Securing the service desk: Why social engineering attacks keep succeeding
ID: 7daddb8c-f9eb-538d-b2ba-6cf05bb387bc
STIX ID: report--7daddb8c-f9eb-538d-b2ba-6cf05bb387bc
Feed Name: Bleeping Computer
This report examines how attackers target outsourced and internal service desks using social engineering (reconnaissance, impersonation, caller ID/SIM swap, MFA bypass) to obtain credentials and escalate access—citing Scattered Spider, Silent Ransom Group, and recent incidents against retailers and Carnival—and recommends verification controls, stricter MFA reset policies, monitoring of help-desk activity, privilege limitations, and red-team testing; it concludes with promotion of Specops Secure Service Desk as a mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
