Keypoints
- MFA raises the bar for account takeover, but attackers now target recovery workflows.
- Service desks can become the weakest link if identity checks are too easy to fake.
- Scattered Spider has used impersonation to persuade help desks to reset passwords and MFA.
- The Marks & Spencer attack showed how social engineering can lead to ransomware and major losses.
- Stronger identity verification should be built into sensitive service desk actions like resets and unlocks.