Most small businesses have spent the last few years hardening the technical side of security. Firewalls, endpoint protection, spam filtering, multifactor authentication on everything. That work matters, and it works. Which is exactly the problem. When the locks get good enough, attackers stop picking them and knock on the door instead.
The knock looks like an ordinary Tuesday morning ticket. Someone is locked out. New phone, dead phone, traveling. They need a password reset and their authenticator moved over. Whoever picks up that request is trying to be helpful and quick, because that is the job. And that is the whole attack. No malware, no exploit. Just a conversation with a person who can hand over an account.
The Shape of the Attack
You do not need to know how to run this attack, only how to recognize it. So here is the shape and nothing more. The FBI and CISA published a joint advisory on the group commonly tracked as Scattered Spider in November 2023, and CISA, the FBI, and international partners updated it in July 2025. The advisory describes the pattern plainly. The group impersonates IT and help desk staff to get credentials from employees, and it runs the play in reverse too, socially engineering real help desk personnel into resetting passwords and transferring multifactor authentication tokens to a device the attacker controls. Supporting moves include repeated multifactor prompts until somebody taps approve out of annoyance, SIM swaps so text codes land on the attacker’s phone, and talking employees into installing remote access software.
None of that defeats your security tools. It goes around them by involving a person. Your multifactor setup was never bypassed. Somebody with permission simply moved it.
Why This Works So Reliably
It is easy to blame whoever did the reset. Wrong read. Nothing about a reset request trips an alarm, because it is not an attack right up until it is. The process failed, and it was built for a different problem.
- Helpful people are the target, not the weak link. The point of a help desk is to unblock people fast. Someone who resists every request is bad at the job. Attackers exploit a competence here, not a flaw.
- Time pressure removes judgment. A caller who is late or stuck at an airport creates urgency, and urgency shortens the checklist. That is a human response, not a training gap.
- The verification was designed for honest mistakes. Reset checks were built to confirm a forgetful employee, not to withstand deliberate pretending.
- Employee details are easier to find than people assume. The July 2025 update to that FBI and CISA advisory notes the group gathers personal information about targets from social media and commercial data services, and may make several calls to learn how a company’s reset process works before the call that matters.
Publicly Known Details Are Not Proof of Identity
This is the single idea worth carrying out of this article. Most reset verification asks the caller to recite facts. Employee ID. Manager’s name. Date of hire. Job title. Last four digits of something. Those questions feel like security because they feel private. They are not private. They are obscure, and obscure is a different thing.
Here is the analogy we use with clients. Knowing the address of a house does not make someone the homeowner. The mail carrier knows your address. So does the county tax roll. A key is proof. Knowledge is not.
Same with your staff directory. Verification has to rest on something the real person has or can do, not something they can recite.
Verification Standards Worth Adopting
CISA’s countermeasure guidance on resetting user account passwords puts it in one sentence: organizations should “ensure a means of attestation is defined to verify the veracity of users requiring a manual password reset.” Attestation is a formal word for a simple idea. There must be a defined way to prove the person is real, and it cannot be a trivia question. Here is what that looks like day to day.
- Call back to the number on record. Not the number the requester gives you. The one already in your HR system. Whoever asks for a reset does not get to choose how you reach them. This control alone stops a large share of these attempts.
- Manager confirmation for privileged accounts. Administrative rights, financial approval authority, access to customer records: those need a second human to say yes, contacted independently.
- Live video or in person for the highest risk resets. Moving a multifactor token to a new device gives away the whole account. Seeing a known face is a fair bar for a handful of requests.
- A shared word set during onboarding. Give every employee a private phrase at hire, stored where only the help desk can see it. It is never typed into anything. It exists for one moment: confirming a human on a phone call.
- Tier the requirements by what the account can reach. A warehouse account that only opens a scheduling app does not need what your controller’s does. Maximum friction everywhere gets the policy abandoned in six weeks.
- Log every reset with who approved it and how. Two lines in a ticket. This costs nothing and turns a future investigation from guesswork into reading.
One honest caveat. Stronger authentication helps. That same FBI and CISA advisory recommends phishing resistant methods such as FIDO and WebAuthn security keys or certificate based authentication, and notes they resist both repeated push prompts and SIM swapping. We agree, and we have written more about how those options differ. But better authentication does not close the reset door. Somebody still decides whether to enroll a new key for a caller. That is a process problem, not a product problem.
Make Slowing Down the Safe Choice
Every policy above collapses if the culture punishes the person who follows it. If your office manager gets chewed out once for making a vice president wait ten minutes, she will never do it again. You have deleted the control and kept the document describing it.
- Say it out loud from the top. The owner states plainly that nobody will ever be in trouble for verifying a request, including one from the owner. Say it at onboarding, then again in a staff meeting when nothing is on fire.
- Give people a graceful exit. Staff need a normal way to pause without accusing anyone. Offering to call the person right back on the number already on file works fine.
- Executives go through more, not less. The accounts worth impersonating are the ones with authority. If leadership gets a fast lane, the fast lane is the attack.
- Treat a near miss as a win. When someone catches a suspicious request, say thank you where the rest of the team can hear it. One visible thank you does more than an annual training module.
The Bottom Line
The account reset process is a security control, whether or not anybody at your company has thought of it that way. It deserves the seriousness you give your firewall and costs far less to fix. Write down who can approve a reset. Define how identity gets proven, using something better than facts a stranger could look up. Require a callback to a number you already have. Add a second approver for the accounts that matter. Then tell your team, more than once, that slowing down never gets them in trouble.
This is one of the rare security improvements that is mostly free. A decision and a paragraph of policy, not a purchase. If you want help writing a verification standard that fits how your team actually works, we do this with small and mid-sized businesses across Denton County. We have written before about why this stopped being optional. The help desk is where a lot of it comes to a head. Contact us today
Sources:
Comments are closed