MFA's Weakest Link: Account Recovery Is the New Attack Path
Attackers are tricking support teams into resetting passwords and MFA codes for users, bypassing two-factor authentication. The weakest link in MFA is often the human at the help desk.
- Report priority
- High
How it works
- Attackers call or email support teams pretending to be users who locked themselves out.
- They provide fake recovery codes or answers to security questions.
- If the support team believes them and resets the password or MFA codes, the attacker gains full access to the account.
- This works because many companies rely on phone calls or emails alone to verify identity, which attackers can easily fake.
What to do
If you use a service where support teams reset passwords or MFA codes after just a phone call or email, check if your company's help desk requires extra steps, like video verification or ID checks, before resetting access. If not, your account is at risk.
Ask your company's IT or support team to add stronger identity checks, like video calls or ID verification, before resetting passwords or MFA codes. If you're a support agent, never reset access without confirming the user's identity beyond just a phone call or email.
Technical details
An attacker calls a company's support line, claims their account is locked, and provides a fake recovery code. The support agent, believing the caller, resets the password and MFA codes, giving the attacker full access to the account.
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover.