It’s Friday, ten past six. Your help desk has two agents left on shift and a queue display that says four callers waiting. The next call is a man who introduces himself as Marcus from revenue operations. He’s at the airport, his flight boards in forty minutes, his new phone won’t accept the authenticator transfer, and he’s locked out of everything he needs for Monday’s close. He has his employee number ready. He knows his manager’s name, and that she’s on leave until Wednesday, which is why she can’t vouch for him. He’s polite, slightly embarrassed, exactly as stressed as a real person would be. The agent has closed forty-one tickets today. Resetting one authenticator takes four minutes and makes both the queue and this man’s evening shorter.
That call, give or take the details, is how MGM Resorts went down in September 2023. It’s also, in mirror image, how thousands of employees get talked into installing remote access tools by someone claiming to be their own IT department. Same weakness, two directions: on a phone call, neither side can prove who they are.
One phone call, ten days of outage
In early September 2023, attackers linked to the group tracked as Scattered Spider looked up an MGM employee on LinkedIn, called the company’s IT help desk, and impersonated him. Reporting at the time put the call at around ten minutes. The reset they obtained led to privileged access in MGM’s Okta identity environment, and from there to ransomware across the estate: slot machines roped off on the Las Vegas floor, digital room keys dead, reservation systems down, roughly ten days of disruption. In an SEC filing the following month, MGM put the hit at about $100 million for the quarter, plus some $10 million in one-off response costs, and confirmed that customer data including Social Security and passport numbers had been stolen.
The Clorox case is less famous and more instructive for anyone who outsources their service desk. In August 2023, a caller rang the help desk that Cognizant operated for Clorox and asked for password and MFA resets on employee accounts. According to the lawsuit Clorox filed in July 2025, agents handed them over without asking for an employee ID, a manager’s name, or anything else the written procedure required; the complaint quotes call transcripts in which the agent simply supplies the credentials. Clorox says the resulting breach forced plants into manual operation and caused months of product shortages, and it is claiming roughly $380 million. Whatever the court decides, the filing already turned help desk verification procedure into a board-level, litigable question. If your reset flow lives with a vendor, the contract now matters as much as the firewall.
The same con runs in the other direction
Flip the roles and the script still works. Instead of calling the help desk as an employee, the attacker calls an employee as the help desk. “This is IT security, we’re seeing malware beaconing from your machine. I need you to install this remote support tool so I can clean it,” or, cheaper still, “I’ve just pushed a reset to your phone, read me the code on your screen so I can confirm it’s you.” A variant softens the target first by spamming MFA push notifications at 2 a.m., then calling in the morning as IT support offering to make the annoyance stop.
None of this is speculative. The joint CISA and FBI advisory on Scattered Spider, first issued in November 2023 and updated as recently as July 2025, describes exactly this dual playbook: threat actors who impersonate employees to help desks to obtain resets, and who impersonate IT and help desk staff to employees to harvest credentials, trigger MFA fatigue, and get remote access tools installed. The group’s callers are fluent, confident, and rehearsed. Most employees have never received a legitimate cold call from IT, but they also have no way to check whether this one is real.
Why knowledge-based checks stopped working
Most help desks verify callers by asking things the caller should know. Employee ID, date of birth, manager’s name, office location, maybe the last ticket they raised. Twenty years ago that was a reasonable filter. Today the org chart is on LinkedIn, birth dates and home addresses are in breach dumps, and infostealer logs sold for a few dollars contain the employee’s browser history, saved credentials, and often screenshots of the intranet. The attacker preparing the call has all of it open in front of them.
There’s a crueller problem underneath, one I keep noticing in incident write-ups: the attacker outperforms the genuine employee. The real Marcus, phoning in a panic, hesitates over his employee number and can’t remember which ticket he raised in March. The impostor answers instantly, because he prepared. Agents measured on handle time and caller satisfaction learn to read confidence as legitimacy, and confidence is the one thing a professional social engineer never lacks. Knowledge-based verification doesn’t just fail against this adversary; it actively selects for him.
The real countermeasures and what they cost
Callback is the strongest simple control: hang up and call the employee back on the mobile number stored in the HR system, never on the number they called from. It works because the attacker doesn’t control that phone. Its costs are real, though. Numbers go stale, new joiners aren’t in the system yet, and a SIM swap, which Scattered Spider also uses, can capture the callback. The classic pretext, “I lost my phone, that’s why I’m calling from this one,” is engineered specifically to make callback feel pointless. It isn’t: a lost-phone claim should raise the verification tier, not lower it.
Video calls with a liveness check, comparing the caller against the HR photo, raise the bar further. Be honest about their ceiling: real-time face-swapping tools are now commodity, and a help desk agent squinting at a compressed video feed is not a deepfake detector. Video raises the attacker’s cost; it doesn’t retire the risk.
Manager approval loops add a second human. They’re also slow, they break when the manager is on a plane, and how is the approval itself verified? An email “from” the manager is exactly as forgeable as the original call.
Passkeys and FIDO2 change what a stolen reset is worth: with phishing-resistant credentials there is no password to hand over and no OTP to read aloud. But the enrollment and recovery flow becomes the new crown jewel. “Register a new passkey for this user” is now equivalent to issuing an identity: treat it as a privileged change with the strongest verification you have, not a routine ticket.
A protocol for both directions
Here’s the shape of a defensible procedure, compressed:
- Tier the actions. A password reset, an MFA re-enrollment, and a reset on a privileged or executive account are different risk classes. Each tier gets stronger verification, and the top tier is never completed on a single inbound call.
- Ban static knowledge as proof. Anything discoverable about a person, ID numbers, birth dates, manager names, verifies nothing. It can route a ticket; it cannot authorize one.
- Call back on the HR-record number, always. If the caller claims that number is dead, the request escalates to in-person or video verification with a second approver. Escalates, never downgrades.
- Treat MFA and contact-detail changes as privileged operations. Notify the old device and the manager, and hold the change in a short delay window during which the real employee can object.
- Give agents the right to refuse. Put it in writing that no executive, however angry, is entitled to a same-call reset. An agent who says no under pressure gets thanked, publicly.
- Tell employees what IT will never do. IT will never cold-call asking you to read out a code, approve a push, install remote software, or share a password. One sentence, repeated until it’s boring.
The employee-facing direction needs only one habit to go with that last rule: hang up and call back through the published internal help desk number or raise a ticket, then report the original call even if you didn’t fall for it. The first employee who reports a fake IT call is usually the only warning the SOC gets that a campaign has started.
Verification that doesn’t depend on knowledge or voice
Everything above still leans on a channel where identity is asserted, then argued about. That asymmetry is the reason we built Hongi. Two people pair once, in person, by scanning a QR code; from then on, each of them sees a rotating codeword, refreshed every 30 seconds and computed offline on their own devices. When someone calls claiming to be a colleague, or claiming to be IT, you ask for the current codeword. An impersonator can’t know it: it doesn’t live in a breach dump, it can’t be cloned like a voice, and it changes before it can be replayed.
For a small team, this works today with the free app: pair every employee with the help desk, or colleagues with each other, in an afternoon. I’ll be straightforward about the limits: at enterprise scale you’d want directory integration and an SDK inside your existing tooling; that track is on our roadmap, not yet in the product. If the direction interests you, the details are on our page for organizations, and the FAQ covers how the codeword mechanism works underneath.
The help desk used to sit behind the perimeter. The calls above are what it sounds like now that it is the perimeter. Verify accordingly.