Help-desk manipulation deceives a support agent — by impersonating a legitimate user, or in reverse by impersonating IT to a user — into performing a password reset, MFA re-enrollment, or access grant that hands the attacker control of an account. The help desk is a structural soft spot: its job is to restore access for frustrated, time-pressured people, and it is measured on speed and satisfaction — a mission in tension with rigorous identity proofing.
In the classic user-impersonation form, the attacker poses as an employee locked out before a deadline, supplies easily-gathered identifiers (name, employee ID, manager, birthdate — scraped from social media or prior breaches), applies polite urgency and sympathy, and asks the agent to reset the password or, critically, to re-enroll MFA to a new device the attacker controls. The MFA reset is the prize: it defeats an otherwise strong second factor by moving it, with the organization’s own help, onto the attacker’s phone. In the reverse direction, the attacker poses as the help desk to a real employee, “verifying” them or walking them through a change that surrenders access — often paired with an MFA-fatigue push.
Both weaponize the same levers — the authority of “IT/support,” the empathy an agent extends to a stressed caller, and manufactured urgency. The signature: someone wants access restored to a new place while resisting or failing the normal proof of who they are.