{
  "id": 13096334,
  "title": "Why identity needs a heartbeat, not a checkpoint",
  "url": "https://urgent.news/2026/10/09/why-identity-needs-a-heartbeat-not-a-checkpoint",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-09T10:55:48.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/why-identity-needs-a-heartbeat-not-a-checkpoint"
  },
  "original_language": "en",
  "account": "When you need to prove your identity, you typically present an ID, take a selfie, or pass a liveness check. However, this checkpoint approach is becoming less effective. Fraudsters and criminals have found ways to bypass these checkpoints. Instead of defeating the initial biometric check, they hijack sessions after a legitimate login or use remote-access tools to control a verified customer's device. In some cases, they even recruit real people to complete onboarding legitimately and then hand the authenticated session to someone else. At the moment of verification, all these elements may be genuine, but the checkpoint alone does not guarantee that the same person remains in control later. This is known as the \"tollbooth mentality,\" where passing verification at login means a business can trust whatever happens afterward. To address this issue, identity should be treated as a continuous signal, like a heartbeat, that should remain consistent throughout the session. This requires capturing behavioral patterns, device and network telemetry, and other characteristics when onboarding. By comparing these signals with activity throughout the session, systems can detect when something has changed and adjust trust levels accordingly. If inconsistencies are detected, the system can increase the risk score, request additional verification, or even terminate the session. The industries moving fastest to adopt continuous, risk-based session monitoring are fintechs, crypto exchanges, and neobanks. They understand that adding friction at the front door can hurt legitimate customers but won't stop automated attackers. However, sectors still relying on one-time checks need to adapt as well. With vast amounts of personal information compromised, static questions and credentials provide diminishing assurance. By establishing a baseline at onboarding and monitoring passive behavioral and device signals continuously, enterprises can maintain trust while minimizing disruption for low-risk customers. This framework includes four key components: establishing a baseline at onboarding, passive monitoring, identifying necessary signals to assess session trustworthiness, and escalating proportionally based on risk. By treating identity as a heartbeat, organizations can prevent disruption for low-risk customers while triggering proportional intervention for anomalous behavior, ultimately avoiding the pitfalls of the \"tollbooth mentality.\"",
  "summary": "Fraudsters bypass login checkpoints post-verification—here's why identity must be monitored continuously, not just checked once.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}