SardineCon SF/2026

Learn More
Identity verification4 min de lectura

¿Qué es Knowledge-based authentication (KBA)?

SUBSCRIBE

Knowledge-based authentication verifies a person by asking things only they should know, like a past address or an old loan amount. It was once a common step-up, but breaches and data brokers have made that data widely available, so today it is considered a weak, low-assurance factor.

What is KBA, in plain English?

Knowledge-based authentication verifies someone by asking questions that, in theory, only they can answer: a previous address, the make of an old car, the amount of a past loan, or which of several street names they once lived on. There are two flavors: static KBA, where the user sets answers in advance like security questions, and dynamic KBA, where questions are generated on the fly from credit and public records.

For years it was a standard step-up, a quick extra hurdle at account opening or password reset. It felt secure because the answers were personal. The problem is that personal is not the same as secret. Decades of data breaches and the rise of data brokers have put exactly this kind of information on the open market.

In fraud and AML, KBA is now treated as low assurance. Fraudsters buying breached data often answer the questions more accurately than the real customer, who may genuinely forget an address from fifteen years ago. It still lingers in many flows, but it should be a weak step-up at most, not a gate for anything sensitive.

Why KBA got weak

What changes

KBA (knowledge)

Possession or biometric

The secret

Facts about your past.

A device you hold or a face you are.

Exposure

Widely leaked through breaches and brokers.

Much harder to steal at scale.

Who answers better

Often the fraudster with the data.

The genuine holder of the factor.

Assurance

Low, treat as a soft signal.

Higher, suitable for sensitive actions.

Who is involved?

Who

Their role

The customer

Answers the questions, sometimes less accurately than the fraudster does.

The KBA provider

Generates questions from credit and public records and scores the answers.

The risk owner

Decides where KBA is acceptable and where a stronger factor is required.

The fraudster

Buys breached data and answers the questions to clear the step-up.

What it looks like in practice

In practice

A caller asks to reset access to an account and hits a dynamic KBA step: which of these four streets have you lived on, and what was your prior car's make. The caller answers all of them quickly and correctly, and the reset goes through.

The real customer later reports the account taken over. The caller was a fraudster reading from a breached data profile that included the victim's address history and vehicle records. The genuine customer, asked the same questions, had hesitated on the old address. KBA rewarded the person with the file, not the person who owned the identity. The team moves resets to a possession-based factor.

Why it matters to operators

KBA is a control many teams still run out of habit, and that habit is a risk. Because the underlying data is exposed, KBA can give a false sense of security while doing little to stop a prepared fraudster. Worse, it can add friction that trips up genuine customers who simply do not remember a detail from years ago, so you get the downside of friction without the upside of assurance.

The practical guidance is to demote it. Use KBA as a low-assurance step-up at most, and prefer possession or biometric factors, a device, a passkey, or a face, for anything sensitive like resets, high-value transfers, or account recovery. If KBA is your main line of defense on a sensitive action, treat that as a gap to close.

What to watch in the data

  • Fast, flawless answers. A caller acing every KBA question instantly can mean someone reading from a data file, not recalling their own life.
  • KBA guarding resets. Password and account-recovery flows protected only by KBA are a soft target for takeover.
  • Genuine customers failing. Real users stumbling on old details shows KBA adding friction without adding much security.
  • Static questions reused. Security answers set once and reused across sites are often already exposed in breaches.
  • KBA on high value. Relying on knowledge factors for sensitive transfers is an assurance gap, not a control.

Quick questions

Why is KBA considered weak now?

Because the answers, past addresses, loan amounts, vehicle history, are widely exposed through breaches and data brokers. Fraudsters with that data often answer more accurately than the genuine customer, which defeats the whole point.

What is the difference between static and dynamic KBA?

Static KBA uses answers the user set in advance, like security questions. Dynamic KBA generates questions on the fly from credit and public records. Both are weak today, since the source data is broadly available.

Should I remove KBA entirely?

Not necessarily, but demote it. It can serve as a low-assurance soft signal, but it should not be the main gate on sensitive actions. Prefer possession or biometric factors for anything that matters.

What should replace it for sensitive actions?

Possession factors like a passkey or hardware key, or biometric factors with liveness. These are much harder to steal at scale than facts about someone's past, so they offer real assurance where KBA does not.

Does a passed KBA prove identity?

No. It only shows the answerer had the information, which a fraudster can buy. Treat a passed KBA as a weak supporting signal, never as standalone proof that the person is who they claim.

Go deeper

  • NIST Digital Identity Guidelines (SP 800-63) ↗ — The US standard for identity proofing and authentication assurance levels.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

Qué saber junto con Knowledge-based authentication (KBA)