Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Scattered Spider’s help-desk tactics: what IAM teams need to fix


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: Scattered Spider’s attacks succeed by using vishing, MFA fatigue, and help-desk manipulation to reset credentials and enroll new devices, allowing legitimate account takeover without malware, according to Trusona. The pattern shows that human verification workflows, not just MFA, remain a weak point when high-privilege access can be reassigned by social engineering.

NHIMG editorial — based on content published by Trusona: Scattered Spider's Playbook: What Every CISO Needs to Know

By the numbers:

Questions worth separating out

Q: How should security teams handle MFA resets and account recovery?

A: Treat MFA resets and account recovery as privileged actions.

Q: Why do social engineering attacks still bypass strong MFA programs?

A: Strong MFA can still fail if attackers can reset the factor through support channels or exhaust users with push prompts.

Q: What do security teams get wrong about help desk verification?

A: They often treat it as a service procedure instead of an identity control.

Practitioner guidance

  • Tier identity recovery by privilege level Apply stronger verification, manager approval, or multi-party approval for resets involving administrators, executives, and other high-risk accounts.
  • Remove knowledge-based authentication from support workflows Replace security questions and caller-ID trust with out-of-band verification tied to authoritative identity records.
  • Log and review all MFA re-enrollment events Treat authenticator replacement as a high-risk identity change and monitor it the same way you would privileged group membership changes.

What's in the full article

Trusona's full blog covers the operational detail this post intentionally leaves for the source:

  • The specific help-desk attack scripts described in the article, including impersonation, vishing, and MFA fatigue patterns.
  • The defensive workflow examples for strong identity proofing, call-backs, and approval gates on recovery requests.
  • The incident references and loss estimates tied to MGM Resorts and Caesars Entertainment.
  • The practical recommendations for zero-trust-style verification in support operations.

👉 Read Trusona's analysis of Scattered Spider's help-desk social engineering playbook →

Scattered Spider’s help-desk tactics: what IAM teams need to fix?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Help-desk recovery is an identity issuance function, not a clerical one. Scattered Spider succeeds because organisations still treat password resets and MFA re-enrollment as routine support tasks rather than privileged trust decisions. The moment support staff can change authenticators, they are effectively issuing access. That makes recovery governance as important as initial authentication, especially for executive and administrator accounts.

A few things that frame the scale:

  • 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to the Ultimate Guide to NHIs.
  • 91.6% of secrets remain valid five days after the targeted organisation is notified, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Who is accountable when a help-desk reset is abused in an identity attack?

A: Accountability sits with the governance chain that failed to preserve verified workflow evidence, not just the analyst who saw the alert. Security, IAM, and service-desk owners all need a documented control path for ticket linkage, approval proof, and reset validation. If the evidence is missing, the organisation cannot prove the reset was legitimate.

👉 Read our full editorial: Scattered Spider’s help-desk playbook exposes human IAM gaps



   
ReplyQuote
Share: