Cybercriminals are increasingly exploiting corporate help desks through social engineering and AI-driven impersonation to bypass traditional security measures, leading to significant data breaches at major organizations like MGM Resorts.
Key Points
- Attackers use basic reconnaissance to impersonate employees, tricking help desk staff into resetting credentials and granting unauthorized network access.
- Phishing and spoofing scams have surged by over 85%, with average financial losses per incident more than doubling to $2,060.
- The U.S. Department of Health and Human Services warned that adversaries are now utilizing AI voice impersonation to target hospital support staff.
- Security experts recommend replacing static security questions with dynamic verification and implementing device-bound passkeys to ensure credentials remain tied to legitimate hardware.
- Organizations are encouraged to adopt bi-directional verification, requiring both the caller and the help desk agent to confirm their identities before sensitive actions occur.