Cybersecurity

Attackers Aren't Cracking MFA. They're Calling Your Help Desk.

A phone call to your help desk is now the fastest way around multi-factor authentication. The tactic behind 2026's biggest financial-services breaches has spread from casinos and airlines into ordinary mid-market companies, and it has nothing to do with buying more security software.

Multi-factor authentication is supposed to be the control that finally stops a stolen password from becoming a breach. It still does that job against phishing kits and brute force. It does nothing against a confident phone call. That is the entire premise behind the technique CrowdStrike's 2026 Financial Services Threat Landscape Report named the single most active threat facing that industry this year: someone calls or messages a company's help desk, claims to be a locked-out employee, and asks for a password reset and a new MFA device.

The crime ring most associated with the tactic is widely tracked under names including Scattered Spider. A July 2026 Justice Department complaint described a member's role in help desk social engineering and MFA resets tied to more than 100 intrusions, and two members of the group pleaded guilty in June. None of it required breaking any encryption or exploiting a software flaw. It required a help desk that would reset a credential on request.

The call takes about five minutes

The pattern is consistent across the incidents that have been reported this year: light research on an employee (a name and department off LinkedIn is usually enough), a call or chat message to the help desk claiming to be locked out, and a request to reset the password and re-enroll a new MFA device. Some operators have skipped the phone entirely and impersonated internal IT support directly inside Microsoft Teams, according to CrowdStrike's reporting, walking an employee through "verifying" their own credentials into an attacker-controlled prompt.

Once a new device is enrolled as a trusted MFA factor, the attacker holds a valid, fully authenticated session. Every technical control sitting behind that login, email, VPN, financial software, admin consoles, trusts it exactly as much as it trusts the real employee, because as far as the system is concerned, nothing suspicious happened. No password was guessed. No malware ran. A help desk did its job.

Why this isn't just a casino and airline problem

The technique spread beyond its original targets because it is cheap, repeatable, and does not care what industry it is aimed at. It needs one thing: a help desk whose identity verification is weaker than the story a well-prepared caller can tell. That describes plenty of companies far smaller than a casino operator. A ten-person firm's "help desk" is often one person handling resets between everything else on their plate, verifying identity with a question whose answer is guessable or already public. An outsourced IT provider without a written, enforced reset procedure has the same gap, just with a different name on the door.

The point isn't that this specific criminal group will call your business next week. It's that the technique it popularized is now a known, documented, low-cost playbook that other operators are free to copy, and that the industries getting hit are broadening past the original headlines and into financial services, insurance, and general mid-market companies with nothing in common except an under-verified reset process.

Clear takeaway

The fix here isn't stronger MFA. It's a help desk, whether that's an internal employee or an outsourced IT provider, that will not reset a credential or enroll a new MFA device on the strength of a phone call alone. Require verification through a channel the caller doesn't control, limit who can approve a reset on a sensitive account, and rehearse the process before someone else tests it on you.

Actions to take this week

  1. Write down your actual reset procedure and check whether "verifying identity" currently means anything more than a security question. If it doesn't, it's a script an attacker can follow too.
  2. Require out-of-band verification for any password or MFA reset tied to email, VPN, or financial systems: a callback to the number already on file, never the one the caller provides, or confirmation from the employee's manager.
  3. Limit who can approve a reset and require a second person's sign-off for anything touching finance, admin, or executive accounts.
  4. Move phishing-resistant MFA (FIDO2 security keys or passkeys) onto your highest-risk accounts, where a help desk can't simply talk someone into "resetting" the factor because there's no code to read back.
  5. Run one unannounced practice call against your own help desk this quarter, or ask your IT provider to show you the results of theirs.

Brotherly Technology helps small and mid-sized businesses across our Northwest Georgia, metro Atlanta, Chattanooga, and Alabama footprint put an actual verification step between a phone call and a password reset, before it gets tested by someone who isn't calling to be helpful.

Sources:

One accountable technology partner.

Tell us what's slowing your team down. We'll show you exactly how we'd fix it — no pressure, no jargon.

Book a Free Consultation
Book a Free Consultation