Attackers target account recovery processes to bypass MFA
Share
Threat actors are increasingly circumventing multi-factor authentication (MFA) by targeting the processes used to recover lost or compromised accounts.
Instead of attacking authentication technology directly, attackers are using social engineering to manipulate service desk staff into resetting passwords or transferring MFA to devices controlled by the attacker.
The hacking collective known as Scattered Spider has been observed employing these tactics. Advisories from CISA and the FBI indicate the group often researches an organisation’s password-reset procedures before attempting a takeover.
A notable example occurred during a 2025 attack on the retailer Marks & Spencer. Attackers impersonated an employee to trick a third-party contractor into resetting a password, which allowed the group to compromise multiple accounts and eventually deploy ransomware across the network. The incident was expected to reduce profits by approximately £300 million.
Service Desks as Identity Security Boundaries
While MFA has significantly increased the cost of account takeovers, it has also incentivised attackers to find alternative routes. When users lose access to security keys or authenticators, the service desk often becomes the primary path for account restoration.
If this recovery process is less secure than the MFA itself, for instance, if it relies on easily phished personal information or simple security questions, the recovery path becomes the primary attack path.
To counter this risk, security experts recommend treating account recovery as a high-assurance identity management task rather than a standard support function. This involves moving away from traditional question-based verification towards methods that require users to securely prove their identity before sensitive changes, such as resetting an MFA factor, can be authorised.




Leave a Reply