SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
VanishID launches AI tool to cut identity attack risk

VanishID launches AI tool to cut identity attack risk

Wed, 5th Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

VanishID has launched an external identity protection platform and previewed an AI exploitability management tool designed to address publicly exposed employee data that can be used in phishing, deepfakes and impersonation attacks.

The platform focuses on personal information about executives, high-access employees and their families that sits outside corporate systems. The AI exploitability product is intended to measure what generative AI models can assemble from data already available on the open web.

Cyber security suppliers have spent years building tools around devices, networks and corporate accounts, but a growing share of attacks now starts with information gathered about people. That shift has drawn attention to public records, data broker listings, social media posts, breach dumps, and audio or image material that can be turned into convincing social engineering attempts.

VanishID said its external identity protection service operates from outside an organisation's perimeter and does not require software agents, integrations or internal credentials. It uses separate AI systems to find exposed personal data, analyse the risks, seek removals where possible and monitor information that cannot be taken down.

According to the company, the service covers data brokers, people-search sites, social media, breach and credential dumps, dark web sources and public records. Customers typically reduce attacker-reachable personal data by 85% within 90 days, including a 93% reduction in exposed data broker profiles, it said.

Human targets

The launch reflects a wider cyber security debate over whether the main attack surface is shifting from systems to people. Fraud involving executive impersonation, false payment instructions, and AI-generated voice or video has become a growing concern for businesses, particularly when an attacker combines public information with a trusted communication channel.

VanishID pointed to a case in which engineering firm Arup lost USD $25.6 million after a finance employee transferred money following a video conference where other participants, including the Chief Financial Officer, were deepfakes. The incident is widely cited as an example of how AI tools can be used in business email compromise and payment fraud without relying on malware or software exploits.

The company's AI exploitability management tool is intended to quantify that risk. It assesses more than 40 attack scenarios, including executive impersonation, real-time deepfakes, voice cloning, spear phishing, business email compromise and other forms of social engineering, then produces an AI Exploitability Score for each person assessed.

VanishID said the tool classifies the building blocks of each attack as required, high-value, useful or contextual. A face photograph, for example, may be essential for some deepfake scenarios, while a voice sample, organisational role and writing style may increase the chance of success.

Outside view

A central part of both products is that they operate entirely from an external viewpoint. That means the company examines only publicly reachable information rather than data from internal systems, aiming to show customers what an attacker could already gather without breaching a network.

Jason Barnett, Vice President and Chief Information Security Officer at Oracle Health & Global Industries, commented on the growing role of AI in attacks on individuals.

"Attacks on people used to be artisanal. One credential broker, patiently piecing together what they could find. AI industrialized that. Now it just needs the breadcrumbs we've all left scattered across the web to easily enable a compromise," said Barnett.

Matt Polak, Chief Executive Officer of VanishID, said many security teams can measure technical weaknesses in detail but struggle to judge what attackers can infer from public identity data.

"Most security teams can quote their patch rate to a decimal point. Almost none can tell you what AI could assemble from their CFO's public exposure this afternoon, and that blind spot is where the attacks now start," said Polak. "We built AI Exploitability Management to make it measurable, attack by attack and person by person, from the attacker's side of the fence. You can't patch a face photo, but once you can measure what it enables, remove what's possible to remove, and neutralize residual risk with existing security operations and tooling instead of leaving it unowned. Measurement is where managing AI risk begins."

Security gap

The company argues that a gap remains between established security controls and the information attackers use during reconnaissance. Identity tools, endpoint products and email defences largely monitor internal systems, while threat intelligence often focuses on attacker behaviour or known indicators of compromise rather than on which individuals are easiest to target and impersonate.

It also said attackers often go after employees whose access makes them useful rather than the most senior executive in the organisation. Executive assistants, finance managers and help desk staff may be lower-profile but can still approve payments, reset credentials or pass along trusted instructions.

That focus on access over title has become more significant as AI reduces the time and effort needed to craft a convincing lure. VanishID cited findings from Verizon's 2026 Data Breach Investigations Report that 35% of breaches start with attacks on people through phishing, credential abuse and pretexting, while 65% of AI-assisted attacks target people.

The external identity protection service is available now, while the AI exploitability management product is in preview. VanishID said more than 100 organisations use its platform, including large enterprises, financial institutions, health systems and public sector bodies.

"Every other tool defends what a company owns. We defend the one thing a company can't patch, the public personal data of its people," said Polak. "External Identity Protection takes the attacker's raw material away continuously, and it protects the people attackers actually target. That list reaches far beyond the C-suite. It's anyone whose access makes them worth attacking, or whose authority makes them worth impersonating."