5 MIN READ
The IT help desk was built to be helpful. That is the entire point of the function, the operator on the phone who wants to solve your problem before lunch, and the operator has been trained on exactly that since week one. The attacker has noticed, and the attacker is now the single largest source of social engineering incidents in the enterprise. The 2025 Verizon DBIR put the help desk at the top of the pretexting list for the third year running. The help desk is the front door, and the front door is open.
What the attack looks like in practice. A caller pretends to be an employee who is travelling, who has lost access, who needs the password reset urgently for the client meeting that starts in 30 minutes. The operator wants to help. The operator walks through the reset. The new credentials land in an inbox the operator has never seen, and the breach is now in progress. The operator never knows, the employee never knows, and the security team finds out three weeks later when the lateral movement shows up in the SIEM. The Okta and Microsoft Digital Crimes Unit briefings from 2024 and 2025 both name the help desk as the primary entry point for the initial access broker.
What actually works at the help desk
Verification through a channel the caller cannot control. The callback to the phone number on file, the video call where the government ID matches the requester, the in person visit at the desk for the high risk changes. Push the verification step into the runbook, into the training, and into the ticketing system, and the social engineer loses the easiest path in. The 2025 SANS Help Desk Security Survey found that organisations with a mandatory callback step for password resets reported 71 percent fewer successful social engineering attempts than organisations without one. The verification step is the cheapest control on the menu, and it is the one most often left out of the runbook.
What changes behind the help desk
Manager approval on the high risk changes. Password resets are routine, MFA disables are not, granting access to a sensitive system is not. A Slack message to the line manager, an email confirmation through a separate channel, a ticketing system notification that requires a click before the change goes through. The friction looks small on paper, and the friction is the entire point. Real employees tolerate a 90 second approval step. Social engineers do not, because the social engineer cannot stay on the phone long enough to push through the additional round trip. The recent Coinbase and Twilio internal incidents both involved a help desk reset that should have required a manager sign off, and both incidents had a manager sign off workflow that nobody was using.
What catches the reset the help desk missed
Detection on the back end. The reset at 2 AM from a phone number the user has never called from. The reset that is not followed by a login inside ten minutes. The reset followed by an immediate change to the recovery email or the MFA factor, which is a pattern the infostealer crews have been running for two years. Splunk, Sentinel, and Elastic all ship detections for this. The security operations team needs to wire them, tune them, and act on them. The reset that gets past the help desk still has to walk past the SIEM, and the SIEM is the second chance the defender has been leaving on the table.

The bottom line
Verification at the desk, manager approval on the high risk changes, detection on the back end. The help desk operator is not the security perimeter, but the help desk operator is the place the attacker walks in. Treat the runbook like the security control it has quietly become.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



