Help Desk Fraud
Help desk fraud is a social engineering attack where a caller impersonates an employee to trick the IT service desk into resetting passwords or MFA.
Help desk fraud — also called help desk impersonation or service desk social engineering — is a vishing-style attack in which the attacker phones an organization's IT service desk pretending to be a legitimate employee and persuades the agent to reset the account's password, enroll a new MFA device, or both. It is the mirror image of the tech support scam: instead of impersonating IT to trick an employee, the attacker impersonates an employee to trick IT.
How it works
The caller first builds a convincing identity from public sources — LinkedIn for the target's role, manager and start date, breach dumps for personal details like date of birth or employee ID. Armed with that pretext, they call the desk with a plausible emergency: a lost phone, a broken laptop, an urgent deadline. Because most desks verify identity with exactly the kind of knowledge-based questions this research defeats, the agent resets the credential and often re-enrolls the attacker's own device as the new MFA factor. In single sign-on environments, that one reset opens email, VPN, and cloud consoles simultaneously. CISA attributes this technique to the Scattered Spider intrusions behind the MGM Resorts outage, and the same pattern appears in the Clorox–Cognizant lawsuit and the 2025 attacks on UK retailers M&S and Co-op.
How to defend against it
Replace researchable verification questions with checks an outsider cannot pass: call the employee back on the number already in the HR system, require live video with company ID for sensitive requests, and add manager approval plus an enforced delay for privileged accounts and any MFA re-enrollment. Notify the account owner on every registered channel when a reset happens, and alert on resets followed by new-device sign-ins. Finally, test the desk with authorized simulated attacker calls — including outsourced providers — and feed the results into an employee- and team-level Human Risk Score. Our guide to help desk impersonation attacks covers the full defense playbook, with the MGM, Clorox and M&S case studies.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo