Help-desk identity processes are attack surfaces when social engineering can trigger password resets or MFA transfer
Several major intrusions began with a convincing phone call to a help desk rather than anything technical.
Reset the password, move the second factor to a new device, and every other control has been bypassed by an entirely legitimate process working as designed. The reset path is an authentication system and it usually has a weaker standard of proof than the login it can override, which is precisely why it gets targeted.
Checked against the primary source.
More on Real incident lessons
- Equifax: knowing about a vulnerability is not knowing it is patchedThe list said five
- Target: supplier access showed why third-party portals need strong segmentation from sensitive systemsThe partitions stop short
- Colonial Pipeline: business shutdown can follow IT compromiseNothing touched the pipe
- British Library: recovery can outlast initial disruptionThe outage was the short part
- Hawaii false missile alert: test and live alert paths need separation because confirmation prompts cannot correct a convinced operatorA hand apart
- CrowdStrike 2024: trusted security software can be concentration riskOne roller, every machine
