The security blind spot that may put your business at risk

Are your security controls vulnerable to threat actors exploiting a simple call to the helpdesk? Learn how your team can strengthen defenses and close this growing security gap.

Do you know that supply chain risk is on the rise for businesses worldwide? According to Verizon, third-party involvement in data breaches has doubled to 30% in the past year. While this risk is often associated with issues in open source components, proprietary software, and traditional suppliers, what happens when your own IT outsourcer becomes the source of a major breach?

Major brands are beginning to face this reality as sophisticated threat actors target their outsourced helpdesks with vishing attacks. The key lies in implementing layered defenses, conducting due diligence, and providing comprehensive cybersecurity training.

Why are helpdesks becoming targets?

Outsourced IT service desks, or helpdesks, are increasingly popular among businesses for their cost savings, specialized expertise, and operational efficiency. However, these service desks have the capability to perform critical functions like password resets, device enrollment, privilege elevation, and disabling multi-factor authentication. These actions provide threat actors with the tools they need to gain unauthorized access to network resources. The challenge lies in convincing helpdesk staff that they are legitimate employees.

Several factors contribute to the increased scrutiny on third-party helpdesks by threat actors:

  • Staffed by IT or cybersecurity professionals early in their careers, who may lack experience in identifying sophisticated social engineering attempts.
  • Helpdesks are designed to serve the client’s employees, leading staff to be overly eager to fulfill requests like password resets.
  • Overwhelmed with requests due to the complexity of IT environments, remote work, and corporate demands, creating opportunities for seasoned vishers.
  • Adversaries may use tactics, such as AI-generated voice impersonations of company leaders, to manipulate helpdesk staff.

Challenges faced by the service desk

Social engineering attacks on helpdesks are not new. Recent incidents, such as the compromise of Jack Dorsey’s Twitter account through a SIM swap attack, highlight the vulnerabilities faced by helpdesk staff. Threat actors have successfully targeted major organizations by exploiting helpdesk employees and manipulating them into providing sensitive information.

Some notable examples include:

  • LAPSUS$ group compromising organizations like Samsung, Okta, and Microsoft by researching specific employees to answer recovery prompts.
  • The Scattered Spider collective using vishing attacks on helpdesk employees to breach companies like MGM Resorts.
  • Clorox suing its helpdesk provider after a staffer complied with a password reset request without proper authentication, resulting in significant financial losses.

Key takeaways from these incidents

These attacks have prompted professional cybercrime groups to recruit English speakers for their operations. Organizations outsourcing their helpdesk services should prioritize due diligence, implement strict user authentication processes, least privilege policies, comprehensive logging, continuous training, regular security assessments, and technical controls to mitigate risks.

Enhance defenses with Managed Detection and Response (MDR)

Vishing attacks present a unique challenge that requires a combination of human expertise, technical solutions, and process improvements. Managed Detection and Response (MDR) services from providers like ESET can complement in-house security teams, offering 24/7 monitoring and advanced AI capabilities to detect suspicious activities.

Leave a Reply

Your email address will not be published. Required fields are marked *