Helpdesk social engineering has quietly become the highest-leverage attack against modern enterprises, because the password reset call is the one identity-verification step where MFA is not present and the verifier is a human under throughput pressure, a gap a recent BleepingComputer analysis of password-reset practice examines in depth. The April 2025 Marks and Spencer breach is the worked example: attackers tied to Scattered Spider impersonated an M&S employee to a third-party service desk, secured a fresh credential, extracted the NTDS.dit file from Active Directory, cracked hashes offline, and detonated ransomware that suspended online sales for five days at an average cost of GBP 3.8 million ($5.1 million) per day. Why password reset queues became the path of least resistance Forrester research cited in BleepingComputer’s coverage estimates every reset costs about $70 in helpdesk time, which is why most large enterprises moved to self-service tools. The unintended consequence: the cases that still hit the helpdesk are the edge cases where self-service enrollment failed, the user is locked out of their MFA device, or social engineers picked the script that bypasses self-service. Those are precisely the scenarios where a verifier has to use judgment, which is where impersonation lands. Verizon’s 2024 Data Breach Investigations Report attributes 44.7% of breaches to stolen credentials, and a helpdesk-issued credential counts the same as one harvested via infostealer. What the Marks and Spencer chain reveals about service-desk controls The Marks and Spencer chain ran through routine helpdesk procedure end-to-end: a caller passed knowledge-based questions, the agent acted, valid credentials were issued. There was no MFA bypass; there was no zero-day. The verification step assumed that someone who knows the employee’s identifiers IS the employee, which knowledge-based authentication has not been safe to assume since at least the Equifax era. What the BleepingComputer writeup under-emphasizes is the
Marks and Spencer Password Reset Call Shows Why Helpdesk Verification Is the New MFA Surface
Read the original article
cybersecurity-insiders.com →