Skip to main content
A photo of a laptop consumed by flames.
Analyst Insights

Help Desk Hell: The Targeted Attacks That Fool Your IT Workers and Steal Your Data

This is social engineering taken to the next level: In help desk attacks, hackers use AI and other cutting-edge technologies to exploit the kindness of well-meaning employees, gain access to your network, and wreak havoc with data, all with relative ease and ruthless efficiency.

Despite the bizarre (and suspect) announcement last week by 14 cybergangs claiming they’ve “decided to go dark,” experts point to ongoing cybercriminal activity linked to one of the most notorious gangs in the group, and warn help desk workers to be on the alert. These groups have reinvented and transformed old tactics that exploit human kindness.

Scattered Spider, a cybercriminal collective of young hackers known for its creative chaos, has been leading this charge, targeting help desks across the United States and United Kingdom at least since the spring. Far from retiring, the group seems to be just hitting its stride, having fine-tuned a new brand of hacking that utilizes a range of cutting-edge technologies to elevate social engineering to the next level.

This year, it started with a phone call at UK retail giant Marks & Spencer—then Co-op Group—then Harrods. The blitz on retailers dominated UK headlines for weeks. They later hit U.S. insurance companies.

Rather than wielding ransomware or zero day attacks, these hackers impersonated employees, spun believable stories, and convinced IT help desk staffers to reset passwords and disable multifactor authentication (MFA). That gave the attackers the keys to the kingdom. What’s more, in some cases, the intruders didn’t just encrypt systems; they quietly exfiltrated data, setting up a new wave of pure extortion threats that needed no malware at all.

This evolved technique is growing more popular. In many such cases, attackers add realism to their deceptions by using deepfake audio tools to impersonate executives or IT staff—including help desk agents themselves. Ultimately, real help desk agents are left juggling urgent calls, fake identities, and panicked pleas from what sound like—but may not be—real co-workers.

“It’s like a classic social engineering attack,” except that it uses modern technology to pull off, says Errol Weiss, CSO for Health-ISAC (Information Sharing and Analysis Center). “The adversaries tell a convincing story—maybe someone lost their phone and needs their MFA reset—and the help desk, trying to be helpful, ends up giving away access.”

Welcome to help desk hell.

Reports of their retirement have been greatly exaggerated

Since forming in 2022, Scattered Spider, a predominantly English-speaking collective made up of young men and teens from the U.S. and UK, has rapidly evolved from SIM-swapping scams to precision-guided ransomware and extortion attacks. Before, groups like these might have employed tactics like phishing to dupe trusting employees into taking ill-advised actions—like clicking on links that launch malware. Now, they’re using combinations of vishing (voice phishing), smishing (a blend of SMS and phishing), and AI tools to con frontline workers.

The adversaries tell a convincing story—maybe someone lost their phone and needs their MFA reset—and the help desk, trying to be helpful, ends up giving away access.
Errol Weiss, CSO, Health-ISAC (Information Sharing and Analysis Center)

The tactic works. Last year, Scattered Spider alone was behind at least six impactful vishing-led campaigns, targeting employees across retail, insurance, and aviation sectors. The group’s methods are aggressive and constantly evolving.

The entry point is mundane. The consequences can be massive. The Marks & Spencer attack, for example, will cost the retailer an estimated $400 million. Around 6.5 million people had their data stolen in the Co-op attack. And Harrods was unable to take online clothing and home orders for a week. It didn’t divulge the financial impact. (The UK’s National Crime Agency announced the arrests of four alleged perpetrators of this cyber spree—a 20-year-old woman and three male teens, ages 17 to 19—in July.)

[Read also: What is identity and access management?]

Once inside, the attackers either install ransomware or quietly siphon off sensitive data. Increasingly, it’s the latter. Encryption-less extortion, where attackers steal data and then demand payment to keep it private, is faster, quieter, and more profitable. Dragos, a cybersecurity firm specializing in infrastructure attacks, reports this “pure data extortion” model is gaining traction fast, especially across Europe.

Help desk attacks: What industry is next?

Retail firms and insurers have been targets of choice this year. But Scattered Spider has a pattern: Strike one industry hard, then move on.

It’s widely believed to be behind the 2023 MGM Resorts International and Caesars Entertainment cyberattacks, which involved using vishing to gain access to corporate systems and deploy ransomware. Authorities suspect the group is behind a series of cyberattacks this summer on airline carriers. The group is among three that claimed responsibility for this month’s devastating cyberattack on Jaguar Land Rover, which triggered global manufacturing shutdowns and hundreds of millions of dollars in estimated losses. And a recent report from the threat analysis outfit ReliaQuest suggests financial services and the tech sector may be likely next targets.

[Read also: A recent wave of cyberattacks in Europe have experts worried about this (rarely discussed) sector]

“Certain industries are more at risk,” says Arda Büyükkaya, senior cyberthreat intelligence analyst at EclecticIQ. “Retail, healthcare, and similar sectors are particularly vulnerable because they often have large help desk operations, fast-paced work environments, and flexible identity-verification processes that attackers can more easily exploit.”

Modern methodology—here’s how help desk attacks work

Cybercriminals mine LinkedIn, social media, and breach dumps (databases of stolen usernames, passwords, and other personal details) to build detailed employee profiles. Then they place a vishing call to a help desk, often posing as a traveling executive who lost access to their phone and email. They drop just enough insider lingo and urgency to sound legit. Some even spoof the company’s real phone numbers or register phishing domains, like “vpn-yourcompany-helpdesk.com.”

Help desks are attractive and vulnerable targets because their staff are trained to resolve issues quickly.
Arda Büyükkaya, senior cyberthreat intelligence analyst, EclecticIQ

“Help desks are attractive and vulnerable targets because their staff are trained to resolve issues quickly, which attackers exploit by creating urgent, emotional scenarios to pressure them into bypassing security protocols,” Büyükkaya says. “Additionally, help desks often have access to highly privileged functions like password resets and multifactor authentication, making them key points of control.”

That access isn’t always used for disruption. Increasingly, it’s used for stealth.

“Vishing supports pure extortion by allowing attackers to gain quiet access to systems without using malware or encryption,” Büyükkaya says. “Instead, they steal sensitive data and then threaten to release it unless a ransom is paid. This method is low risk for attackers, quick to execute, and often goes undetected until the extortion demand is made.”

Planning a response to help desk attacks

So, what can companies do about it?

[Empower workers to challenge anything] if they really feel that something is off, that a call is not legitimate, or that it doesn’t make sense.
Christopher Hadnagy, CEO, Social-Engineer

“Security teams can take immediate actions such as always calling individuals back using trusted contact numbers, implementing multi-step verification processes instead of relying solely on phone calls, and requiring secret passphrases for high-privilege actions like password resets,” Büyükkaya says. “They should also verify identities through a web camera or require in-person verification for sensitive actions. Regular training for helpdesk staff, including social engineering simulations, and enforcing clear rules for stopping urgent or high-risk requests are also critical steps.”

One of the most effective defenses is training help desk employees on what to watch for, said Christopher Hadnagy, CEO at Social-Engineer, a security consulting and training company, in a recent webinar. The old rules of thumb such as trusting voices you know and being wary of unfamiliar ones or those with an accent no longer apply. Modern deepfake technology can generate convincing recordings, and AI-powered tools like FraudGPT can even make any accent sound local, he said.

[Read also: Deepfakes, AI tricks and more—a comprehensive guide to disinformation, from definitions to best defense strategies]

Büyükkaya says part of that training should be about educating employees on red flags, like urgent requests that pressure staff to skip verification steps, callers who appear to have extensive knowledge about internal systems, requests for password or MFA resets without backup proof, calls from unknown or spoofed numbers, and inquiries made at odd hours or from unusual locations.

Another kind of help desk “hack”—support suspicion

Training should also be about empowerment.

Help desk employees need to know that “if they really feel that something is off, that a call is not legitimate, or that it doesn’t make sense,” they can challenge it, shut it down, and report it without consequence—even if it was their boss or CEO, Hadnagy said in the webinar.

Hadnagy pointed to a 2024 example in which a Ferrari executive received messages and even a deepfaked phone call from someone posing as CEO Benedetto Vigna. Suspicious, the executive asked the caller to recall a book Vigna had recently recommended. When the imposter couldn’t answer, the attempt quickly unraveled.

“That one question saved Ferrari from a massive breach,” Hadnagy said. “And why? Because the executive didn’t have fear that if he was actually questioning the real CEO, he would have been reprimanded, scolded, or shamed. He was empowered to know that he had the power to question that guy on the phone, and that stopped the breach.”

Government and other expert guidance for U.S. and UK enterprises

The National Cyber Security Centre (NCSC), part of Britain’s Government Communications Headquarters (GCHQ), an intelligence and security organization, has also issued urgent guidance for UK firms to review and harden their help desk protocols.

In the U.S., various industry ISACs have been issuing similarly helpful guidance. Weiss, who helped build Citigroup’s Cyber Intelligence Center, says the finance sector’s threat-sharing model could serve as a blueprint for retail and healthcare industries.

“We had threat intel baked into everything, from strategic planning to real-time operations,” he says. “That level of integration helps you get ahead of what’s coming.”

While biometrics may be falling out of favor as a verification device, Weiss notes that technology can play a role. “There’s voice recognition and behavioral verification tech that can flag anomalies in real time,” he says. “Solutions like Clear are exploring active proof-of-life checks to confirm identity. That could be part of the answer.”

[Read also: A new decentralized cyberdefense model gains traction in the EU]

But he and Büyükkaya agree on the most important defense: preparation.

“Don’t just train once and move on,” Büyükkaya says. “Run drills. Require secret passphrases. And make it clear that any urgent request is a red flag, not an excuse to skip protocol.”

In today’s threat landscape, your biggest vulnerability might be a well-meaning employee just trying to help.

“We tell companies all the time,” says Weiss, “If you’re not proactively testing your help desk and updating your playbooks, you’re already behind.”