3 retailers
M&S, Co-op, and Harrods all breached in 2026 via service desk social engineering — the same technique, the same group
63%
of IT professionals rate AI-enhanced social engineering as their top threat in 2026
4 questions
average number of identity verification questions IT service desks ask before resetting credentials — most answers are findable via LinkedIn and company websites

SponsoredRetool

Retool's new app builder is where AI-generated code ships safely

Building apps with AI is easy. Getting them to production safely is another story.

Start building for free today

Attackers calling your IT helpdesk and impersonating employees to get credentials reset is not a new technique. What is new is the scale, the tooling, and the results. The Scattered Spider group used helpdesk social engineering to breach Caesars Entertainment, MGM Resorts, and then the 2026 UK retail sector — executing the same playbook across multiple high-profile targets because it works against organizations that have not changed their identity verification processes.

The attack succeeds because service desk agents face competing pressures: verify identity carefully versus resolve tickets quickly. When a caller sounds legitimate, references internal project names, uses correct organizational terminology, and expresses frustration at being locked out, most agents approve the reset. The controls below make social engineering harder — not by training agents to be more suspicious, but by making verification independent of the caller's convincingness.

How the helpdesk attack works

The Scattered Spider service desk pattern is documented across multiple incidents and follows a consistent sequence.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Control 1: Out-of-band identity verification via manager or known contact

The most reliable verification control that cannot be defeated by OSINT is callback verification through a known, pre-established contact — not through information the caller provides.

Process: When any credential reset or MFA modification is requested by phone or chat, the service desk agent does not process the request immediately. Instead, the agent closes the interaction and initiates a callback to the requestor through a verified contact method: their corporate email (send a verification link), their Teams/Slack handle (send a one-time code), or their manager's verified contact (confirm the employee is actually requesting a reset). The requester cannot continue until they confirm through the second channel.

This process adds 2 to 5 minutes to a legitimate reset. It makes social engineering via phone alone impossible — the attacker cannot receive verification links sent to the target employee's email or chat account.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

Control 2: Tiered verification based on request sensitivity

Not all service desk requests carry the same risk. Password resets for standard user accounts are lower risk than MFA resets, privileged account credential changes, or VPN access provisioning.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Control 3: Real-time alerting to the employee being impersonated

Even when verification fails and a reset proceeds, immediate notification to the impersonated employee creates a detection window before the attacker can fully exploit the access.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Control 4: Move high-privilege MFA resets off the phone channel entirely

For administrative accounts, executive accounts, and IT staff accounts, eliminate the phone reset channel. MFA resets for these tiers require: physical presence at an IT security desk with government ID, or a pre-established emergency recovery process using a hardware backup key (a second FIDO2 key registered to the account and stored in a secured physical location).

If an executive genuinely cannot authenticate — travel, lost phone, phone replacement — they use their backup hardware key. If the backup key is also unavailable, they escalate to a physical in-person process with IT security. There is no phone pathway that can bypass this.

This eliminates the social engineering vector for the accounts that matter most, at the cost of slightly more friction in rare legitimate lockout scenarios — a trade-off that every organization that has experienced a helpdesk social engineering breach would make again.

The bottom line

Helpdesk social engineering succeeds against organizations that verify identity based on what a caller knows. It fails against organizations that verify identity through out-of-band channels the caller cannot control and hardware credentials the caller cannot replicate. The controls are procedural, not technical — they require policy changes and agent training, not new tool purchases. The organizations breached by Scattered Spider were not technologically unsophisticated; they had not closed the procedural gap between agent pressure to resolve quickly and the verification rigor required to stop a well-prepared social engineer.

Frequently asked questions

How did Scattered Spider breach MGM Resorts specifically?

Public reporting indicates Scattered Spider social-engineered the MGM IT help desk by impersonating an employee and convincing the agent to reset MFA. The attacker researched the target employee on LinkedIn before the call, provided convincing identity details, and used urgency framing. The breach resulted in an estimated $100 million in losses. MGM has not publicly confirmed all technical details of the initial access method.

Is self-service password reset safer than agent-assisted resets?

Self-service password reset through a portal that sends a verification link to the employee's corporate email or registered mobile device is generally more secure than agent-assisted phone resets — the identity verification is automatic and cannot be manipulated by social engineering. Self-service with email verification eliminates the agent judgment variable. Enable self-service password reset for standard accounts and reserve agent-assisted processes only for accounts where self-service has failed after proper verification.

What questions should a service desk agent ask to verify identity?

Knowledge-based questions alone are insufficient. The most secure verification process does not rely on questions at all — it uses callback to a verified channel (corporate email, Teams/Slack DM to the account in question) where only the legitimate account holder can respond. If knowledge-based questions must be used as one factor, pair them with a mandatory callback, never use them alone for privileged account modifications.

Sources & references

  1. Marks & Spencer Breach Analysis - BleepingComputer
  2. HYPR: How to Prevent Helpdesk Social Engineering Attacks
  3. Infosecurity Magazine: Anatomy of a Service Desk Social Engineering Attack

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Black Hat Giveaway

Win a $2,495 Black Hat pass.

Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.

Joins Decryption Digest daily briefing. Unsubscribe anytime.

Giveaway: Black Hat USA 2026 Full-Access Pass ($2,495 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $2,495 Black Hat USA 2026 pass.