CybersecurityMay 21, 202610 min

The Help Desk Has Become Your New Security Perimeter

How is MFA bypassed in 2026?

Short answer: it is not bypassed technically, someone is asked to turn it off. The most profitable intrusion campaigns of the past two years rely on a call to the help desk, where the attacker impersonates an employee and obtains a password reset or a second-factor re-enrolment. The rest (real-time relayed phishing and session cookie theft) covers the cases where MFA is not phishing-resistant.

This is a complete reversal of defensive logic. For twenty years, security focused on the technical perimeter. The most publicized intrusions of the recent period (British retail chains, telecom operators, cloud platforms) exploited no software flaw. They exploited a human process designed to be helpful.

Anatomy of a malicious call

1.

Reconnaissance : the attacker gathers the target's name, role, manager, internal vocabulary and sometimes employee number from professional social networks

2.

Pretext : they call posing as that employee, often late in the day or during a busy period, with a credible reason: lost phone, travel, new device

3.

Pressure : urgency, reference to a real project, mention of an executive who is waiting

4.

Request : a password reset or, better for them, enrolment of a new MFA factor on their own device

5.

Exploitation : legitimate sign-in, lateral movement and exfiltration within hours

The quality of impersonation crossed a threshold with voice cloning: a few seconds of public recording is enough to reproduce a voice. The agent on the line no longer has any reliable way to recognize a caller by ear.

Hardening the recovery procedure

The guiding principle is simple: identity reset must be an instrumented authentication event, not an agent's judgment call.

Ban knowledge-based verification : date of birth, employee number, manager name and address are publicly available or sitting in past breaches

Require cryptographic proof where possible: a second already-enrolled authenticator, or assisted enrolment from a managed device

Video verification with liveness detection for privileged accounts, compared against an HR reference photo

Manager attestation out of band : call back on the number in the internal directory, never the number the caller supplies

A waiting period on sensitive re-enrolments : a few hours of delay breaks the urgency dynamic the attack depends on

A posted anti-social-engineering script, with an explicit right to refuse and escalate without justification

Culture matters as much as procedure: the agent must know they will never be penalized for slowing a request down. Organizations that measure the help desk solely on handling time manufacture their own vulnerability.

Moving to genuinely phishing-resistant MFA

Not all second factors are equal. SMS codes, app-based one-time codes and simple push notifications are relayable: a proxy placed between the user and the legitimate service captures the code in real time and replays it, the adversary-in-the-middle attack, industrialized through off-the-shelf kits.

Factors based on FIDO2 and WebAuthn (hardware keys and passkeys) are not relayable, because the cryptographic proof is bound to the legitimate domain. A site imitating your portal cannot obtain a valid signature.

A realistic rollout proceeds in concentric circles:

1.

Circle 1 : domain and cloud administrators, finance leadership, and the help desk itself

2.

Circle 2 : remote access, privileged application accounts, developers with production access

3.

Circle 3 : all employees, keeping a hardware backup factor rather than falling back to SMS

4.

Lockdown : disable weak methods once migration completes, otherwise the attacker will simply request the weakest factor still accepted

That last step is the one most often skipped: as long as SMS remains available as a fallback, the account's real security level is the security level of SMS.

Test rather than assume

The only way to know whether your help desk holds is to test it. A scoped social engineering exercise (written scope, formal authorization, blame-free debrief) measures what no policy can: actual behaviour under pressure.

At ITCS Group these tests are part of our offensive engagements. We measure the disclosure rate, time to escalation, actual use of the script and the team's ability to report the suspicious call. The deliverable is not a list of failures: it is a revised procedure and a training scenario drawn from your own calls.

Conclusion

As long as account recovery remains a trust-based, verbal process, it will be the cheapest path into your systems. Hardening it costs a few weeks of procedure work and a FIDO2 rollout in circles. ITCS Group runs social engineering tests, reviews recovery procedures and supports migrations to phishing-resistant MFA. Contact us to test your help desk.

Sources

CISA : joint advisory on social engineering tactics targeting help desks

Field Effect : Anatomy of a helpdesk social engineering attack

ITCS Group social engineering engagements : 2025-2026

Share this articleLinkedInXFacebook