phishing
The Help Desk Is Still the Easiest Door Into Your Network
2026-06-25

Service desks keep getting rolled, and it isn't because the tech behind them is weak. They get rolled because someone picks up the phone, sounds convincing, and asks for a password reset. That is genuinely all it takes most of the time.
The Scattered Spider attacks on Marks & Spencer, Co-op and Harrods earlier this year were the loudest examples, but they weren't outliers. M&S Chairman Archie Norman confirmed publicly that the attackers impersonated an employee and talked a third-party service desk agent into resetting credentials. That single conversation handed them the keys to internal systems.
Carnival Corporation has since disclosed a similar incident, where social engineering got an attacker into part of its IT environment. The FBI has been warning about the Silent Ransom Group running the same playbook, posing as IT support and walking staff into remote access sessions using perfectly legitimate admin tools.
Why the help desk keeps losing
The appeal is obvious once you look at it from the attacker's side. Help desk staff are trained, first and foremost, to be helpful. They have the rights to reset passwords, provision accounts and disable MFA. A confident caller who knows the lingo, sounds rushed, and drops the right names can be inside in minutes without tripping a single alert.
No phishing kit. No zero-day. No malware sandbox to evade. Just a conversation between two people, one of whom is lying.
Verizon's latest Data Breach Investigations Report puts stolen credentials in the mix for 44.7% of breaches, and the service desk is one of the cleanest ways to obtain them. Awareness campaigns, regulation and a string of high-profile arrests have not meaningfully slowed it down. The underlying problem is procedural rather than technical. If an agent can reset an account based on information an attacker can pull off LinkedIn in ten minutes, the attacker will keep winning.
What actually works
The fix is unglamorous. Verify identity before you touch the account, every time, with something the caller has to actively prove rather than recite.
- MFA challenges against the registered device, not a number read out over the phone.
- Directory attribute checks that go beyond what's on a public profile.
- Callbacks to a known number on file, not one the caller has provided.
- Manager or supervisor confirmation for sensitive actions like MFA resets and privileged account changes.
None of this is novel. It's the same identity verification banks have used for decades, dropped into the one workflow most organisations have left wide open. The reason it isn't standard practice yet is friction. It's slower. It frustrates legitimate users. It makes the help desk feel less helpful.
That trade-off is the whole game. Helpful is good. Helpful without verification is the breach.