MFA Account Recovery Vulnerability: The New Attack Vector
Security teams have made account takeover harder, but attackers are now targeting account recovery processes.
MFA Has Raised the Cost of Account Takeover
Multi-factor authentication (MFA) added crucial protection to password-only authentication, while conditional access and device trust add further checks before users can reach sensitive systems. However, these controls give attackers a reason to look for another route. Some attacks that are becoming increasingly common target the processes around authentication mechanisms, in particular account recovery. After all, why steal a user’s second factor if you can convince someone with the rights to manage it to replace it for you? That makes the service desk more than a support function. It makes it part of the organization’s identity security boundary.
None of this means that MFA has failed
In many cases, the opposite is true: MFA works well enough that attackers have an incentive to find ways around it rather than attack it head-on. That can mean stealing session tokens, abusing existing authenticated sessions or targeting authentication processes that sit outside the normal login flow. And one of the most important processes is account recovery. Every strong authentication system still needs an answer to a routine problem: what happens when a legitimate employee loses access to it? At that point, the security of the account may depend less on the MFA technology protecting it and more on the process used to reset it.
When the Recovery Path Becomes the Attack Path
Employees replace phones, lose security keys, change numbers, damage devices, and forget credentials. Sometimes an authenticator simply becomes unavailable. When self-service recovery is no longer possible, the service desk typically becomes the route back into the account. Depending on the organization and the user’s privileges, an agent may be able to reset a password or MFA, remove an existing authentication method, issue temporary credentials, approve registration of a new authenticator, or otherwise restore access. While these are necessary support functions, from a security perspective, they are also sensitive identity-management actions. That makes the verification step before the reset critical. If a user normally must satisfy multiple authentication factors to access an account but only has to answer a handful of questions to replace those factors, the recovery process can become the weaker path to the same identity. This is increasingly being treated as an identity assurance problem rather than a conventional help desk problem.
Recent Attacks Highlight the Risk
The tactics employed by hacking collective Scattered Spider are a clear example of the challenge service desks face. A joint advisory from CISA, the FBI and international partners states the group has posed as employees to persuade IT and help desk staff to reset passwords and transfer MFA to attacker-controlled devices. The same advisory notes that attackers may spend several calls learning about an organization’s password-reset process before attempting the takeover. The 2025 attack on Marks & Spencer shows how damaging sophisticated impersonation can be. Scattered Spider impersonated an employee to trick a third-party contractor into resetting their password to gain access. From there, the group compromised more accounts, and M&S chairman Archie Norman told Parliament that the incident was expected to reduce profit by around 300 million before recoveries, underlining how a successful identity-focused social engineering attack can become a major business incident.
Make Identity Verification Part of the Service Desk Workflow
Closing this gap means moving the service desk away from questions such as Does this person sound legitimate? or Can they answer our verification questions? and toward a stronger one: Can this person securely prove they are the employee associated with the account? That is where Specops Secure Service Desk fits. It makes identity verification a required part of sensitive service desk workflows, helping reduce reliance on easily guessed or phished information and judgment that a social engineer may be able to manipulate. Specops Secure Service Desk can use existing identity data in Active Directory or Entra ID and integrate with authentication services such as Duo, Okta, PingID and Symantec VIP. With support for more than 15 MFA factors, service desks can verify different types of users without introducing a separate enrollment process. Crucially, verification sits directly in front of high-risk actions. Agents can reset passwords, unlock accounts and require a password change at the next logon only after the caller has been successfully verified.
Verification Secure Your Service Desk with Specops
Strong authentication only works if the process used to reset or recover it is just as secure. Treating service desk verification as part of the identity security process helps reduce the risk of social engineering without making legitimate support harder. Specops helps organizations put stronger identity verification in front of high-risk service desk actions such as password resets and account unlocks. Contact Specops today to see how you can strengthen identity verification and secure your service desk.
