iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
El Nino May Weaken India's Monsoon, Threaten Rice and Maize Output, FAO Warns Nigel Farage Warns UK Social Media Ban 'Unlikely to Work' Due to VPNs YouTube Premium at $16 Includes YouTube Music: Subscription Swap Analysis for Heavy Users New Lara Croft voice actor calls role 'the pinnacle' for gaming actresses ahead of 2027 Tomb Raider games Sarvam AI Raises $234M Led by HCLTech, Becomes India's Newest Unicorn Kerala University unveils vision plan for sustainable fisheries and blue economy growth Potensic Atom 3 drone launch underscores US import ban on all foreign-made drones Tanzania's Mohammed Dewji: East African Conglomerate and Africa's Billionaire Landscape Alien: Isolation 2 Brings Classic Horror's Uncompromising Tension to New Setting Trump's UFC White House Event Opens Lobbying Channel for Corporate Interests El Nino May Weaken India's Monsoon, Threaten Rice and Maize Output, FAO Warns Nigel Farage Warns UK Social Media Ban 'Unlikely to Work' Due to VPNs YouTube Premium at $16 Includes YouTube Music: Subscription Swap Analysis for Heavy Users New Lara Croft voice actor calls role 'the pinnacle' for gaming actresses ahead of 2027 Tomb Raider games Sarvam AI Raises $234M Led by HCLTech, Becomes India's Newest Unicorn Kerala University unveils vision plan for sustainable fisheries and blue economy growth Potensic Atom 3 drone launch underscores US import ban on all foreign-made drones Tanzania's Mohammed Dewji: East African Conglomerate and Africa's Billionaire Landscape Alien: Isolation 2 Brings Classic Horror's Uncompromising Tension to New Setting Trump's UFC White House Event Opens Lobbying Channel for Corporate Interests
Home ›› Technology ›› Ai ›› Llms ›› Why Your Help Desk Remains the Biggest Security Risk in Your Organization

Why Your Help Desk Remains the Biggest Security Risk in Your Organization

TechRadar reports that help desk social engineering attacks, like those that hit MGM Resorts, Marks & Spencer, and Harrods, bypass most security controls. AI has amplified the threat, with phishing scams up 85% and average losses doubling to $2,060. Best practices include hardening identity operations and tying device enrollment to identity.

iG
iGEN Editorial
June 15, 2026
Why Your Help Desk Remains the Biggest Security Risk in Your Organization

When MGM Resorts suffered a crippling cyberattack in 2023, forensic teams expected to find sophisticated malware or a zero-day exploit. Instead, they discovered something far simpler: an attacker called the help desk, impersonated an employee, and was handed the keys to the kingdom, according to TechRadar. Marks & Spencer and Harrods fell victim to similar attacks in 2025. This pattern reveals a harsh reality – organizations spend millions hardening networks and endpoints while leaving identity, their most vulnerable entry point, completely exposed.

The Vulnerability That Bypasses Most Security Controls

Help desks are under constant pressure to restore locked-out employees' productivity quickly, TechRadar reports. This creates an environment where speed often trumps security. The typical interaction follows a predictable path: the caller provides basic identifying information, explains why they need access, and receives credentials. For an attacker who has done minimal reconnaissance on LinkedIn or company websites, this is trivial to replicate.

This attack vector is particularly dangerous because it bypasses most security controls, such as firewalls, endpoint detection, and network monitoring. These measures are blind to an attacker who talks their way through the front door with legitimate credentials issued by your own staff.

Why AI Has Made This an Urgent Crisis

Artificial intelligence has lowered the barrier for social engineering attacks, TechRadar notes. The U.S. Department of Health and Human Services has warned that adversaries are using AI voice impersonation to target hospital help desks. Accelerated by AI, phishing and spoofing scams increased by over 85%, and the average financial losses have more than doubled from $1,000 to $2,060.

Metric Before AI-Driven Attacks After AI-Driven Attacks Change
Phishing & spoofing scam volume Baseline +85% Significant increase
Average financial loss per incident $1,000 $2,060 106% increase

Three Best Practices for Help Desk Security

TechRadar outlines two interconnected controls (the third was not fully detailed in the source):

1. Harden Identity Operations

Every access request should trigger the same verification standards. Multi-factor authentication cannot be optional or easy to bypass. Implement passwordless, phishing-resistant authentication methods using industry standards. However, even passwordless systems can be compromised if credential recovery and enrollment processes remain vulnerable to social engineering. Security questions based on static information should be replaced with dynamic verification that is harder to research or guess. Conduct regular identity governance reviews to eliminate stale accounts and ensure no identity has more access than necessary.

2. Tie Device Enrollment to Identity

When resetting credentials or restoring access, verify that the receiving device belongs to the legitimate user. Device-bound credentials can prevent attackers from using stolen passwords on unauthorized hardware.

The most common pushback to strengthening help desk security is operational. What happens when an executive loses their phone while traveling? What if an employee legitimately cannot access their registered device? The answer is tiered response protocols combined with the controls above, TechRadar reports. While the third control was not fully described in the source, the two listed practices form a strong foundation to close the help desk vulnerability gap.


Sources: TechRadar – Main Feed

Keep Reading

Recommended Stories

Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations Technology

Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations

Oracle has issued a security advisory for a critical remote code execution vulnerability (CVE-2026-35273, CVSS 9.8) in PeopleSoft versions 8.61 and 8.62. The extortion group ShinyHunters is exploiting it, claiming to have breached over 100 organizations and exfiltrated data from ~300 instances. Google's Mandiant reported zero-day exploitation between May 27 and June 9, 2026, and alerted over 100 potentially vulnerable entities.

June 15, 2026
FBI Dismantles AI-Powered Phishing Service That Used Over a Million URLs to Steal Credit Cards Technology

FBI Dismantles AI-Powered Phishing Service That Used Over a Million URLs to Steal Credit Cards

The FBI dismantled a Chinese phishing-as-a-service operation called Outsider Enterprise, seizing servers, cryptocurrency, and a Telegram bot. The three-year-old service generated around 9,000 fake websites and over a million fraudulent URLs, resulting in theft of 3.8 million credit card records and $1.9 billion in losses. Google filed a civil lawsuit and reported that criminals sent 2.5 million fraudulent SMS messages in just two weeks.

June 15, 2026
Check Point Patches Critical VPN Flaw Exploited by Qilin Ransomware Group Technology

Check Point Patches Critical VPN Flaw Exploited by Qilin Ransomware Group

Check Point addressed a critical VPN authentication bypass vulnerability (CVE-2026-50751, CVSS 9.3) that has been exploited by the Qilin ransomware group since early May 2026. The attacks affected dozens of organizations globally, with at least one case leading to Qilin ransomware deployment. Customers are urged to apply fixes and mitigations immediately.

June 14, 2026
1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever Technology

1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever

Troy Hunt loaded the 1,000th breach into Have I Been Pwned, highlighting that disclosure lag times are worsening despite GDPR and CCPA. Examples include Carnival's 43-day delay and Zara's 45-day silence after ShinyHunters attacks, leaving victims uninformed for weeks.

June 14, 2026