AUTO-UPDATED

Why your help desk is still your biggest security risk

Cybercriminals are increasingly exploiting corporate help desks through social engineering and AI-driven impersonation to bypass traditional security measures, leading to significant data breaches at major organizations like MGM Resorts.

Key Points

  • Attackers use basic reconnaissance to impersonate employees, tricking help desk staff into resetting credentials and granting unauthorized network access.
  • Phishing and spoofing scams have surged by over 85%, with average financial losses per incident more than doubling to $2,060.
  • The U.S. Department of Health and Human Services warned that adversaries are now utilizing AI voice impersonation to target hospital support staff.
  • Security experts recommend replacing static security questions with dynamic verification and implementing device-bound passkeys to ensure credentials remain tied to legitimate hardware.
  • Organizations are encouraged to adopt bi-directional verification, requiring both the caller and the help desk agent to confirm their identities before sensitive actions occur.

Why it Matters

Help desks have become a critical security blind spot because they prioritize rapid productivity over rigorous identity verification, effectively bypassing advanced network firewalls. By failing to secure these human-centric entry points, companies leave themselves vulnerable to attackers who can easily manipulate staff to gain full system access.
TechRadar Published by Greg Nelson
Read original