Skip to content

Workforce and access social engineering · Also called help desk social engineering, IT service desk impersonation, MFA reset scam, password reset vishing, Scattered Spider help desk calls

Help desk password and MFA reset impersonation

Help desk reset impersonation is an attack in which a criminal phones a company's IT help desk pretending to be an employee, often using personal details found online, and asks for a password reset or for the employee's multi-factor authentication to be moved to a new device. The criminal then signs in as that employee.

How it works

  1. Criminals collect names, roles, and personal details of employees from social media, business websites, and earlier data breaches.
  2. They call employees and the help desk, sometimes over several calls, to learn what the reset process asks for.
  3. Posing as the employee, they ask the help desk to reset the password and move multi-factor authentication to a device they control.
  4. With the new login, they take over the account, often through single sign-on, and use it to steal data for extortion or to deploy ransomware.

Red flags

If you are targeted

Where to report, by country

Prevention

For individuals

For organisations

Real cases

Delivered through: Voice phishing (vishing)

How official datasets classify it

MITRE ATT&CK
T1684.001, T1566.004, T1098.005

Questions

What is help desk social engineering?
It is when an attacker calls an IT help desk while pretending to be an employee and talks the agent into resetting that employee's password or multi-factor authentication. CISA reports that the Scattered Spider group has used this method against large companies.
How should a help desk verify a caller before a reset?
Use checks an attacker cannot easily fake: call back the employee's registered number, confirm through their known corporate email, or verify them on camera or in person. Avoid relying on details such as date of birth, which attackers often already hold.

Related scams

Read more