Service Desk Social Engineering Attacks Keep Succeeding — Here's Why
Executive Briefing
- Attackers target service desks because staff are trained to help, making them susceptible to urgent impersonation attempts.
- Scattered Spider breached M&S, Co-op, and Harrods by convincing service desk agents to reset employee credentials.
- Social engineering bypasses firewalls entirely, granting legitimate access in minutes without triggering security alerts.
- Stolen credentials factor in 44.7% of breaches, per Verizon's 2025 Data Breach Investigation Report.
- Experts recommend strict out-of-band identity verification, MFA protections, and regular social engineering simulations to defend service desks.
Sponsored