Skip to content
Under attack?Get emergency help now
All articles
21 September 2026F1 IT Solutions

When the Attacker Phones Your Help Desk

Identity SecuritySocial EngineeringAccess ManagementSecurity AwarenessManaged ITCybersecurity

Most security spending assumes the attacker will try to get in through technology. Phishing links, malware, an unpatched server facing the internet. So businesses buy tools that watch those routes, and the routes get harder.

The response has been to stop attacking the technology and start phoning a person instead. Someone calls your help desk, says they are a member of staff, says they have a new phone and cannot get into their account, and asks for the multi-factor authentication to be reset. If that call succeeds, the attacker does not need to defeat MFA. They are handed a working login.

Why the help desk is the target

Whoever answers support calls holds more power than almost anyone else in the business. They can reset a password, unlock an account, register a new authentication device and sometimes lift a permission. They are also measured on being helpful and quick, which is exactly the pressure an attacker wants to apply.

The FBI and CISA have documented criminal groups using this method against large organisations, impersonating both staff and IT support to get passwords reset and MFA disabled, then using those perfectly valid accounts to move around undetected. Nothing about it is technically advanced. That is the point.

The caller usually sounds convincing because the preparation is easy. Names, job titles and reporting lines come off LinkedIn. Personal details come from old breach dumps. Internal wording and system names come from earlier phishing, a supplier, or a former employee. Voice cloning has made "they sounded like Sarah" worth very little as evidence.

Where the usual checks fall down

Most verification scripts rely on things the caller knows. Employee number, date of birth, last four digits of a phone number, the name of a manager, the answer to a security question set up years ago. Every one of those is either public, purchasable, or guessable.

Two other habits make it worse:

  • Deference to seniority. A caller claiming to be a director, mid-flight and locked out, gets fewer questions rather than more. Attackers know this and pick their persona accordingly.
  • Manufactured urgency. A payroll deadline, a board meeting in ten minutes, a client waiting. Urgency exists to stop the agent following the process, and it is the single most reliable tell that something is wrong.

There is also the account that is easiest to forget. If an outsourced provider, a branch office or a contractor can raise a reset on your behalf, your verification standard is only as strong as theirs.

What a stronger process looks like

The aim is not to make support unhelpful. It is to make identity something that is proved rather than described.

Verify against something the caller cannot simply know

  • Send a code to a device or number already registered in your directory and ask the caller to read it back, rather than asking questions about details found in a breach.
  • Use a callback to the number on record. Never to a number the caller supplies during the call.
  • For staff you can reach, a short video call with a company ID or a known face is quick and very hard to fake convincingly.
  • Where a manager confirms the request, contact the manager yourself through a known channel. Do not accept an email the caller says has been sent.

Treat account recovery as a privileged action

Resetting MFA is not a routine task. It is the moment an account's protection is switched off and switched back on again, so it deserves the same care as granting administrative rights. Tier it: an ordinary password reset can be lighter touch, while resetting authentication factors for finance, executive and administrator accounts should need a second person to approve. Pairing this with phishing-resistant authentication removes a good deal of the reason to call at all, because passkeys and hardware keys fail far less often than an app on a replaced phone.

Log it, alert on it, review it

Every reset should leave a record of who asked, who approved, what proof was accepted and when. Send an automatic notice to the account owner and their manager whenever authentication factors change, so an unauthorised reset gets challenged by the real person within minutes. Then review the log monthly and watch for volume spikes, repeat requests on the same account, and resets outside working hours. Our managed IT and monitoring work is built around exactly that sort of routine checking, because the pattern is usually visible before the damage is.

Give your agents permission to say no

An agent who refuses a plausible caller must be backed, not questioned. Write it into the procedure: no verification, no reset, regardless of who the caller claims to be, and escalate instead of improvising. Rehearse it too. A short test call to your own service desk will tell you more about your real exposure than any policy document, which is why we fold it into security awareness training rather than leaving it to an annual slide deck.

The quiet version of this risk

Very few businesses know how many MFA resets they performed last month, who approved them, or what proof was accepted. That gap is the risk, and closing it costs almost nothing beyond writing the procedure down and holding to it.

If you are not sure how your own help desk would handle that call this afternoon, that is a reasonable place to start looking. A tightened recovery process is one of the cheapest improvements available to most businesses, and it sits alongside the rest of your cybersecurity controls rather than replacing any of them.

Want this handled for you?

Talk to the F1 team about cybersecurity, AI and managed IT for your business.