Help-desk identity processes are attack surfaces when social engineering can trigger password resets or MFA transfer

Several major intrusions began with a convincing phone call to a help desk rather than anything technical.

Reset the password, move the second factor to a new device, and every other control has been bypassed by an entirely legitimate process working as designed. The reset path is an authentication system and it usually has a weaker standard of proof than the login it can override, which is precisely why it gets targeted.

Checked against the primary source.

More on Real incident lessons