Shapefin

Token Positions Biometric FIDO2 as Defense Against Advanced Phishing Attacks Following Aflac Breach

Share It:

Token, a provider of secure, biometric identity protection solutions, has stated its technology could have prevented the recent data breach at Aflac, which reportedly exposed sensitive customer information, emphasizing the vulnerabilities of legacy multi-factor authentication (MFA) methods.

The Aflac breach, confirmed on June 20, 2025, potentially exposed customers’ Social Security numbers, insurance claims, and personal health information. This incident is considered significant within a growing trend of cyberattacks targeting the insurance industry. “With billions in revenue and millions of customers, Aflac now joins a troubling list,” said Kevin Surace, Chair, Token. “Erie Insurance and Philadelphia Insurance Companies were also hit this month, with major IT disruptions affecting customer services.”

Industry experts suggest that the cybercrime group Scattered Spider is responsible for the Aflac breach. Their attack methodology exploits legacy MFA systems, where SMS codes can be intercepted or relayed, and users can be tricked into approving authenticator app prompts during real-time phishing. These methods are described as easily manipulated, requiring minimal technical ability, allowing attackers to execute hacks quickly.

Token’s solutions, including Token Ring and Token BioStick, integrate biometric ID (fingerprint) with proximity verification via encrypted Bluetooth to the specific device logging in. The system stores a unique private key per site, secured by a fingerprint. During login, it signs a one-time challenge from the legitimate site’s FIDO2 server, which then verifies the signature and its origin. If the origin does not match, the login is rejected, effectively blocking phishing and spoofing attempts. This design prevents real-time phishing because credentials are cryptographically locked to the exact web origin for which they were created, and the authenticator will only sign a challenge that originates from that domain and is confirmed by a live fingerprint match.

According to Token, if Aflac employees had been utilizing a Token product, the described hack could not have occurred. The company highlights that its products store a negotiated key pair per site and only release a signature when the site matches the domain the user is genuinely visiting, the domain possesses the correct secret key pair matching the initial device registration, and the fingerprint sensor verifies the legitimate user. This approach prevents remote adversaries from spoofing keys or forwarding signatures, unlike traditional OTP codes or push-approval applications. FIDO2, when implemented as Token has done, offers true phishing-resistant MFA, enhancing security significantly beyond legacy MFA solutions. Token asserts that deploying Token Ring or Token BioStick across a workforce provides a robust defense, rendering phishing attempts ineffective even if an employee engages with a malicious email. For more information, visit www.tokenring.com.

Latest Posts