TL;DR: Voice-based social engineering, public OSINT, and help desk workflow abuse can combine to defeat knowledge-based verification, according to Trusona’s breakdown of Scattered Spider, with CrowdStrike reporting the group used help desk voice impersonation in almost all observed Q2 2025 incidents. The lesson is that identity proofing built on public answers cannot withstand modern impersonation campaigns.
NHIMG editorial — based on content published by Trusona: The Scattered Spider Field Manual: How They Pick Targets, Build Profiles, and Make the Call
By the numbers:
- CrowdStrike said Scattered Spider used help desk voice-based social engineering in almost all observed incidents during Q2 2025.
- Brightside AI found that over 95% of executive profiles on data broker sites contain information about family members and colleagues.
- Pindrop documented a 680% year-over-year increase in deepfake voice activity.
Questions worth separating out
Q: How should organisations secure help desk password reset workflows against impersonation?
A: Use device-bound or cryptographic verification for all high-risk recovery events, and remove approval authority from the same agent who receives the call.
Q: Why do public employee details make social engineering against IAM teams easier?
A: Because attackers can build convincing pretexts from information that is already exposed in LinkedIn profiles, corporate bios, conference footage, and data broker records.
Q: What breaks when MFA recovery is handled by the same team that grants account resets?
A: The boundary between identity proofing and authentication state changes collapses.
Practitioner guidance
- Replace knowledge-based recovery with device-bound verification Require proof through an enrolled device or strong out-of-band method before any password reset, MFA change, or account unlock is approved.
- Separate recovery authority from privilege change Make sure help desk staff can initiate recovery without being able to complete MFA removal, factor enrolment, or privileged account changes on the same call.
- Review every public-answer recovery question Remove questions based on LinkedIn data, executive bios, office location, travel status, or manager names because attackers can research those inputs before calling.
What's in the full article
Trusona's full blog covers the operational detail this post intentionally leaves for the source:
- The full phase-by-phase Scattered Spider field manual, including target selection, OSINT gathering, call timing, and post-access movement.
- Concrete examples of how the group uses help desk workflows, MFA resets, and token enrolment to convert social engineering into access.
- Referenced incident context across M&S, MGM, Caesars, Co-op, and Harrods, useful for teams mapping this pattern to their own environment.
- The source article's disruption indicators and control observations, which give practitioners a deeper view of where the attack chain can be interrupted.
👉 Read Trusona's field manual on Scattered Spider social engineering and identity abuse →
Scattered Spider’s playbook: what help desk teams are still missing?
Explore further
Help desk recovery has become an identity trust boundary, not a back-office process. This attack pattern works because organisations still treat credential recovery as operational support rather than privileged identity decision-making. Once a reset can unlock MFA, federation, or administrator paths, the service desk becomes part of the IAM control plane. Practitioners must recognise that recovery workflows are now as security-critical as primary authentication.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to Ultimate Guide to NHIs.
A question worth separating out:
Q: Who is accountable when a support workflow leads to identity compromise?
A: Accountability usually spans IAM, service desk leadership, security operations, and the business owner of the affected system. If the support channel can restore access without strong proofing, the issue is governance, not just a single user error. Frameworks that emphasise access control and operational resilience should be mapped to the reset and recovery process.
👉 Read our full editorial: Scattered Spider shows why help desk identity verification fails