By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: TrusonaPublished September 5, 2025

TL;DR: Traditional MFA fails when attackers bypass the second factor through help desk social engineering, MFA fatigue, vishing, or SIM swapping, according to Trusona’s analysis. The real control boundary is identity verification and reset governance, because a strong authenticator cannot save a weak recovery process.


At a glance

What this is: This is an analysis of why traditional MFA breaks down against Scattered Spider’s social engineering, especially when help desk reset processes can be manipulated.

Why it matters: It matters because IAM teams cannot treat MFA as a standalone control if account recovery, device enrollment, and help desk authentication remain exploitable paths into human and high-privilege accounts.

By the numbers:

  • Obsidian Security notes that attackers have figured out ways to subvert MFA in 70% of SaaS breaches.

👉 Read Trusona's analysis of why traditional MFA fails against Scattered Spider


Context

Traditional MFA is not the same as resilient identity verification. If an attacker can persuade a help desk agent to reset a factor, enroll a new device, or send a reset link to a different channel, the second factor becomes a process weakness rather than a control.

This is a human identity problem first, but it also affects privileged access governance, because the most damaging resets often involve accounts with broad access. The article’s core point is that social engineering turns recovery workflows into the real attack surface, which is where IAM programmes usually have the least discipline.

Scattered Spider demonstrates a broader pattern that extends beyond one group. The same weaknesses appear anywhere security teams trust knowledge-based verification, unmanaged callback paths, or discretionary help desk approvals, and that makes the starting position more common than many organisations want to admit.


Key questions

Q: How should security teams handle MFA resets and account recovery?

A: Treat MFA resets and account recovery as privileged actions. Require out-of-band verification, enforce approval for high-risk changes, and log them as security events that trigger follow-up monitoring. If the recovery process is easy to socially engineer, it becomes an attacker entry point rather than a resilience control.

Q: Why do traditional MFA controls fail against social engineering campaigns like Scattered Spider?

A: Traditional MFA fails when the factor can be redirected, coerced, or socially engineered. Push fatigue, SIM swap, and one-time code theft all exploit the fact that possession is not proof of the real user. Phishing-resistant authentication reduces this risk because the challenge is bound to the legitimate identity registration and cannot be reused by a caller.

Q: What do teams get wrong about phishing-resistant MFA?

A: They often measure success by the presence of a strong factor instead of the absence of weaker bypasses. A deployment can include passkeys and still be vulnerable if users can fall back to OTP, push approval, or password reset. Governance should focus on reachable paths, not just enrolled methods.

Q: Who is accountable when a help desk reset leads to account takeover?

A: Accountability sits with the organisation that owns the recovery process, not just the individual agent who approved the action. Security, IAM, and service owners should define the controls, evidence standards, and escalation paths before resets can restore trust. If the process can be abused, the process owner owns the risk.


Technical breakdown

Why help desk resets defeat traditional MFA

Traditional MFA assumes the second factor is controlled by the legitimate user and can only be changed through a trustworthy recovery process. Scattered Spider abuses that assumption by targeting help desk workflows, where agents may rely on caller confidence, partial personal data, or informal overrides. Once the attacker convinces the agent to remove or replace the factor, the authentication chain is no longer defending the account. In practice, the reset path becomes more important than the login path, because that is where the attacker obtains a fresh valid factor.

Practical implication: treat MFA recovery as a privileged workflow, not an administrative convenience.

How MFA fatigue and vishing turn people into the control plane

MFA fatigue works because repeated push prompts create user exhaustion, while vishing works because a convincing voice can pressure both users and help desk staff into bypassing procedure. Generative AI makes impersonation cheaper and more credible by enabling voice cloning and scripted urgency. These attacks do not break the cryptography behind MFA. They break the human decision point that authorises the factor. That means the effective control is not the token itself but the quality of the verification and approval process around it.

Practical implication: remove discretionary approval steps and replace them with verifiable, auditable identity proofing.

Why SMS and delegated enrollment remain weak recovery channels

SMS and email are brittle recovery channels because both can be intercepted, redirected, or socially engineered. SIM swapping can move a phone number to the attacker, while delegated enrollment lets an attacker convince a help desk agent to send a reset flow to an attacker-controlled address or device. In both cases, the control failure is the same: the organisation trusts a channel that is easy to transfer without proving continuing identity. That is why phishing-resistant authenticators and stronger recovery checks matter together, not separately.

Practical implication: stop treating recovery channels as equivalent to identity proof and review every delegated enrollment path.


Threat narrative

Attacker objective: The attacker wants to turn a help desk interaction into durable account takeover and then use that access for broader intrusion.

  1. Entry begins with the attacker gathering personal data from social media, breaches, and internal directories to support impersonation.
  2. Credential access occurs when the attacker uses help desk social engineering, MFA fatigue, vishing, or SIM swapping to obtain a valid second factor or reset path.
  3. Impact follows when the attacker takes over the account, resets the password, and gains access to enterprise systems, including privileged environments.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Traditional MFA fails when recovery is weaker than authentication. The article shows that the real control boundary is not the login ceremony but the reset ceremony. If help desk staff can be manipulated into replacing a second factor, MFA becomes a recoverable inconvenience rather than a security control. Practitioners should treat factor recovery as part of the authentication lifecycle, not as an administrative side door.

Identity proofing, not factor volume, is what separates secure MFA from exposed MFA. Adding SMS, push, and email channels does not fix the underlying problem if the organisation still trusts verbal callbacks and knowledge-based checks. The failure mode is a verification model built for convenience, not adversarial pressure. Teams need to reclassify reset workflows by risk, because the highest-value accounts are also the easiest social targets.

Scattered Spider is a help desk governance failure as much as a phishing campaign. The attacker does not need to defeat cryptography when the organisation allows human agents to override process under pressure. That makes help desk scripts, callback verification, and escalation rules part of identity security, not support operations. The implication is that IAM and service desk governance must be managed as one control plane.

Phishing-resistant MFA only works when the surrounding process is equally resistant. FIDO2 and hardware-bound authenticators reduce replay risk, but they do not eliminate reset abuse if recovery still routes through weak channels. The article reinforces a broader NHI and human IAM lesson: the stronger the authenticator, the more damaging a weak offboarding or reset process becomes. Practitioners should align authenticator strength with recovery assurance.

Help desk discretion is an identity risk multiplier. Any process that lets an agent decide, under pressure, whether a reset is legitimate creates a high-leverage attack surface. The problem is not just malicious callers but the variability of human decision-making across shifts, locations, and support tiers. Security teams should assume that discretionary recovery will eventually be targeted, and plan controls accordingly.

From our research:

  • 64% of valid secrets leaked in 2022 are still valid and exploitable today, according to the State of Secrets Sprawl 2026.
  • AI-related credential leaks surged 81.5% year-over-year in 2025, and the surrounding AI infrastructure leaked 5x faster than core LLM providers.
  • That pattern reinforces the need to pair stronger recovery governance with the Guide to the Secret Sprawl Challenge when credentials and identity proofing both become attack targets.

What this signals

Help desk recovery is now part of the identity attack surface. Organisations that still separate IAM from service desk operations will continue to miss the real control failure point, which is factor reissuance. With 70% of SaaS breaches already involving MFA subversion, the governance gap is structural rather than tactical, and support workflows need the same scrutiny as privileged access processes.

The named concept here is recovery-path abuse: when the attacker cannot break MFA directly, they target the workflow that replaces it. That shifts programme design away from stronger prompts and toward stronger proofing, tighter callbacks, and more visible escalation controls. Teams should expect this to matter more, not less, as voice cloning and support automation make impersonation easier.


For practitioners

  • Reclassify MFA recovery as privileged access Put reset and device enrollment workflows under the same governance standards as high-risk administrative access, including approval rules, logging, and periodic review.
  • Require secure identity proofing for resets Use verified app-based proofing, liveness checks, or equivalent controls before changing a factor or sending a reset link to any new channel.
  • Eliminate discretionary help desk bypasses Remove informal exceptions, verbal approvals, and ad hoc manager overrides from factor reset procedures, especially for privileged accounts.
  • Harden callback and enrollment channels Restrict resets to numbers and devices already on file, and block delivery of reset links to unverified phone numbers or email addresses.
  • Instrument reset abuse detection Alert on repeated MFA resets, unusual support-call patterns, and rapid factor replacement across the same user population.

Key takeaways

  • Scattered Spider succeeds by attacking MFA recovery, not the cryptography behind MFA.
  • Help desk resets, callback practices, and delegated enrollment are the control points that determine whether MFA actually holds.
  • Security teams should govern recovery as privileged access and measure it with the same rigor as authentication.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Help desk resets and factor reissue map directly to identity verification weaknesses.
NIST CSF 2.0PR.AC-1The article is about authenticating users and controlling account recovery paths.
NIST SP 800-53 Rev 5IA-5IA-5 governs authenticator management, including issuance and reset lifecycle.
NIST Zero Trust (SP 800-207)Reset workflows should never assume trust based on the caller alone.

Review recovery workflows under PR.AC-1 and remove discretionary reset paths for sensitive accounts.


Key terms

  • Help Desk Social Engineering: Help desk social engineering is the manipulation of support staff into approving or performing an access action without proper verification. Password resets are a common target because attackers exploit urgency, confusion, and inconsistent procedures to bypass stronger controls elsewhere in the identity stack.
  • Identity proofing: The process of verifying that a person is who they claim to be before granting or restoring access. In higher-risk recovery paths, proofing can include stronger evidence checks such as government ID validation or liveness-based facial verification so the assurance level matches the sensitivity of the request.
  • Phishing-Resistant MFA: Phishing-resistant MFA uses authentication factors that cannot be easily replayed, intercepted, or socially engineered. In regulated environments, this usually means device-bound or cryptographic methods rather than push prompts or SMS codes, because the control must hold up under realistic attack conditions.
  • Recovery path abuse: The exploitation of password reset, callback, account recovery, or support workflows after a victim has already been socially engineered. These paths are often treated as administrative, but they can become the final trust handoff that turns deception into real loss. They need the same scrutiny as primary authentication.

What's in the full article

Trusona's full blog covers the operational detail this post intentionally leaves for the source:

  • Step-by-step identity proofing workflow for help desk reset requests and factor enrollment.
  • Specific guidance on callback controls, approval routing, and denial conditions for risky reset requests.
  • Examples of phishing-resistant MFA patterns and device-bound recovery flows used to reduce support abuse.
  • Process recommendations for training support staff to resist urgency, impersonation, and MFA fatigue.

👉 Trusona's full post covers help desk bypass tactics, reset governance, and verification-first controls.

Deepen your knowledge

NHI governance, machine identity security, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org