Account recovery attacks are increasingly being used to bypass multi-factor authentication, with cyber criminals impersonating employees and persuading help-desk staff to reset passwords or move authentication to devices they control.
The shift has made service desks an important part of an organisation’s identity-security boundary. While multi-factor authentication can prevent stolen passwords from being used on their own, a weak recovery process may allow attackers to replace the additional protection altogether.
Employees regularly lose phones, damage devices, change telephone numbers or mislay security keys. When self-service recovery is unavailable, support agents may have powers to reset passwords, remove authentication methods, issue temporary credentials or approve a new authenticator.
Those actions are necessary for legitimate users, but they also provide a route into protected accounts. If a caller can regain access by answering basic questions or supplying information gathered online, the recovery process may offer less protection than the login system it is intended to restore.
Scattered Spider tactics exposed the risk
A joint advisory from the US Cybersecurity and Infrastructure Security Agency, the FBI and international partners warned that the Scattered Spider hacking collective has impersonated employees to convince IT and help-desk teams to reset passwords and transfer multi-factor authentication to attacker-controlled devices.
The advisory said attackers may make several calls to learn how an organisation handles password resets before attempting to take over an account. That preparation can help them identify which questions are asked, what information agents accept and where approval processes are weakest.
The group has been linked to the cyber attack on Marks & Spencer in 2025. In that incident, an attacker posing as an employee reportedly persuaded a third-party contractor to reset a password, giving the group an entry point from which it compromised further accounts.
Archie Norman, the retailer’s chairman, told MPs that the disruption was expected to reduce profits by about £300 million before recoveries. The incident demonstrated how an apparently routine identity-verification failure can develop into a major operational and financial crisis.
Security teams have responded by strengthening the authentication used at the point of login. Organisations are moving away from weaker methods such as text messages towards authenticator applications, passkeys and physical security keys, while conditional-access systems assess devices, locations and other circumstances before granting access.
But these safeguards do not remove the need for a secure recovery route. In some cases, attackers may seek to steal active session tokens or exploit existing logins; in others, it can be simpler to persuade an authorised employee to change the victim’s security settings.
Account recovery must match the strength of MFA
Microsoft describes account recovery in Entra ID as a “high-assurance” process and has contrasted traditional question-based help-desk checks with stronger methods intended to re-establish trust before access is restored.
The basic test is whether the person requesting a reset can securely demonstrate that they are the employee associated with the account. A caller’s confidence, familiarity with internal details or ability to answer easily obtainable questions should not be treated as proof of identity.
Organisations can place an additional identity-verification step immediately before high-risk actions, including password resets, account unlocks and the replacement of authentication methods. Verification records can also be sent to security monitoring and audit systems, allowing unusual recovery activity to be investigated.
Multi-factor authentication remains an effective barrier against account takeover. However, its protection is weakened when the process for replacing the factors is easier to defeat than the original login. Securing that recovery path is therefore becoming a central part of defending organisations against social engineering.
