Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Vishing plus AiTM phishing: what identity teams need to stop


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Vishing now routinely pairs with AiTM phishing to trick users into password resets, MFA approvals, or attacker-controlled page visits, and Push Security says these combined campaigns are being used to hijack SSO accounts across hundreds of organisations. The control problem is not just user awareness but browser-level detection, identity verification, and session-focused response.

NHIMG editorial — based on content published by Push Security: Vishing

By the numbers:

  • 2026, ce code phishing attacks have skyrocketed in 2026, enabling attackers to steal access tokens while bypassing standard access controls.

Questions worth separating out

Q: How should security teams reduce vishing-driven account takeover risk?

A: Start by treating voice verification as an access control, not a support courtesy.

Q: Why do AiTM phishing attacks remain effective against SSO environments?

A: Because they target the authenticated session, not only the password.

Q: What do security teams get wrong about help desk social engineering?

A: Many teams treat the help desk as a service function rather than a security boundary.

Practitioner guidance

  • Harden help desk identity verification Require out-of-band callback checks, step-up questions that are not publicly discoverable, and supervisor approval for high-risk resets or MFA recovery.
  • Instrument browser-session detection Monitor for suspicious redirects, unusual login page provenance, token replay indicators, and browser sessions that suddenly expand scope across SaaS applications.
  • Reduce MFA approval abuse Replace simple prompt approval where possible with phishing-resistant methods and enforce context-aware checks for high-risk resets, new devices, and impossible travel conditions.

What's in the full article

Push Security's full article covers the operational detail this post intentionally leaves for the source:

  • Specific examples of how voice phishing is paired with browser-based phishing to complete account takeover.
  • The attack flow from support impersonation to password reset, MFA approval, and session hijack.
  • Push's own browser-security telemetry examples for spotting suspicious identity activity earlier in the chain.
  • The article's campaign-level context on how these techniques are being used across identity-led attacks.

👉 Read Push Security's analysis of vishing and AiTM phishing account takeover →

Vishing plus AiTM phishing: what identity teams need to stop?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Vishing is no longer a social engineering side channel, it is an identity entry point. The attack works because help desks and users are still trusted to authenticate identity decisions through conversation. Once that trust is exploited, the attacker does not need to bypass IAM directly, only to redirect an existing workflow into a fraudulent reset or approval. Identity teams should treat voice-based deception as part of the access control surface, not as a separate awareness problem.

A few things that frame the scale:

  • The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to The 2024 ESG Report: Managing Non-Human Identities.
  • Our research also found that 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, which is a governance signal rather than an edge case.

A question worth separating out:

Q: Who is accountable when a social engineering call leads to SSO compromise?

A: Accountability is shared across identity operations, help desk governance, and security architecture. Teams that own resets, MFA recovery, browser telemetry, and identity monitoring all influence the outcome. Framework-wise, this sits under identity governance, access control, and incident response rather than only user training.

👉 Read our full editorial: Vishing and AiTM phishing are driving SSO account takeover



   
ReplyQuote
Share: