Stop hiring fraud before it starts. Visit 909Shield.ai

by
Den Jones

The Weakest Link Isn't Your Firewall. It's Your Help Desk.

How a Ten-Minute Phone Call Can Undo Millions in Security Investment

In September 2023, a caller reached MGM Resorts' IT help desk claiming to be a locked-out employee. Using information the attacker had gathered from LinkedIn, the call lasted roughly ten minutes. That's all it took. By the end of it, the caller had a reset password and multi-factor authentication (MFA) credentials that opened the door to MGM's Okta and Azure environments. The cost: an estimated $100 million. That breaks down to $84 million in lost revenue and $10 million in incident response, legal, and advisory fees. MGM also pledged a further $40 million to rebuild its IT infrastructure. The attackers, a loosely organized collective tracked as Scattered Spider (also known as UNC3944), walked away with roughly 6 terabytes of customer data.

That single call is now one of the most cited case studies in cybersecurity, and for good reason. It illustrates a shift in how serious intrusions actually begin. Organizations have spent the last decade hardening perimeters, patching vulnerabilities, and training employees to spot phishing emails. Attackers responded by going around all of it and calling the help desk instead.

Why the Service Desk Became the Target of Choice

The service desk exists to solve exactly the problem an attacker wants solved: “I've lost access to my account.” Help desk staff are trained, measured, and rewarded for restoring access quickly and courteously. That is precisely the pressure a social engineer exploits. Mandiant's 2026 M-Trends report found that voice phishing has become the second most common initial access vector it observed in 2025, behind only exploited vulnerabilities, and specifically called out UNC3944 for “continued targeting [of] help desk staff by impersonating employees requesting password resets and multi-factor authentication changes.” The same report found that once an attacker gains a foothold, the median time to hand access off to a follow-on operator has collapsed to just 22 seconds. That operator is often a ransomware affiliate. Back in 2022, the same handoff took more than eight hours. Speed like that is only possible when the initial compromise doesn't require breaking anything technical at all.

CISA's advisory on Scattered Spider lays out the group's playbook in granular detail. Actors pose as IT or help desk staff over phone and SMS to harvest credentials directly from employees. They talk targets into installing legitimate remote access tools, and separately call the real help desk to request password and MFA resets. Where MFA can't be socially engineered away outright, the group falls back on SIM swapping to hijack phone-based codes. Or “MFA fatigue”: bombarding a victim with push notifications until they tap Accept just to make the alerts stop.

A joint sector alert from the U.S. Department of Health and Human Services describes the reconnaissance behind these calls. Attackers scrape LinkedIn profiles and prior breach data for an employee's last four Social Security digits, employee ID, and other verification details. They spoof a local area code, then claim a broken phone to explain away the missing MFA device. All so a stressed, well-meaning technician will simply enroll a new one. The same alert notes that roughly one in four people surveyed had either experienced an AI voice-cloning scam themselves or knew someone who had... a preview of how much easier this style of attack is about to become.

The Numbers Behind the Trend

The FBI's Internet Crime Complaint Center (IC3) issued a public service announcement in November 2025 describing a related pattern: criminals impersonating financial institution support staff to trick customers into handing over credentials or one-time passcodes, which are then used to log in and reset the account's own password, locking the real owner out. Between January and late November 2025, IC3 logged more than 5,100 complaints tied to this exact scheme, with losses exceeding $262 million.

Verizon's 2026 Data Breach Investigations Report puts pretexting-style attacks, the broader category that help desk impersonation falls under, at 6% of breaches overall. Credential abuse appears somewhere in the attack chain of 39% of all breaches analyzed. The report also found that phone-based phishing simulations produced a 2% click-through rate compared to 1.4% for email. That's roughly 40% higher. It suggests voice-based social engineering is measurably more effective at fooling people than a typed message, even in a controlled test. Perhaps most relevant to help desks specifically, which are very often outsourced: the DBIR found that 48% of breaches now involve a third party, a 60% year-over-year increase, and that only 23% of third-party-related MFA gaps get fully remediated once identified.

IBM's 2025 Cost of a Data Breach report adds the financial backdrop. The global average cost of a data breach was $4.44 million. Breaches originating from phishing, the category that covers both email and voice-based pretexting, averaged $4.8 million and accounted for 16% of all incidents studied. In the United States specifically, the average breach cost climbed to a record $10.22 million.

When the Help Desk Is Someone Else's Employee

The MGM incident is the best-known example, but it's far from the only one. Caesars Entertainment was breached by the same threat actor around the same time and, unlike MGM, paid approximately $15 million in ransom. Twilio, Okta, Reddit, and Cloudflare have all disclosed intrusions rooted in some flavor of MFA or credential social engineering aimed at employees or their support vendors.

The Clorox case is arguably more instructive than MGM's, because it shows what happens when the help desk itself is a third-party contractor operating under a documented, ignored process. Clorox is currently suing its outsourced IT services provider, Cognizant, for $380 million, alleging that Cognizant help desk agents repeatedly bypassed Clorox's own identity-verification policy (a tool called MyID, or at minimum a callback to the employee's manager) during an August 2023 attack. According to the lawsuit, a caller impersonating a Clorox employee was granted an Okta password reset with no verification. Then a VPN password reset when the “employee” claimed not to have it. Then two separate Microsoft MFA resets the same day, again without verifying identity. Then finally a phone number change for SMS-based MFA. The attacker used that access to pivot to an IT security employee's account with the same technique and had privileged network access within three hours. Clorox states the resulting disruption cut sales volume by 6% over the following six months and created product shortages on store shelves. It is seeking $380 million against $49 million in direct remediation costs and $100 million recovered through insurance. Cognizant has responded that it performed the narrow scope of services it was contracted for and that Clorox's own internal controls were inadequate.

Whichever side prevails in court, the case makes a point that the MGM and Caesars incidents only imply: the failure point in nearly all of these breaches is not a missing technology control. Clorox had a documented verification policy. MGM had MFA enabled. The gap was a person on the phone, under time pressure, choosing to trust a voice over a process.

Closing the Gap

None of this argues that MFA or help desk support should be abandoned. Both remain essential. It argues that the workflow surrounding “I'm locked out” needs to be treated with the same rigor as a firewall rule, because attackers have already recognized it as the softer target. A few changes show up repeatedly across the incidents above and the guidance issued in their wake: requiring a callback to a phone number already on file rather than one the caller provides, escalating any MFA-device change or phone-number update to mandatory manager or security-team verification, moving away from SMS-based MFA toward number-matching push authentication or phishing-resistant methods like FIDO2 security keys, and critically, extending all of the above to outsourced or contracted help desk providers rather than assuming a vendor's SLA implies equivalent security discipline.

Every one of those fixes is really pointing at the same underlying problem. The person answering the phone has no reliable way to confirm who is actually on the other end of the call. Caller ID can be spoofed. Security questions can be answered from a LinkedIn profile and a breached data dump. A “manager callback” still depends on a human judgment call happening correctly under time pressure, every single time, at 2 a.m., on a busy queue, for a caller who sounds exactly like a stressed employee. And in the AI-voice-cloning era described above, it increasingly is one.

This is the specific gap 909Shield is built to close. Rather than asking a help desk agent to make an identity determination on judgment alone, 909Shield turns high-risk requests into verified transactions before the agent ever acts on them. That includes password resets, MFA re-enrollments, and phone number changes on file. The caller is asked to complete a quick identity check: a government-issued ID scan cross-matched against a live selfie, followed by a short biometric video call that screens for the deepfake and voice-cloning techniques now showing up in real attacks. 909Shield's fraud-detection layer runs underneath that check, flagging injected or synthetic video, mismatched liveness signals, and other markers of an AI-assisted impersonation attempt in real time. This is the same category of attack the HHS/HC3 alert warns is becoming a mainstream tool for credential thieves.

The economics are built for exactly this use case: high-risk help desk transactions, not every call. At $5 per verification, 909Shield is designed to sit in front of the small slice of interactions that account for essentially all of the incidents described in this article... password resets, MFA changes, payment or payroll routing edits... without adding meaningful cost or friction to the routine tickets that make up the bulk of help desk volume. In practice, that means MGM's ten-minute call, Clorox's chain of unverified resets, and the credential-reset scheme the FBI logged more than 5,100 complaints about in 2025 all become attempts that fail at the identity check, rather than incidents that make the news.

The technical sophistication in these attacks is close to zero. The social engineering is not. A trivial phone call can defeat a well-funded security program. That's exactly why the service desk deserves board-level attention and a real verification layer at the point of highest risk. Not just a line item in the security awareness training deck.

Sources

Still have questions?