Attackers can research the answers to service desk security questions and use them to take over employee accounts. Organizations should require verified authentication before agents can reset passwords, change multifactor authentication methods or recover accounts.
For too many service desks, identity verification still relies on asking the caller questions that only the real employee should be able to answer. Unfortunately, security questions don’t stand up particularly well against modern attacker techniques.
Employee IDs, dates of birth, manager names, job titles and office locations can often be found through social media, public websites or data exposed in previous breaches. With enough reconnaissance, an attacker can arrive at the service desk knowing exactly the information an agent has been trained to ask for.
The challenge for the service desk is verifying identity when security questions don’t provide that assurance.
Knowledge-based verification only works when the information being requested is difficult for anyone other than the employee to obtain. Increasingly, that is no longer the case.
An attacker researching a target can build a surprisingly detailed profile from public sources, previous data breaches and other stolen information. More sensitive details, such as dates of birth or partial identity numbers, may already have been exposed elsewhere.
Mandiant has observed UNC3944, also associated with reporting on Scattered Spider, contacting service desks while already holding the personal information needed to get through identity checks. In investigated incidents, attackers used details including dates of birth, the last four digits of Social Security numbers, manager names and job titles to impersonate employees.
The problem is therefore bigger than choosing better security questions. Asking several weak questions doesn’t necessarily create strong verification if an attacker can research or steal the answers to all of them.
Security questions establish that somebody knows information about an employee, but don’t provide reliable proof that the person making the request is that employee. For sensitive service desk actions such as password resets and multifactor authentication (MFA) changes, that distinction has become increasingly important.
Attackers have learned that it can be easier to persuade someone to reset an account than to defeat the security protecting it.
A joint advisory from CISA, the FBI, NCSC and other agencies highlights that Scattered Spider repeatedly used social engineering to convince IT help desk staff to reset employee passwords or transfer MFA to devices controlled by the attacker. The advisory also notes that the group gathers personal information from social media, open-source research and data leaks before making those calls.
The 2025 ransomware attack against UK retailers like Marks & Spencer (M&S) demonstrate the damage the hacking group’s tactics can cause. M&S chairman Archie Norman told Parliament that the company’s breach began with “sophisticated impersonation”. The attackers appeared to be a genuine individual and had their details, while a third party was also involved in the initial point of entry. M&S estimated the incident would reduce profit by around £300 million before any recoveries.
The lesson is straightforward: password resets, MFA changes and account recovery are not routine administrative tasks from a security perspective. They are high-value identity events, and attackers increasingly treat them that way.
The answer is not to find a more obscure set of security questions. Modern service desk verification needs to establish identity using stronger factors and make that verification part of the workflow itself.
The important point is consistency. A verification process is only as strong as its weakest exception. If an agent can bypass it because a caller sounds convincing, claims to be in a hurry or knows enough personal information, attackers still have something to work with.
Solutions like Specops Secure Service Desk address this by turning identity verification into a technical control rather than a judgment call. Organizations can use existing authentication services such as Duo, Okta, PingID and others to verify the caller, and require that process to succeed before the agent can reset a password or unlock an account.
Agents can make use of any combination of more than 15 MFA factors that ensure every caller, whether they have a mobile device or not, can be securely verified.
That means the service desk agent no longer needs to decide whether somebody sounds legitimate based on the information they can provide. The system enforces the organization’s chosen verification process before the sensitive action becomes available. For organizations trying to reduce social-engineering risk, that is a much stronger model than relying on training and policy alone.
Security questions remain common because they are familiar and easy to use. But, if attackers can research the answers to identity checks before contacting the service desk, those questions are no longer providing meaningful proof of identity. The same applies to processes that depend on an agent deciding whether a caller seems genuine.
Service desk security should take a different approach: verify the user through trusted authentication methods, apply stronger checks to higher-risk actions and enforce those controls before a reset or account change can take place.
Specops Secure Service Desk is designed to support agents by delivering that assurance. Instead of asking agents to judge whether a caller knows enough to be trusted, it enforces identity verification before sensitive actions can proceed. If you’re interested in seeing how Specops can help secure your service desk, book a demo today.