| Information technology (IT) help desk staff are heavily targeted because they often possess privileged administrative rights and provide an entry point for account recovery, such as resetting passwords and bypassing multi-factor authentication (MFA). To identify high-value targets, threat actors perform reconnaissance on corporate websites, networking platforms such as LinkedIn, or social media websites. They pose as legitimate employees and use voice phishing (vishing) in their social engineering attacks to trick internal or outsourced IT help desk staff into bypassing controls. Vishing, which has surged significantly over the past several years, combined with publicly available information and artificial intelligence (AI), enables threat actors to increasingly impersonate legitimate employees, clone voices, and create audio deepfakes. |
| In IT help desk schemes, threat actors claim they were locked out of their account, could not access their authenticator, lost their phone, or damaged their laptop. They may also create urgent or stressful scenarios, such as a business meeting starting shortly or an employee traveling on business, and request immediate access to the account. Once threat actors convince the IT help desk staff to reset the password or disable the original MFA token, they can register their own device, granting them complete, legitimate access to the network. Prominent and aggressive threat actors, such as Scattered Spider and O-UNC-034, have posed as employees or traveling executives to initiate account takeovers. Their main goal is to infiltrate networks, establish persistence, move laterally to critical assets, access internal applications or cloud services, exfiltrate data, and deploy ransomware. |
| The NJCCIC received a report of threat actors impersonating an employee of a New Jersey organization and contacting the organization’s outsourced IT help desk to reset their password. The IT help desk staff bypassed established procedures, reset the password, and set up the corporate app on the device. The threat actors then accessed the account and changed the impersonated employee’s bank account information for direct deposit to a threat actor-controlled account. |