← All terms

Help Desk Fraud

Help desk fraud is a social engineering attack where a caller impersonates an employee to trick the IT service desk into resetting passwords or MFA.

Help desk fraud — also called help desk impersonation or service desk social engineering — is a vishing-style attack in which the attacker phones an organization's IT service desk pretending to be a legitimate employee and persuades the agent to reset the account's password, enroll a new MFA device, or both. It is the mirror image of the tech support scam: instead of impersonating IT to trick an employee, the attacker impersonates an employee to trick IT.

How it works

The caller first builds a convincing identity from public sources — LinkedIn for the target's role, manager and start date, breach dumps for personal details like date of birth or employee ID. Armed with that pretext, they call the desk with a plausible emergency: a lost phone, a broken laptop, an urgent deadline. Because most desks verify identity with exactly the kind of knowledge-based questions this research defeats, the agent resets the credential and often re-enrolls the attacker's own device as the new MFA factor. In single sign-on environments, that one reset opens email, VPN, and cloud consoles simultaneously. CISA attributes this technique to the Scattered Spider intrusions behind the MGM Resorts outage, and the same pattern appears in the Clorox–Cognizant lawsuit and the 2025 attacks on UK retailers M&S and Co-op.

How to defend against it

Replace researchable verification questions with checks an outsider cannot pass: call the employee back on the number already in the HR system, require live video with company ID for sensitive requests, and add manager approval plus an enforced delay for privileged accounts and any MFA re-enrollment. Notify the account owner on every registered channel when a reset happens, and alert on resets followed by new-device sign-ins. Finally, test the desk with authorized simulated attacker calls — including outsourced providers — and feed the results into an employee- and team-level Human Risk Score. Our guide to help desk impersonation attacks covers the full defense playbook, with the MGM, Clorox and M&S case studies.

Full guide
Read the deep dive on this attack →

Related terms

Tech Support ScamA tech support scam impersonates IT or vendor support to gain remote access or payment, often via fake virus pop-ups, cold calls, or search ads.PretextingPretexting is a social engineering technique where the attacker creates a fabricated scenario to gain the victim's trust and extract information or access.VishingVishing (voice phishing) is a social engineering attack conducted over phone calls to manipulate victims into revealing sensitive information or taking harmful actions.MFA Fatigue AttackAn MFA fatigue attack bombards a user with repeated multi-factor authentication push notifications until they approve one out of frustration or confusion.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo