Join our Newsletter — 33% off our NHI Course

Social engineering, MFA bypass, and the identity gap teams miss

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Recent UK retail breaches show how social engineering, SIM swapping, and help-desk compromise can still bypass traditional MFA and expose customer data, with Marks & Spencer losing more than $80 million in profit and $1.3 billion in market value, according to 1Kosmos and the BBC. The lesson is that identity programmes built on credentials and devices alone cannot withstand impersonation-driven access theft.

Editorial analysis by NHI Mgmt Group, based on content published by 1Kosmos: “‘Spider’ Strikes Britain: The Hacks at M&S, Co-Op & How to Stop Them”.

Practitioner guidance

  • Harden account recovery controls Require step-up verification, out-of-band approval, and fraud-resistant checks before any password reset, SIM change, or device rebind can complete.
  • Separate support from privilege administration Restrict help-desk staff from making identity state changes unless the request passes a higher assurance workflow with explicit escalation and audit.
  • Review supplier and telecom trust paths Inventory every third-party path that can alter user authentication state, then remove any route that can approve resets without verified business need.

Bottom line: Social engineering remains effective because attackers exploit the recovery and support layers around identity, not only the authentication factor itself.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 21 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Social engineering has become an identity-layer bypass, not just a fraud problem: The article shows that attackers are no longer trying to defeat MFA in the abstract. They are targeting the operational steps around identity verification, especially help desks, telecom providers, and reset workflows. That means identity governance has to treat recovery paths as part of the control plane, not as administrative afterthoughts. Practitioners should assume that any process able to rebind trust can also be weaponised.

👉 Read our full editorial: Social engineering and MFA bypass are still breaking enterprise identity


This post was modified 21 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.