Skip to content
  • About
  • Documents
  • Resources
  • Governance
  • Public & Legal Notices
    • Public & Legal Notices Archive
  • Login (Members Only)
  • Contact
IT Help Desk Staff Targeted
  • View Larger Image computer keyboard with IT support
Beware of Threat Actors Targeting IT Help Desk Staff
Information technology (IT) help desk staff are heavily targeted because they often possess privileged administrative rights and provide an entry point for account recovery, such as resetting passwords and bypassing multi-factor authentication (MFA). To identify high-value targets, threat actors perform reconnaissance on corporate websites, networking platforms such as LinkedIn, or social media websites. They pose as legitimate employees and use voice phishing (vishing) in their social engineering attacks to trick internal or outsourced IT help desk staff into bypassing controls. Vishing, which has surged significantly over the past several years, combined with publicly available information and artificial intelligence (AI), enables threat actors to increasingly impersonate legitimate employees, clone voices, and create audio deepfakes.
In IT help desk schemes, threat actors claim they were locked out of their account, could not access their authenticator, lost their phone, or damaged their laptop. They may also create urgent or stressful scenarios, such as a business meeting starting shortly or an employee traveling on business, and request immediate access to the account. Once threat actors convince the IT help desk staff to reset the password or disable the original MFA token, they can register their own device, granting them complete, legitimate access to the network. Prominent and aggressive threat actors, such as Scattered Spider and O-UNC-034, have posed as employees or traveling executives to initiate account takeovers. Their main goal is to infiltrate networks, establish persistence, move laterally to critical assets, access internal applications or cloud services, exfiltrate data, and deploy ransomware.
The NJCCIC received a report of threat actors impersonating an employee of a New Jersey organization and contacting the organization’s outsourced IT help desk to reset their password. The IT help desk staff bypassed established procedures, reset the password, and set up the corporate app on the device. The threat actors then accessed the account and changed the impersonated employee’s bank account information for direct deposit to a threat actor-controlled account.
Recommendations
  • Reduce publicly available information about employees, organizational structures, and operational processes that threat actors could use to target them.
  • Assess IT help desk staff privileges and access management tools and processes, such as independent validation, escalation controls, and secondary approvals, before initiating sensitive requests.
  • Help desk staff are advised to:
    • Verify the caller’s identity, such as manager callback, video call, or employee ID verification.
    • Apply a temporary bypass, such as enabling a short-term exclusion window (e.g., 30 minutes) or issuing a one-time Temporary Access Pass (TAP).
    • Instruct the user to log in immediately to register their new permanent MFA device.
    • Log the incident for auditing purposes, such as ticket details, verification method, and performed actions.

Published by NJCCIC Weekly Newsletter August 6, 2026

Stacey Ehling2026-08-06T13:52:02-04:00

© Copyright 2026 | NJ MEL-JIF | All rights reserved

Page load link
Go to Top