{
  "slug": "add-authenticator-takeover",
  "title": "The takeover button is labelled \"Add authenticator\"",
  "summary": "Enrolling a new passkey is the most consequential action in an account, and almost every platform gates it with the session an attacker already stole.",
  "lede": "Your account security model probably treats a payment as high risk and a settings change as routine. That ranking is backwards. Enrolling a new authenticator is the single most consequential thing anyone can do inside an account, because it converts a stolen session that expires into durable access that does not.",
  "date": "2026-09-14",
  "reading_time": "17 min read",
  "category": "Security",
  "tags": ["MFA enrollment", "passkey security", "account takeover", "WebAuthn", "authenticator registration", "Scattered Spider"],
  "image": "https://cdn.twc.sh/images/igcache/Add%20Authenticator%20Takeover/1200_630/blog.jpg",
  "url": "/blog/add-authenticator-takeover.html",
  "wordcount": 4428,
  "related": ["passkey-recovery-weakest-link", "session-theft-aitm", "payee-add-is-the-transaction"],
  "schema": "Article"
}
