Attackers are increasingly bypassing multi-factor authentication (MFA) by targeting the processes used to recover lost or compromised accounts via service desks.
Threat actors are increasingly exploiting account recovery workflows to circumvent MFA, turning service desk support into a primary target for identity theft.

