Help Desk Impersonation: Defending the IT Service Desk
Attackers don't hack the help desk — they call it. Inside the password-reset attacks that hit MGM, Clorox and M&S, and the controls that stop them.

The most reliable way into a hardened enterprise in 2026 is not a zero-day. It is a polite phone call to the IT service desk from someone claiming to be an employee who lost their phone. The service desk resets the password, re-enrolls the attacker's device for MFA, and closes the ticket with a good satisfaction score. Minutes later the attacker is inside the SSO portal with a valid credential and a valid second factor, and nothing about the login looks wrong.
This is the technique that CISA and the FBI attribute to Scattered Spider — attackers who "posed as company IT and/or helpdesk staff" and used "voice communications to convince IT help desk personnel to reset passwords and/or MFA tokens." It sits inside a broader shift toward voice-based intrusion: CrowdStrike's 2025 Global Threat Report recorded a 442% increase in vishing operations between the first and second half of 2024, and the Verizon DBIR still puts the human element in 62% of breaches. The help desk variant deserves its own defense guide because it inverts the usual direction of attack: instead of tricking an employee into giving something to "IT," the attacker tricks IT into giving them the employee.
One phone call, then the whole SSO estate
The attack is cheap because everything it needs is lying around in public. The caller researches a target on LinkedIn — name, role, manager, start date, even a voice sample from a conference talk — and supplements it with personal data from past breaches. That is usually enough to sail through the identity questions most service desks ask, which is a pretexting problem, not a technology problem: employee ID numbers, birthdays and manager names were never secrets.
The playbook typically runs four steps:
- Select an account worth stealing. Groups like Scattered Spider favor IT administrators, executives and finance staff. ReliaQuest's analysis found 81% of the group's phishing domains impersonated technology vendors precisely to harvest high-value credentials — and reports that skilled social-engineering callers can earn $10,000–$25,000 a month.
- Call the desk with a plausible emergency. A lost phone, a broken laptop before a board meeting, a new starter locked out. Urgency and sympathy are the levers; native-English callers make the pretext land.
- Convert the reset into control. The password reset alone is often not the prize — the MFA re-enrollment is. Once the attacker's device is the registered second factor, the account's protection now works for the intruder.
- Move before anyone notices. With SSO, one reset opens email, VPN, admin consoles and cloud tenants at once. From there the playbook looks like any modern intrusion: session theft, privilege escalation, data exfiltration, often ransomware.
Note the mirror image of the classic tech support scam: there, the attacker pretends to be the help desk and calls the employee. Here, the attacker pretends to be the employee and calls the help desk. Mature programs simulate and defend against both directions.
Three breaches that started at the service desk
| Incident | How the desk was beaten | Reported cost |
|---|---|---|
| MGM Resorts (Sep 2023) | Attackers reportedly identified an employee on LinkedIn and phoned the help desk to obtain access; casino operations and hotel systems were disrupted for days | ~$100M hit to Q3 results |
| Clorox (Aug 2023) | Callers linked to Scattered Spider asked the outsourced service desk for password and MFA resets — and, per the lawsuit, received them without identity verification | $380M sought from the provider, incl. ~$49M remediation |
| M&S and Co-op (Apr–May 2025) | Attackers impersonated employees to IT help desks to obtain resets; the UK NCSC responded with sector-wide guidance | ~£300M estimated impact on M&S operating profit |
The Clorox complaint is worth reading because it reproduces the failure verbatim. Describing the calls in which agents reset credentials for the attacker, it states:
"At no point during any of the calls did the Agent verify that the caller was in fact Employee 1." — Clorox v. Cognizant complaint, July 2025
After the UK retail attacks, the NCSC's advice was equally blunt: review "how the helpdesk authenticates staff members' credentials before resetting passwords, especially those with escalated privileges."
Why good agents hand over credentials
Blaming individual agents misses the design flaw. Service desks are measured on speed, ticket closure and caller satisfaction — every metric rewards helping the caller and none rewards refusing them. Knowledge-based verification questions were chosen for convenience decades ago and have been hollowed out by OSINT and breach data since. Outsourcing adds a contractual gap: the client assumes verification happens, the provider follows whatever script was agreed years earlier, and nobody tests the path an attacker would actually take. The result is a process where the attacker's script is rehearsed and the defender's script is not.
There is also an asymmetry of sympathy. An agent who challenges a "stressed executive locked out before a flight" risks a complaint; an agent who quietly resets the credential risks nothing visible. Until the organization makes verification a defended, praised behavior — the same way reporting a phishing email is praised — agents will keep resolving that tension in the attacker's favor.
Hardening the reset path
The goal is not to make the help desk unfriendly. It is to make identity verification as strong as the assets behind it, and to make the high-risk operations — MFA changes, privileged accounts — deliberately slower than the routine ones.
- Tier requests by blast radius. A standard user's password reset and a domain admin's MFA re-enrollment should not share a workflow. Define the high-risk tier explicitly: privileged accounts, executives, finance roles, and any request that touches MFA or account recovery.
- Replace knowledge with possession and liveness. Drop verification questions an outsider can research. Verify by calling the employee back on the number already in the HR system, by live video with company ID for sensitive requests, or by manager/in-person confirmation for the privileged tier. Assume anything on LinkedIn or in a breach dump is known to the caller.
- Slow down MFA changes on purpose. Re-enrollment should trigger notification to the account owner on every registered channel, a short enforced delay, and supervisor approval for the high-risk tier. A real employee tolerates an hour's wait; an attacker's window usually doesn't. Where SIM swapping is a concern, remove SMS from the recovery path entirely.
- Give agents a safe refusal. Script the escalation path, and make it policy that no caller — however senior they claim to be — can waive verification. Celebrate blocked attempts publicly. An agent who says "I can't reset this without callback verification" should be a success story, not a complaint ticket.
- Treat reset activity as detection telemetry. Alert on resets followed by new-device sign-ins, unusual-hours requests, repeated failed verification, and clusters of calls against one department. If a reset does slip through, the response is an identity containment problem — sessions, passwords, MFA devices, OAuth grants — covered in our incident response playbook for social-engineering attacks.
- Test the desk like you test your inbox. Authorized simulated attacker calls against the service desk — including any outsourced provider, with contractual cover — reveal whether the procedure survives a rehearsed pretext. Fold the results into role-level risk data alongside phishing and MFA fatigue simulations, so exposure at the desk shows up in your Human Risk Score rather than in your incident postmortem.
Measure the desk, not just the users
Most programs measure employee click rates but have no number for the service desk at all. Track verification pass rate on simulated calls, the share of resets completed with strong verification, time-to-notify on MFA changes, and reported suspicious calls per quarter. Those metrics tell you whether the reset path is closing — and they give agents the same feedback loop that phishing simulations give everyone else. The organizations in the table above did not lack MFA, EDR or budget. They lacked a service desk that could tell an employee from a stranger with a good story. That is a fixable problem, and it is fixable this quarter.
Frequently asked questions
What is a help desk impersonation attack?
A help desk impersonation attack is a social engineering technique in which an attacker phones an organization's IT service desk pretending to be a legitimate employee — often one researched in advance on LinkedIn and in breach data — and persuades the agent to reset the employee's password or re-enroll their MFA device. Because the desk hands over a working credential and a working second factor, the attacker walks straight through controls that would have stopped a conventional phishing attempt. CISA attributes exactly this technique to the Scattered Spider intrusions.
How do attackers get past MFA in these attacks?
They don't bypass MFA — they replace it. The caller asks the help desk to reset both the password and the registered MFA token, claiming a lost or broken phone. Once the agent enrolls the attacker's device as the new second factor, every subsequent MFA challenge is answered by the attacker. This is why MFA re-enrollment should be treated as a higher-risk operation than a password reset, with stronger verification, a notification to the account owner, and a review of sign-ins that follow it.
What should a help desk require before resetting a password or MFA token?
Verification that public information cannot beat. Employee ID, date of birth, manager name and answers to security questions are all discoverable through OSINT and breach data, so they should not be sufficient on their own. Stronger options include calling the employee back on the phone number already on file, live video verification against a company ID for sensitive requests, in-person or manager-confirmed verification for privileged accounts, and a deliberate delay plus user notification on any MFA re-enrollment. The UK NCSC explicitly advises reviewing how the desk authenticates staff before resets, especially for accounts with escalated privileges.
Are outsourced help desks a bigger risk?
They can be, not because outsourced agents are less capable, but because verification procedures often live in a contract nobody tests. Clorox's lawsuit against its service desk provider alleges agents reset credentials without performing any of the agreed identity checks. If a third party answers your reset calls, the verification procedure needs to be explicit in the contract, trained on both sides, covered by call audits, and tested with simulated attacker calls — the same way you would test your own staff with phishing simulations.
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo