Threats & Social EngineeringIntermediateAttack Technique2 validated evidence records

Help Desk Social Engineering

Also known as: Service desk social engineering, IT support impersonation

30 sec

Social engineering aimed at IT or identity-support personnel to reset credentials, enroll attacker-controlled MFA, recover accounts, or change trusted access.

Know

What is Help Desk Social Engineering?

Help desk attacks exploit recovery processes that exist specifically for users who cannot authenticate normally. Attackers collect employee information, impersonate the user, and pressure support personnel to reset passwords, change MFA, add devices, or bypass standard verification. Because the resulting access is legitimate, subsequent activity can be difficult to distinguish from the real employee.

Why it matters

2026 incident reporting continues to show attackers using help desks and identity recovery as a reliable path into enterprise SaaS and SSO environments. The weakness is often the recovery workflow rather than the authentication technology itself.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Technical ValidationOperational validation

Fake IT-support contacts use Teams to obtain user-approved remote access

2026-09-02Microsoft Threat Intelligence

Microsoft describes external Teams contacts impersonating support staff and persuading users to grant remote access. The documented chain includes implant deployment, discovery, and lateral movement, following user authorization through legitimate support tools.

Why this is evidence

This is evidence of support-workflow abuse and social engineering. It does not establish a Teams software vulnerability or suggest that merely receiving a chat compromises a device.

See the source — Microsoft Threat Intelligence: Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Technical ValidationMeasured outcome

Cloud and SaaS incidents were dominated by identity compromise and data theft

2026-H1Google Cloud / MandiantCloud and SaaS

Google Cloud reports identity issues were used for initial access in 83% of major cloud and SaaS incidents it analyzed, while data theft was targeted in 73%. The report also documents vishing, help-desk manipulation, SaaS token abuse, living-off-the-cloud behavior, and compromised third-party trust.

Why this is evidence

The report connects identity, SaaS, cloud, social engineering, and trusted integrations into a single modern intrusion pattern rather than isolated threat categories.

See the source — Google Cloud: Cloud Threat Horizons Report H1 2026

Understand the mechanics

How it works

  1. 1

    Gather employee identity and organizational information.

  2. 2

    Contact the help desk using a believable pretext.

  3. 3

    Pass weak knowledge-based checks or pressure staff to make an exception.

  4. 4

    Reset credentials or register attacker-controlled authentication.

  5. 5

    Use the newly trusted identity to access SSO, SaaS, cloud, or internal systems.

Practice

What to watch for

  • Urgent reset request from an unusual number or channel
  • User asks to replace MFA and password simultaneously
  • Caller resists call-back or manager verification
  • Repeated recovery attempts
  • New device or factor enrolled immediately before sensitive activity

Perform

What to do

  1. 1

    Freeze further recovery changes.

  2. 2

    Contact the employee and manager through known channels.

  3. 3

    Remove unauthorized factors and revoke sessions.

  4. 4

    Review all access performed after the recovery event.

  5. 5

    Preserve help-desk recordings, tickets, and authentication logs.

How to reduce the risk

  • Strong recovery verification
  • Manager or secondary approval for sensitive resets
  • No knowledge-only identity proofing
  • Number-matching or phishing-resistant MFA
  • Recovery event alerts
  • Help-desk threat simulations

Business impact

  • SSO takeover
  • SaaS data theft
  • Privilege escalation
  • Ransomware enablement
  • Fraud

What different roles should do

Help Desk

  • Treat recovery as a privileged security transaction
  • Never let urgency replace identity proof

Security

  • Monitor recovery events as high-value identity telemetry

Framework & standards context

  • MITRE ATT&CK Valid Accounts
  • NIST Digital Identity Guidelines

Keep learning

Source transparency

Authoritative sources

Last reviewed: 2026-09-02