context verification (known number, callback, OTP), CRM cross-check, detection of account or number changes, verification escalation on sensitive actions.
The threat
the attacker passes as a legitimate user (impersonation), exploits a wrong account match or takes over a session (account takeover) to act on their behalf.
Angle mortWhy classic frameworks miss it
the risk is not in the authentication channel but in the trust given to the declared context; a I-am-Mr-X accepted without cross-check opens the door with no technical intrusion.
MitigationProposed approach
context verification (known number, callback, OTP), CRM cross-check, detection of account or number changes, verification escalation on sensitive actions.
The proposed control
no sensitive action on declaration alone.
Expected evidence
demonstrate that a declarative account takeover is blocked by a deterministic control.