IT helpdesk attacks

IT helpdesks are easy to overlook as a target

And that’s exactly why bad actors attack there. With one MFA reset, they can take down your entire system.

How helpdesk attacks play out

Armed with basic personal data from social media and leaked credentials, most of it available for mere dollars on the dark web, attackers call in, impersonate an employee, and request an MFA reset. If the helpdesk relies on knowledge-based authentication alone, they open the door for the scammer. From there, it’s a straight path to unauthorized access, ransom, IP theft, and the ability to move anywhere in your systems.

Real world example

That’s how the Scattered Spider attack against MGM Resorts played out.1 The hackers found an MGM employee’s LinkedIn® profile,2 impersonated that employee on a call with the helpdesk, and asked for login support. From there, the hackers gained access to MGM’s internal systems.1

The damage was severe. Widespread system outage impacted systems for several days.3 Caesars Entertainment and MGM shares fell in the immediate aftermath3 and the organization faced a class action lawsuit over the protection of customer privacy.4

That was all possible through impersonation at the helpdesk.

With AI, attackers can convincingly impersonate an individual’s voice and even face to aid in their scheme. They can also use AI to automate attacks, probing at channels like the helpdesk to find vulnerabilities to exploit, turning this once-trusted channel into a wide open door for attackers.

“For thousands of years, trust was based on perception: recognizing someone’s voice or seeing someone face-to-face. We’re now in an age where trust can be synthesized. AI has changed what we think of as proof.”Head of Fraud, Financial Crimes, and Trust Systems, HealthEquity
Ajit Gaddam

Real world example

Microsoft released a warning to employees in 2026:5 scammers are infiltrating organizations, sending Teams messages pretending to be IT or helpdesk staff, and requesting remote access to victims’ computers. Once inside, they can get access to sensitive data, systems, and IP.

Sources and disclaimers

Wealth management scams

Continue reading

Move from understanding to action

Fight back against AI attacks with Pindrop.

Schedule a demo