iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports Domestic Sugar Prices to Remain Firm in Short-Term, Says Triveni Engineering Saia’s Softer Q3 Margin Guidance Triggers 12% Share Drop Despite Record Q2 Results Buffalo meat and non-basmati rice lead 14% surge in India's Q1 agri exports Mahindra & Mahindra Records 34% Profit Jump Despite Commodity Cost Headwinds CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports Domestic Sugar Prices to Remain Firm in Short-Term, Says Triveni Engineering Saia’s Softer Q3 Margin Guidance Triggers 12% Share Drop Despite Record Q2 Results Buffalo meat and non-basmati rice lead 14% surge in India's Q1 agri exports Mahindra & Mahindra Records 34% Profit Jump Despite Commodity Cost Headwinds
Home ›› Technology ›› Ai ›› Llms ›› Why Your Help Desk Remains the Biggest Security Risk in Your Organization

Why Your Help Desk Remains the Biggest Security Risk in Your Organization

TechRadar reports that help desk social engineering attacks, like those that hit MGM Resorts, Marks & Spencer, and Harrods, bypass most security controls. AI has amplified the threat, with phishing scams up 85% and average losses doubling to $2,060. Best practices include hardening identity operations and tying device enrollment to identity.

iG
iGEN Editorial
June 15, 2026
Why Your Help Desk Remains the Biggest Security Risk in Your Organization

When MGM Resorts suffered a crippling cyberattack in 2023, forensic teams expected to find sophisticated malware or a zero-day exploit. Instead, they discovered something far simpler: an attacker called the help desk, impersonated an employee, and was handed the keys to the kingdom, according to TechRadar. Marks & Spencer and Harrods fell victim to similar attacks in 2025. This pattern reveals a harsh reality – organizations spend millions hardening networks and endpoints while leaving identity, their most vulnerable entry point, completely exposed.

The Vulnerability That Bypasses Most Security Controls

Help desks are under constant pressure to restore locked-out employees' productivity quickly, TechRadar reports. This creates an environment where speed often trumps security. The typical interaction follows a predictable path: the caller provides basic identifying information, explains why they need access, and receives credentials. For an attacker who has done minimal reconnaissance on LinkedIn or company websites, this is trivial to replicate.

This attack vector is particularly dangerous because it bypasses most security controls, such as firewalls, endpoint detection, and network monitoring. These measures are blind to an attacker who talks their way through the front door with legitimate credentials issued by your own staff.

Why AI Has Made This an Urgent Crisis

Artificial intelligence has lowered the barrier for social engineering attacks, TechRadar notes. The U.S. Department of Health and Human Services has warned that adversaries are using AI voice impersonation to target hospital help desks. Accelerated by AI, phishing and spoofing scams increased by over 85%, and the average financial losses have more than doubled from $1,000 to $2,060.

Metric Before AI-Driven Attacks After AI-Driven Attacks Change
Phishing & spoofing scam volume Baseline +85% Significant increase
Average financial loss per incident $1,000 $2,060 106% increase

Three Best Practices for Help Desk Security

TechRadar outlines two interconnected controls (the third was not fully detailed in the source):

1. Harden Identity Operations

Every access request should trigger the same verification standards. Multi-factor authentication cannot be optional or easy to bypass. Implement passwordless, phishing-resistant authentication methods using industry standards. However, even passwordless systems can be compromised if credential recovery and enrollment processes remain vulnerable to social engineering. Security questions based on static information should be replaced with dynamic verification that is harder to research or guess. Conduct regular identity governance reviews to eliminate stale accounts and ensure no identity has more access than necessary.

2. Tie Device Enrollment to Identity

When resetting credentials or restoring access, verify that the receiving device belongs to the legitimate user. Device-bound credentials can prevent attackers from using stolen passwords on unauthorized hardware.

The most common pushback to strengthening help desk security is operational. What happens when an executive loses their phone while traveling? What if an employee legitimately cannot access their registered device? The answer is tiered response protocols combined with the controls above, TechRadar reports. While the third control was not fully described in the source, the two listed practices form a strong foundation to close the help desk vulnerability gap.


Sources: TechRadar – Main Feed

Keep Reading

Recommended Stories

Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports Technology

Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports

Google Chrome's security team has moved to twice-a-week patching after AI vulnerability hunting led to a surge in bug discoveries. In June, the browser fixed 1,072 security bugs—more than the prior 23 releases combined. The team sees this as a near-term spike but expects a new equilibrium.

July 30, 2026
AI Scammers Outperform Humans in Building Trust, New Study Finds Technology

AI Scammers Outperform Humans in Building Trust, New Study Finds

A new study from four universities tested AI chatbots against human scammers in trust-building phases of pig butchering fraud. The AI outperformed humans, with nearly half of test subjects complying compared to fewer than one in five for humans. The findings highlight the growing threat of AI-powered social engineering, potentially replacing forced-labor workers in Southeast Asian scam operations.

July 30, 2026
Jailbreaking Frontier AI Models Is Cheap and Easy, New Report Warns Enterprise Users Technology

Jailbreaking Frontier AI Models Is Cheap and Easy, New Report Warns Enterprise Users

A new report from AI safety nonprofit FAR.AI shows that jailbreaking some of the most advanced AI models is frighteningly easy and cheap—as low as $58 for Grok. The findings highlight the need for enterprise buyers to scrutinize model safety before deployment.

July 29, 2026
Cyber frauds shift to on-call scams and mule networks, Biocatch report reveals Technology

Cyber frauds shift to on-call scams and mule networks, Biocatch report reveals

India's cyber-fraud landscape is pivoting from device takeover to real-time social engineering, with victims executing transfers under live phone guidance. A Biocatch report shows attempted fraud sessions fell 12% but value rose 35%. Meanwhile, the CBI identified over 8.5 lakh mule accounts in 2025, with total complaints linked to Rs 22,496 crore in fraud.

July 27, 2026