For companies

Help desk caller verification before password and MFA resets

For an attacker, the IT help desk is a shortcut. Instead of breaking strong passwords or multi-factor authentication, they call support, pretend to be an employee and ask for a reset. If the help desk accepts the caller’s word, the strongest login protection can be bypassed with one phone call.

US authorities describe exactly this pattern. In its advisory on the Scattered Spider group, CISA and the FBI report that the attackers used phone calls to convince IT help desk staff to reset passwords and transfer MFA tokens.

Which requests need strong verification

Treat these as high-risk, whoever the caller appears to be:

  • password resets and account unlocks
  • enrolling, replacing or removing an MFA device or authenticator app
  • changing the phone number or e-mail address used for recovery
  • granting new access rights or administrator privileges
  • any request concerning executive, finance or administrator accounts

Why common checks fail

  • Knowledge questions. Employee ID, manager’s name, date of joining or office location can often be found on professional networks, in leaked data or through earlier calls.
  • Caller ID. An internal or familiar number on the screen can be spoofed. See caller ID spoofing explained.
  • The voice. A colleague’s voice can be imitated, and help desk staff often do not know the caller personally anyway. See how to detect deepfake voice calls.
  • Codes read out by the caller. If the help desk sends a one-time code and the caller reads it back, an attacker may have obtained it from the real user in a parallel call or phishing page.
  • Urgency and seniority. “I’m the CFO, I’m about to board a plane and I’m locked out” is designed to make agents skip steps.

A practical verification process

1. Call back on the number already on file

The agent ends the call and calls the employee on the number stored in the HR system or identity provider – never on a number the caller provides. If no number is on file, move to the next option instead of improvising.

2. Use a factor the user still has

Where possible, prompt the user’s existing authenticator or a registered device to approve the request. Self-service reset through an existing factor removes the human judgement call entirely.

3. Confirm with a second person for high-risk accounts

For executives, administrators and finance staff, require confirmation from the manager or a second help desk approver, reached through the directory rather than through the caller.

4. Handle “all factors lost” as a special case

If the user has lost every factor, use a stronger process: identity verification in person or through an approved identity-proofing service, a waiting period, and notification of the change to the user’s other known channels. Be aware that live video can also be manipulated.

5. Notify and log

After any reset, notify the user through existing channels (“Your MFA device was changed at 14:05 – not you? Call security.”) and log who verified the request and how.

Scripts that make it easy for agents

Agents follow procedures more consistently when the wording is prepared:

“For security reasons I can’t make this change on an incoming call. I’ll call you back on the number in our directory within the next few minutes.”

“I understand it’s urgent. Our policy applies to everyone, including executives, and protects your account too.”

Make it explicit that agents will never be blamed for following the process, especially with senior callers.

Where technology can help – and its limits

Number reputation and network attestation can add context about the calling number, but they do not identify the person. Verified caller identity between enrolled employees and the help desk can confirm that a call originates from a known account or device, provided enrollment and account recovery are themselves secure. Audio analysis can flag possible synthetic speech but can miss fakes and raise false alarms. Technology supports the process; it does not replace the callback and the existing-factor check.

What Identity Phone is building

Identity Phone is in development for business customers. Planned capabilities include help-desk verification that confirms a caller’s identity before passwords or MFA devices are reset, verified caller identity between colleagues, and an audit trail of flagged calls. We do not yet have independently verified performance results.

If attackers impersonate executives rather than employees, read our guide to deepfake CEO fraud and verifying high-risk calls. Companies can join the waitlist for early access.