Banana Navy
Catalog FR
Lab · Threat modeling IA · Fiche détaillée

User identity impersonation and account takeover

the attacker passes as a legitimate user (impersonation), exploits a wrong account match or takes over a session (account takeover) to act on their behalf.

SheetF5
CategoryS-TB7-01 + E-TB7-01
Layers12 · Identity & Context Check
Systemvoicebot IA

context verification (known number, callback, OTP), CRM cross-check, detection of account or number changes, verification escalation on sensitive actions.

The threat

the attacker passes as a legitimate user (impersonation), exploits a wrong account match or takes over a session (account takeover) to act on their behalf.

Angle mortWhy classic frameworks miss it

the risk is not in the authentication channel but in the trust given to the declared context; a I-am-Mr-X accepted without cross-check opens the door with no technical intrusion.

MitigationProposed approach

context verification (known number, callback, OTP), CRM cross-check, detection of account or number changes, verification escalation on sensitive actions.

The proposed control
no sensitive action on declaration alone.

Expected evidence
demonstrate that a declarative account takeover is blocked by a deterministic control.

SourcesReferences and public research

MITRE ATLAS 2026.07AML.T0043 Craft Adversarial Data
Recherche publiquePublic research sources: MITRE ATLAS 2026.07 (verified technique mapping), OWASP GenAI (catégories par abus de modèle), and the public risk-voicebot (aivansoul/risk-voicebot) template defining the 20 checkpoints. No client registry data: generic sheet, no rating, no verdict.
couche 12 · Identity & Context Check

Explore the 20 security layers

MITRE ATLAS 2026.07 · OWASP GenAI · risk-voicebot