Banana Navy
Catalog FR
Lab · AI threat modeling · Detailed card

User identity impersonation and account takeover

Acting in the conversation under an identity that is not your own.

CardF5
CategoryS-TB7-01 + E-TB7-01
Layers12 · Identity & Context Check
SystemAI voicebot

Verify identity out-of-band and tighten checks on sensitive actions.

The threat

the attacker passes as a legitimate user (impersonation), exploits a wrong account match or takes over a session (account takeover) to act on their behalf.

Blind spotWhy classic frameworks miss it

the risk is not in the authentication channel but in the trust given to the declared context; an "I-am-Mr-X" claim accepted without cross-check opens the door with no technical intrusion.

MitigationProposed approach

context verification (known number, callback, OTP), CRM cross-check, detection of account or number changes, verification escalation on sensitive actions.

The proposed control
no sensitive action on declaration alone.

Expected evidence
demonstrate that a declarative account takeover is blocked by a deterministic control.

SourcesReferences and public research

MITRE ATLAS 2026.07AML.T0043 Craft Adversarial Data
Public researchPublic research sources: MITRE ATLAS 2026.07 (verified technique mapping), OWASP GenAI (model abuse categories), and the public risk-voicebot (aivansoul/risk-voicebot) template defining the 20 checkpoints. No client registry data: generic card, no rating, no verdict.

Explore the 20 security layers

MITRE ATLAS 2026.07 · OWASP GenAI · risk-voicebot