Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Help desk identity verification gaps: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: Scattered Spider’s help desk attacks show that social engineering can bypass mature infrastructure when identity verification is weak, according to Trusona’s analysis of MGM, Caesars, and related tactics. The real exposure is the control assumption that a caller can be trusted based on knowledge checks, callback routines, or voice alone; that model no longer holds.

NHIMG editorial — based on content published by Trusona: The 9 Questions Your IT Help Desk Should Be Able to Answer (And the One That’s a Trap)

By the numbers:

  • Gen AI voice cloning costing less than $10 has made convincing impersonation tools broadly accessible.
  • The FBI recorded $26 million in SIM swap losses in the US in the same period.

Questions worth separating out

Q: How should security teams verify callers before help desk account changes?

A: They should use real-time authoritative identity verification tied to the live session, not security questions or caller intuition.

Q: Why do knowledge-based authentication checks fail in help desk workflows?

A: KBA fails because the underlying facts are often available through breaches, brokers, or public sources, and Gen AI can help answer them convincingly.

Q: What breaks when help desk teams rely on phone numbers to confirm identity?

A: Phone-based confirmation breaks when attackers perform SIM swaps or control the caller’s number through a compromised carrier relationship.

Practitioner guidance

  • Replace knowledge-based authentication Remove security questions, shared secrets, and biographical checks from help desk recovery for high-risk actions.
  • Introduce real-time telephony risk checks Check for SIM swap signals, number portability anomalies, and device-context mismatch before accepting a caller as verified.
  • Bind support actions to verified sessions Require the identity proof event to be tied to the live verification session and the requesting device.

What's in the full article

Trusona's full blog covers the operational detail this post intentionally leaves for the source:

  • The full nine-question help desk assessment with the weighting behind each critical control.
  • The vendor’s example identity verification flow showing how live verification is expected to work in practice.
  • The stated capabilities for SIM swap detection, GPS checks, and anti-replay protections that support the assessment model.
  • The scoring logic that maps help desk answers to Identity Verification, Process Controls, and Infrastructure Defense.

👉 Read Trusona's analysis of help desk identity verification and Scattered Spider risk →

Help desk identity verification gaps: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Help desk identity verification is a frontline IAM control, not a service courtesy. When a support agent can change access based on a persuasive call, the enterprise has delegated identity assurance to the least trustworthy channel in the workflow. That makes help desk operations part of the privileged access path, not just a user experience layer. The implication is that human identity governance must treat support verification as enforceable control, not etiquette.

A few things that frame the scale:

A question worth separating out:

Q: Who is accountable when a help desk scam leads to account takeover?

A: Accountability is shared across identity, support, and application owners. The help desk owns the verification process, IAM owns the policy for resets and MFA changes, and application owners own whether direct login paths and recovery flows are too permissive. If any one of those layers is weak, a scam can turn into an enterprise-wide access event.

👉 Read our full editorial: Help desk identity verification gaps are fueling social engineering risk



   
ReplyQuote
Share: