TL;DR: 69% of organisations experienced an identity-related breach in the last three years, 24% saw breach costs above $10M, and 90% still face passwordless adoption challenges as help desk hijacks intensify, according to RSA Security’s 2026 ID IQ Report. Identity governance now fails at the recovery and support layers, not just at login.
At a glance
What this is: RSA Security’s 2026 ID IQ Report shows identity breaches, help desk hijacks, and passwordless adoption friction are converging into a broader IAM control problem.
Why it matters: IAM, IGA, and PAM teams need to treat account recovery and service desk processes as high-risk identity controls, not operational support tasks.
By the numbers:
- 69% of organisations experienced an identity-related breach in the last three years.
- 24% of organisations said identity-related breach costs exceeded $10M.
- 90% of organisations reported challenges in moving toward passwordless authentication.
Context
Identity security now fails in the places many programmes still treat as operational support, especially the help desk and account recovery flow. When attackers can persuade support staff to reset credentials or bypass checks, the identity system stops being a gate and becomes a shortcut.
RSA Security’s report frames that failure as a growing breach driver rather than a narrow authentication problem. The core issue is not simply whether organisations adopt passwordless, but whether they can govern identity recovery, service desk escalation, and access restoration with the same rigour as primary authentication.
Key questions
Q: What breaks when the help desk becomes an authentication back door?
A: The main failure is that identity proofing becomes weaker at the exact point where attackers can influence a human operator. If support staff can reset credentials, approve recovery, or override checks too easily, the attacker does not need to defeat the primary login method. They only need to persuade the support process to vouch for them.
Q: Why do passwordless programmes still get compromised through recovery paths?
A: Because passwordless improves the login step, not every way identity is re-established. If users or help desks can reset access through weaker questions, informal validation, or alternate channels, attackers will target those paths instead of the primary factor.
Q: How can security teams tell whether identity breach risk is improving?
A: Look beyond enrollment numbers and check whether support-mediated actions are shrinking, harder to complete, and more heavily logged. A programme is improving when resets, unlocks, and manual overrides are rare, high-friction, and tightly governed. If those actions remain common, the identity perimeter is still soft.
Q: Who should own account recovery risk in an identity programme?
A: Recovery risk should be owned jointly by IAM, service desk leadership, and security governance. Authentication is not complete until recovery is controlled, so the accountable team must cover the full identity journey, including fallback access, verification rules, and support approvals.
Technical breakdown
Why help desk bypass works as an identity control failure
Help desk bypass attacks target the trust relationship between a caller and the support process. Instead of breaking cryptography, attackers exploit weak identity proofing, scripted verification, or over-permissive reset workflows to get a legitimate action performed on their behalf. That makes the service desk part of the authentication surface. Once a reset or account recovery path is abused, the attacker inherits the trust of the original identity without defeating the login flow itself. In practice, the weak point is often the recovery channel, not the password or passkey mechanism.
Practical implication: treat account recovery and support escalation as privileged identity flows with stronger verification than normal login.
Why passwordless does not remove recovery risk
Passwordless authentication reduces exposure to reusable passwords, but it does not eliminate identity recovery paths, device replacement, or support-mediated restoration. Every passwordless programme still needs a way to re-establish trust when a user loses a device or cannot complete an authenticator step. That means attackers can shift from credential theft to recovery abuse if those processes are weaker than the primary authentication method. The control problem moves from secret protection to recovery assurance and support-channel resistance.
Practical implication: design passwordless rollouts alongside recovery governance, not as a standalone authentication change.
How identity breaches translate into higher loss
Identity compromise often provides an attacker with broad, trusted access early in the intrusion, which shortens the path to data theft, privilege escalation, and extortion. That is why identity-related incidents frequently become expensive quickly: the attacker is not working around controls, but through them. The report’s cost data reinforces that identity failure affects both containment speed and blast radius. In governance terms, the breach cost reflects how much authority the compromised identity could reach before detection or revocation caught up.
Practical implication: map breach cost exposure to the privilege and recovery paths an identity can reach before containment.
Threat narrative
Attacker objective: The attacker wants legitimate identity access that bypasses normal authentication controls and opens a path to data theft, disruption, or extortion.
- Attackers begin with social engineering or support abuse aimed at the help desk, where weak verification can turn a request into a trusted identity action.
- They obtain or reset access through the service desk process, which gives them legitimate credentials or session access without breaking primary authentication.
- With that access, they move to data access, privilege expansion, or fraud actions that create the breach impact and associated cost.
Breaches seen in the wild
- Co-op cyber attack 2025: Attackers linked to Scattered Spider tricked their way into a Co-op employee account and stole personal data of all 6.5 million members.
- Caesars Entertainment breach 2023: Social engineering of an IT support vendor let attackers copy Caesars loyalty database; about $15 million was reportedly paid.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Help desk governance has become part of the identity perimeter: The report confirms that the most consequential identity failures increasingly happen in support workflows, not only in primary authentication. That changes the programme boundary for IAM, PAM, and IGA teams, because recovery and reset processes can now determine breach likelihood as much as credential policy. Organisations that still treat the service desk as a back-office function are leaving a control gap in the middle of the identity stack.
Passwordless adoption does not solve recovery assurance: The article shows that 90% of organisations still face passwordless challenges, but the deeper issue is the trust model behind fallback and recovery. Passwordless removes one class of secret, yet it does not remove the need to re-establish identity when a user is locked out or a device is lost. The implication is that passwordless maturity should be judged by recovery assurance, not enrollment alone.
Identity breach cost reflects privilege reach, not just entry: The 24% of organisations reporting losses above $10M shows that identity compromise can scale quickly once an attacker crosses a trusted boundary. That pattern is consistent with standing access, overbroad support permissions, and slow containment. The practical lesson is that identity governance must be measured by how far a compromised identity can travel before revocation and review interrupt the chain.
Support-channel abuse is now a repeatable threat pattern: The report’s concern about service desk bypass attacks shows this is no longer an isolated social engineering story. It is an identity operations failure mode that combines process trust, human judgment, and weak escalation controls. Security leaders should read this as a governance problem with measurable failure points, not as a one-off awareness issue.
Identity recovery trust debt: The strongest named concept in this report is the trust debt accumulated in reset and recovery workflows. Every exception, manual override, and weak proofing step creates future exposure that attackers can spend later. For practitioners, the question is not whether the login flow is hardened, but whether the recovery path is harder than the attacker's best social engineering route.
From our research library:
- 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to the Ultimate Guide to NHIs.
- Read next: Account Recovery and Help Desk Security Guide
What this signals
Support-channel abuse now belongs in the identity risk register: Organisations should treat the help desk as part of the authentication and recovery surface, because attackers increasingly target the human workflow that restores access. The strongest control signal is not whether a user can log in, but whether a recovery request can be abused faster than it can be challenged.
Passwordless maturity is a governance test, not a rollout milestone: Moving to passwordless changes the credential model, but it does not end identity compromise if fallback paths remain weak. Teams should measure how often support staff can still restore access manually, because that is where attack cost and operational risk often concentrate.
For practitioners
- Harden help desk verification Require stronger identity proofing for password resets, MFA resets, and device replacement requests than for ordinary sign-in flows. Remove script-only checks that attackers can rehearse and replace them with out-of-band or risk-based verification for high-impact account actions.
- Map recovery paths as privileged flows Document every account recovery route, escalation path, and manual override that can restore access. Assign ownership, approval requirements, and logging to each path so the support process is governed like a privileged access workflow.
- Test service desk resistance to social engineering Run controlled exercises against reset, unlock, and callback procedures to see whether staff can distinguish genuine users from persuasive attackers. Use the findings to remove ambiguous steps and tighten escalation rules.
- Measure passwordless success by recovery integrity Track how often passwordless users fall back to support-mediated recovery, how long those cases take, and how many require manual intervention. High fallback rates can indicate that the primary authentication change is outpacing governance.
Key takeaways
- Identity-related breaches are rising because attackers increasingly exploit support and recovery workflows, not only primary login controls.
- The report shows that breach costs can escalate quickly when compromised identity paths provide broad trusted access.
- The most effective response is to govern the help desk and recovery process as privileged identity infrastructure, not as a back-office convenience.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The report centres on bypassing identity verification through help desk and recovery workflows. |
| NHI-10 — Human Use of NHI | The report shows humans using support processes to restore or override identity trust in machine-mediated flows. | |
| Recommendation — Tighten recovery verification and remove weak support overrides that let attackers bypass authentication. Separate human-assisted recovery from automated identity issuance and log every manual exception. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Recovery, reset, and passwordless fallback are authenticator lifecycle concerns. |
| Recommendation — Apply authenticator management controls to resets, replacement, and fallback recovery paths. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Service desk actions can restore or expand entitlements without strong governance. |
| Recommendation — Limit who can restore access and require approvals for privileged recovery actions. | ||
| MITRE ATT&CK | TA0006;TA0004 — Credential Access; Privilege Escalation | Help desk hijacks commonly start with credential access and can end in elevated access. |
| Recommendation — Map support-driven identity compromise to credential access and privilege escalation detections. | ||
Key terms
- Help Desk Hijack: A help desk hijack is when an attacker uses social engineering to get support staff to reset, re-enrol, or bypass identity controls. The tactic turns operational trust into access, making the support workflow part of the attack surface rather than a neutral service channel.
- Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
- Identity Recovery: Identity recovery is the process of restoring identity systems to a trusted state after compromise. It includes containment, forensic validation, removal of persistence, and confirmation that access controls and directory relationships no longer expose the environment.
- Support-Channel Trust: Support-channel trust is the assumption that a help desk or service desk can reliably verify a user and safely restore access. In mature IAM programmes, that trust must be deliberately constrained, logged, and periodically tested because the recovery channel can become a privileged attack surface.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org