Some of the most destructive breaches against large companies didn't begin with cutting-edge exploits or malicious software, according to a new analysis from Infosecurity Magazine. They started with a phone call to the help desk. The analysis examines how the Scattered Spider hacking group uses social engineering to turn routine account-recovery procedures into a pathway around security systems, with recent 2025 attacks on UK retailers demonstrating how vulnerable these processes remain.
The group's recent targets include high-profile organizations where social engineering and identity theft were central to the attack. In 2023, Scattered Spider claimed involvement in the MGM Resorts breach, where social engineering enabled initial access before the incident grew into widespread operational chaos and ransomware deployment. UK retailer Marks and Spencer faced a highly focused cyber-attack in April 2025 that severely disrupted its online systems and led to customer information being stolen. Co-op was hit during the same attack wave, with intruders using social engineering to compromise an employee account. Harrods also became a target in April 2025, limiting internet connectivity across portions of its infrastructure after identifying efforts to obtain unauthorized entry.
The attack method follows a consistent pattern. First, attackers construct a believable identity by mining LinkedIn for employee details or gathering information from company sites and breach databases, sometimes reinforcing their impersonation with caller-ID spoofing or SIM-swapped phones. Next, they contact the service desk posing as a legitimate employee facing an urgent problem—a lost phone, malfunctioning authenticator, or locked account before an important meeting. The report notes that during the Co-op attack, CDIO Rob Elsey told Parliament the attackers successfully answered multiple security questions while impersonating a colleague, had the account reset, and within roughly an hour the company spotted malicious activity tied to that account. CISA warns specifically that Scattered Spider uses social engineering to convince service desk staff to reset login credentials and move MFA tokens, letting the attacker seize control of the target account in single sign-on environments.
The analysis finds the service desk represents a repeated weak point across Scattered Spider attacks, with attackers exploiting gaps in account-recovery and identity-verification workflows to convert convincing impersonation into access. The core issue isn't that support teams are overly accommodating, but that they're asked to approve sensitive actions—password resets, MFA modifications—using information that provides weak proof of identity. When details like name, job title, employee number, manager, or location are accepted as identity verification, attackers can arrive prepared with correct answers, make a standard request, and abuse the same recovery systems built to help real users regain access. The service desk effectively sits upstream of many identity controls organizations rely on, meaning a password reset or MFA change may appear to be an administrative support task but both are security-critical actions that determine who the organization accepts as a legitimate user.
To reduce risk, the report recommends organizations strengthen identity verification for password resets using out-of-band checks through known secondary contact methods, protect MFA resets by requiring additional verification before tokens can be reset or transferred, and train service desk teams to recognize social engineering tactics including urgent or emotional requests and spoofed internal numbers. Organizations should monitor unusual service desk patterns such as repeated password resets or MFA removals for privileged accounts, limit service desk privileges by requiring escalation before agents can reset credentials for administrative and high-risk accounts, apply role-based access controls with detailed audit logs that alert security teams to high-risk changes, and test processes regularly with social engineering simulations covering phone and chat-based attacks beyond email phishing. The bottom line: strong authentication at login loses its value if the process for recovering an account relies on identity checks an attacker can satisfy. Service desks that layer identity verification and escalation requirements into account recovery can close the gap that makes social engineering so effective, turning what's now a vulnerability into a genuine barrier for attackers who arrive prepared with employee details and polished scripts.

