Every day, enterprise IT help desks at health systems field calls from employees who have forgotten their passwords, lost an authenticator device, or need MFA reconfigured before a shift. The process is routine: Verify a name, confirm a few answers, complete the reset. But recent trends point to an uncomfortable question: would your help desk even notice if the caller was fake?
How Attackers Exploit Trust in the Hospital Help Desk
The short version: Because AI-powered voice cloning and social engineering attacks now easily bypass traditional knowledge-based verification at healthcare help desks, organizations must adopt automated, multi-signal identity verification to securely confirm caller identity.
AI voice cloning has made impersonation indistinguishable from the real thing for many human listeners. Attackers bypass knowledge-based authentication (KBA) challenges, the security questions help desks often rely on, more than 50% of the time using publicly available data.1 The result? The credential reset workflow is a critically exposed entry point into a healthcare network.
How have help desk attacks evolved?
In September 2023, the threat group Scattered Spider called the IT help desk of MGM Resorts, impersonating employees using details pulled from LinkedIn and prior breach data, and talked its way into credential resets. MGM refused to pay ransom and absorbed a ten-day outage and more than $100 million in lost EBITDA. CISA’s own advisory on the group, issued weeks later, confirmed vishing to IT help desks as one of its core tactics.
Voice channel attacks, including at the enterprise help desk, are not new, but the scale is, and healthcare is now seeing the same playbook.
In April 2024, the U.S. Department of Health and Human Services warned that threat actors were calling hospital IT help desks posing as physicians and revenue cycle staff, using names, departments, and even employee ID numbers pulled from public sources to request password resets and MFA reconfiguration. There are many additional examples of this happening, including attacks by Scattered Spider.
AI is accelerating voice channel attacks: the FBI’s 2025 Internet Crime Report broke out AI-enabled fraud as its own category for the first time, tracking 22,364 complaints and nearly $893 million in losses. The report states, “AI-enabled synthetic content is becoming increasingly difficult to detect and easier to make, which allows criminal actors to potentially conduct successful fraud schemes against individuals, businesses, and financial institutions.” Pindrop research shows the same acceleration: AI voice attacks surged 1,390% between Q4 2024 and Q1 2026 alone, across a study of more than 700 million calls.2
Why do current verification methods fail?
Humans struggle to detect synthetic audio and attackers have access to security question answers. The standard help desk verification flow rests on two assumptions that are rapidly weakening: that the caller is an authentic human, and that knowing personal information proves identity.
On the first assumption: One study found that human listeners could correctly identify a voice as AI-generated or real only about 60% of the time. Separate research on AI-generated content detection puts the figure at roughly 50%, no better than a coin flip. A third study found something perhaps more troubling: people have grown more skeptical of all audio, and accuracy on genuine recordings actually dropped by 8.6 percentage points relative to a 2021 baseline. Listeners aren’t great at spotting fakes and they’re growing suspicious even of real voices.
On the second assumption: NIST already called this out in its Digital Identity Guidelines, Special Publication 800-63-4. The guidelines state that knowledge-based authentication “does not constitute an acceptable secret” for identity verification. Pindrop data quantifies why that model fails: fraudsters bypass KBA more than 50% of the time, and even one-time passcodes, often treated as the stronger control, are still bypassed roughly 25% of the time.1 Today’s attacker has access to personal information, rendering KBA challenges largely ineffective.
Where are regulations headed?
Regulators, industry leaders, and government agencies are calling for protections against clinician deepfakes and updating identity verification guidelines. Our commentary to the recent CMS RFI on reducing healthcare fraud calls for proactive defenses against voice and deepfake attacks in Medicare, Medicaid, and CHIP programs.
This attack front is evolving quickly and firm policy decisions remain to be seen, but voice and deepfake threats will certainly be top of mind as long as healthcare carries the highest average data breach cost of any industry, at $7.42 million per breach. As such, many healthcare organizations are not waiting for regulatory guidance to act in defense of their patients and staff.
What does a defensible Help Desk verification process look like?
A defensible process is one that produces clear and actionable evidence of risk. In practice, that means answering three questions on every help desk call, before trust is extended and before any credential changes hands: Is this a machine? Is this a bad actor? Is this the right human? If an auditor asks how the organization confirmed identity before a credential reset, there should be a clear picture of the interaction: what information was exchanged and what signals were used to determine identity.
The following elements are foundational to thorough identity verification:
- Is this a machine? Synthetic voice detection analyzes a live call and flags synthetic audio in roughly two seconds, at up to 99% accuracy with a false positive rate under 1% in Pindrop’s internal testing.3 Either the voice passed or it didn’t, and a clear and documented risk signal exists.
- Is this a bad actor? Risk scoring should look at more than just the voice itself; it should consider the device, behavior, caller ID, and known fraud-consortium data, flagging anomalous call metadata or bad-actor associations for escalation before any privileged action is taken.
- Is this the right human? Passive authentication matches the caller against device and behavioral signals built up over prior interactions, so a legitimate, recognized caller moves through with less friction while an unrecognized or mismatched one gets flagged, regardless of whether they sound convincing or know the right answers.
How can organizations measure gaps?
Three questions will tell you where you stand.
Human efficacy
Can anyone on your help desk team verify, in real time and with consistency, whether a caller’s voice is synthetic?
Multi-signal analysis
Does your risk assessment look past what a caller says to the device, behavior, and network signals behind the call?
Audit trail
If an auditor asked for evidence of identity behind the last ten credential resets, could you produce it this afternoon, or would it take weeks of digging through call logs and agent notes?
If any answer is no, you have an opportunity to arm your help desk team with a documented, automated layer of identity verification on every call. Acting in these areas empowers help desk staff to focus on efficient service, while simultaneously deepening security against staff impersonators.
The next call your help desk answers could be entirely synthetic. The underlying question is whether your process would know.
Sources
- Pindrop. 2025 Voice Intelligence & Security Report. 2025.
- Pindrop. Analysis of customer call data, Q4 2024-Q1 2026, based on a study of more than 700 million calls.
- Pindrop, internal dataset and testing analysis, as of May 2026.