How helpdesk attacks play out
Armed with basic personal data from social media and leaked credentials, most of it available for mere dollars on the dark web, attackers call in, impersonate an employee, and request an MFA reset. If the helpdesk relies on knowledge-based authentication alone, they open the door for the scammer. From there, it’s a straight path to unauthorized access, ransom, IP theft, and the ability to move anywhere in your systems.
Real world example
That’s how the Scattered Spider attack against MGM Resorts played out.1 The hackers found an MGM employee’s LinkedIn® profile,2 impersonated that employee on a call with the helpdesk, and asked for login support. From there, the hackers gained access to MGM’s internal systems.1
The damage was severe. Widespread system outage impacted systems for several days.3 Caesars Entertainment and MGM shares fell in the immediate aftermath3 and the organization faced a class action lawsuit over the protection of customer privacy.4
That was all possible through impersonation at the helpdesk.
With AI, attackers can convincingly impersonate an individual’s voice and even face to aid in their scheme. They can also use AI to automate attacks, probing at channels like the helpdesk to find vulnerabilities to exploit, turning this once-trusted channel into a wide open door for attackers.
“For thousands of years, trust was based on perception: recognizing someone’s voice or seeing someone face-to-face. We’re now in an age where trust can be synthesized. AI has changed what we think of as proof.”Head of Fraud, Financial Crimes, and Trust Systems, HealthEquity
Ajit Gaddam
Real world example
Microsoft released a warning to employees in 2026:5 scammers are infiltrating organizations, sending Teams messages pretending to be IT or helpdesk staff, and requesting remote access to victims’ computers. Once inside, they can get access to sensitive data, systems, and IP.
Text
1%
Text
Text
1%
Text
Text
1%
Text
Text
Lorem ipsum dolor sit amet consectetur. Sit convallis ullamcorper et varius venenatis blandit vitae hendrerit blandit. Hac aenean tellus consectetur elit orci aenean ipsum arcu. Turpis a laoreet sit rhoncus eros penatibus facilisis dolor tempus. Vitae gravida fames nunc dui scelerisque porta nulla ut. Sit mi volutpat ipsum odio nulla sociis.
Lorem Ipsum is simply dummy
Vitae eleifend mi lorem iaculis malesuada sit adipiscing vel. Sit massa ut etiam eu.
1University of Hawaii—West O’ahu, “ALPHV: Hackers Reveal Details of MGM Cyber Attack,” October 2023.
2LinkedIn is a registered trademark of LinkedIn Corporation and its affiliates in the United States and/or other countries.
3Reuters, “MGM Resorts breached by ‘Scattered Spider’ hackers: sources,” September 2023.
4Fox5 Vegas, “MGM begins payouts in $45M data breach settlement,” December 2025.
5Tech Radar, “Microsoft issues warning over Teams helpdesk impersonation attacks – hackers are ‘blending into routine IT support activity’ by abusing remote assistance access,” April 2026.




