Join our Newsletter — 33% off our NHI Course

Help desk scams and MFA resets: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Help desk scams let attackers reset credentials, bypass MFA, and take over privileged accounts, with Scattered Spider-linked campaigns tied to major retail and insurance disruptions according to Push Security. The core problem is that many help desk workflows still assume identity proofing can survive social engineering and high-pressure impersonation.

Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “Scattered Spider: Understanding help desk scams and how to defend your organization”.

Key questions

Q: What breaks when help desk resets are treated as low-risk support tasks?

A: The reset path becomes a privileged access channel that attackers can target through social engineering.

Q: Why do help desk scams work so well against privileged accounts?

A: They work because many organisations use one reset process for everyone, even though a privileged account carries far more blast radius.

Q: What are the signs that a help desk social engineering attack is in progress?

A: Warning signs usually appear as a suspicious chain of events rather than a single alert.

Practitioner guidance

  • Separate privileged resets from standard support Create a distinct, higher-friction recovery path for admin and high-risk accounts, with explicit escalation and denial authority.
  • Require step-up verification for recovery Use stronger verification when a request affects MFA enrollment, password reset, or device replacement for sensitive identities.
  • Add multi-party approval for admin recovery Force a second human approval before any reset that would restore access to privileged, finance, or infrastructure accounts.

Bottom line: Help desk scams succeed when recovery workflows trust the requester more than the account risk, turning support into an access control weakness.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 22 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Help desk recovery has become a privilege boundary, not a support function. The article shows that reset workflows can hand attackers the exact control plane meant to restore legitimate access. That means identity recovery is now part of the attack surface, especially when the same process applies to both ordinary and privileged users. Practitioners should treat recovery as a governed security control with explicit risk tiers.

A few things that frame the scale:

A question worth separating out:

Q: How should organisations balance help desk usability and account security?

A: They should preserve speed for low-risk requests but introduce friction, escalation, and denial authority when the request affects privileged access or MFA re-enrolment. The goal is not to make support unusable. It is to make socially engineered recovery materially harder than legitimate recovery for high-value identities.

👉 Read our full editorial: Help desk scams are the gateway to privileged account takeover


This post was modified 22 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.