Passkeys Emerge as a Powerful Defense Against Account Takeovers
HealthEquity's Ajit Gaddam highlights passkeys and biometrics as crucial tools to combat account takeover fraud by replacing vulnerable passwords.

Passwords, long the cornerstone of digital security, are increasingly proving to be a significant weak point, enabling widespread account takeover (ATO) fraud. The ease with which credentials can be forgotten, stolen, or reused by users creates fertile ground for attackers. These compromised credentials are then frequently exploited through automated attacks like credential stuffing or by manipulating often-flawed account recovery processes, allowing threat actors to impersonate legitimate users and gain unauthorized access.
Ajit Gaddam, head of fraud, financial crimes, and product security at HealthEquity, argues that the future of robust account security lies in moving beyond traditional passwords. He champions passkeys, a technology that leverages device-based cryptography and biometric verification, as a superior alternative. In this model, the private cryptographic key securely resides on the user's device, and access is granted through familiar biometric authentication methods such as facial recognition or fingerprint scans.
Gaddam emphasizes that this passwordless approach offers a dual benefit: it significantly shortens login times for users, thereby reducing friction, while simultaneously enhancing identity assurance. Crucially, it diminishes reliance on vulnerable account recovery workflows, which have become a prime target for sophisticated fraud schemes. "The best password in the world is you. You are your own identity," Gaddam stated, underscoring the inherent security of personal biometrics.
HealthEquity's journey towards adopting passkeys involved overcoming several hurdles, including educating users and support staff, and ensuring a seamless user experience. Gaddam noted that successful passkey adoption hinges on comprehensive user education, a clear and intuitive user interface, and well-trained support teams capable of assisting users through the transition.
Beyond passkeys, Gaddam also touched upon the critical role of fraud signals and AI in modern cyber defense. He highlighted that call center staff, often the first line of defense, can inadvertently become the weakest link against social engineering tactics if not adequately trained. Organizations must equip these teams with the knowledge and tools to identify and thwart manipulative attempts by attackers.
With over two decades of experience in enterprise cybersecurity, Gaddam's expertise spans fraud prevention, AI-driven security, and security engineering. His prior roles at Visa, where he led security engineering and product security programs, and his extensive patent portfolio in cybersecurity, fraud detection, and AI, lend significant weight to his insights on combating evolving threats.
The shift towards passwordless authentication, exemplified by passkeys, represents a significant evolution in the fight against account takeover. By moving away from easily compromised static credentials and embracing user-centric, cryptographically secured methods, organizations like HealthEquity are building stronger defenses against a persistent and damaging threat vector.