Workforce and access social engineering · Also called help desk social engineering, IT service desk impersonation, MFA reset scam, password reset vishing, Scattered Spider help desk calls
Help desk password and MFA reset impersonation
Help desk reset impersonation is an attack in which a criminal phones a company's IT help desk pretending to be an employee, often using personal details found online, and asks for a password reset or for the employee's multi-factor authentication to be moved to a new device. The criminal then signs in as that employee.
How it works
- Criminals collect names, roles, and personal details of employees from social media, business websites, and earlier data breaches.
- They call employees and the help desk, sometimes over several calls, to learn what the reset process asks for.
- Posing as the employee, they ask the help desk to reset the password and move multi-factor authentication to a device they control.
- With the new login, they take over the account, often through single sign-on, and use it to steal data for extortion or to deploy ransomware.
Red flags
- A caller asks for a password reset and a new multi-factor authentication device in the same call.
- The caller proves who they are only with details that can be found or bought, such as date of birth or the last four digits of a Social Security number.
- The request is for an administrator or other highly privileged account.
- The caller creates urgency or alarm to rush the agent into making the change.
If you are targeted
- Stop: do not make the change. End the call and verify the request by calling back the employee's registered number or writing to their known corporate email.
- If a reset has already been made, reset the password again, remove any newly registered MFA device, and revoke the account's active sessions.
- Check for logins from unusual sources, such as VPN services in residential address ranges, and review what the account accessed.
- Report it to your security team, then to the national service; our Report a scam page lists where, such as ic3.gov in the US.
Prevention
For individuals
- Limit the personal details you post publicly, such as your role, phone number, and date of birth, because attackers use them to pass help desk checks.
- If you get a notice that your password or MFA device was changed and you did not ask for it, report it to IT straight away.
- Never read out a one-time code or approve a login for someone who calls claiming to be IT.
For organisations
- Require positive identity verification before any password or MFA reset, such as on-camera or in-person checks and ID verification, at least for privileged accounts.
- Require an out-of-band callback to the employee's registered number, or confirmation from their known corporate email, before any high-risk change.
- Do not rely on publicly available data such as date of birth or the last four digits of a Social Security number to verify callers.
- Allow MFA re-registration only from corporate or trusted locations, notify users of every security change, and move to phishing-resistant MFA such as FIDO security keys.
Real cases
2025-09 · US · Charged · $115M ransom
Scattered Spider: Thalha Jubair charged in New Jersey, 20252025-04 · GB · Disclosed · £80M impact
Co-op and Harrods cyber attacks, 20252025-04 · GB · Disclosed · £300M estimate
Marks & Spencer cyber attack via third-party impersonation, 20252024-08 · GB · Sentenced · £29M impact
Transport for London hacked after a help desk password reset, 20242023-09 · US · Disclosed
Caesars loyalty database taken after IT vendor social engineering, 20232023-09 · US · Disclosed · $100M impact
MGM Resorts cyberattack after a reported help desk call, 20232020-07 · US · Sentenced · $118,000 stolen
Twitter account takeover via fake IT help desk calls, 2020
Delivered through: Voice phishing (vishing)
How official datasets classify it
- MITRE ATT&CK
- T1684.001, T1566.004, T1098.005
Questions
- What is help desk social engineering?
- It is when an attacker calls an IT help desk while pretending to be an employee and talks the agent into resetting that employee's password or multi-factor authentication. CISA reports that the Scattered Spider group has used this method against large companies.
- How should a help desk verify a caller before a reset?
- Use checks an attacker cannot easily fake: call back the employee's registered number, confirm through their known corporate email, or verify them on camera or in person. Avoid relying on details such as date of birth, which attackers often already hold.
Related scams
- MFA fatigue (push bombing)
- SIM swap
- Vishing into a malicious OAuth connected app
- Deepfake CEO voice and messaging fraud