all the, uh, the insights on identity, and, uh, troubling as it may be, um, thankfully you've, you've been working on this for some time, and I'm gonna encourage
[00:16:22] Kevin Surace: time. Long
[00:16:23] Sean Martin: with you and the, and the TokenCore team,
[00:16:26] Kevin Surace: Appreciate that
[00:16:27] Sean Martin: and grab, grab your own Token Ring.
[00:16:29] Kevin Surace: Yeah, yeah. Uh, tokencore.com. All good. And there is my Token Ring
[00:16:34] Sean Martin: There it is. All right. Thanks everybody for listening. Uh, stay tuned. There's more, let's see, more coming from Black Hat, funny enough. And, uh, pleasure having you on, Kevin. Good to see you. And, uh, keep well, keep, keep doing good things at TokenCore. Thanks everybody
[00:16:49] Kevin Surace: Thanks, Sean