A social engineering attack that uses phone or SMS impersonation to trick support staff or users into resetting credentials, enrolling devices, or revealing MFA codes. In identity programmes, it turns operational support into an authentication path and bypasses controls that assume requests are legitimate because they sound legitimate.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on June 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org
Reviewed and updated by the NHIMG editorial team on June 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org