AI Can Impersonate Anyone. Can Your Campus Tell the Difference?
Right now, someone is calling a university help desk claiming to be a locked-out student or staff member, and answering every security question correctly. They know the student ID, the advisor's name, the last four of a Social Security number. They sound convincing. They might even look convincing on video. And none of it proves they are who they say they are, because every one of those details is available to an attacker armed with AI and a few minutes of research. Universities are uniquely exposed. They manage two distinct identity populations—students and employees—with different life cycles, different risk profiles, and constant overlap. A student becomes a TA. An adjunct is hired semester-to-semester. An alumnus keeps email access for decades. Each transition is a verification gap attackers are learning to exploit. Most institutions have invested heavily in authentication—MFA, SSO, passwordless—but have not re-examined the identity verification layer underneath it. The question "is this the right account?" gets answered well. The question "is this the right person?" still depends on a security question and a judgment call. That gap runs through the help desk, financial aid, account recovery, and every high-risk workflow on campus. This session names the problem, maps where it hides, and gives attendees a practical framework to assess their own exposure and start closing it.
Presenters
-
Aaron Painter
CEO