Social engineering at the service of cybercrime: when service desk is the key

Author: Published 4 min de lectura 176 reading

The images in this article were generated with artificial intelligence. How we publish

The 2025 incidents that affected several large UK chains and the recent case of Carnival Corporation recall an uncomfortable truth for corporate cybersecurity: it is not always necessary to violate a software to enter a network, it is enough to deceive the person in charge of opening the door. Social engineering for service desk exploits operational confidence and pressure to solve rapid problems, making support equipment a high impact and low cost vector for attackers.

These attacks work because they combine public and filtered information with improved performance techniques: calls with forged numbers, use of RR data. HH. or LinkedIn profiles to validate identities, and urgent narratives that pressure agents to perform sensitive actions. When an agent can re-establish passwords, disable MFA or create privileged accounts, the attacker gets legitimate access that usually goes unnoticed by traditional technical controls.

Social engineering at the service of cybercrime: when service desk is the key
Image generated with IA.

The consequences are varied and serious: from data theft and industrial espionage to the installation of ansomware or the creation of persistent access accounts. In addition, by using legitimate credentials, attackers often draw signature-based detections and trigger less alerts, allowing them to move laterally and scale privileges before being discovered.

In this context, the response should be separated into three fronts: prevention, detection and resilience. In prevention, It is essential to reassess identity verification policies in the service desk: the foreseeable personal questions are not enough, and the replacements must require confirmation by an independent channel or the approval of a second responsible for high-risk accounts. It is also recommended to apply minimum access principles and to segregate functions so that an agent does not have unilateral capacity over administrative accounts.

In order to improve detection, organizations should implement specific alerts on service desk activity - for example, spikes of reset, MFA changes or account creation with privileges - and correlate them with abnormal identity signals. Behaviour analysis solutions (UEBA) and SIMS configured with rules focused on support processes can shorten the investigation time and contain incidents before they become mass leaks or encryption.

Operational resilience requires continuous exercises: telephone and chat simulations that reproduce vishing and smithing, table tests (tabletop) with external suppliers and contractual reviews that require minimum verification standards. Subcontracting support does not exempt the company from responsibility: processes, training and audits must be defined and must be required contractually.

From a technical point of view, strengthen MFA with methods resistant to SIM exchange and ensure that certain critical changes require physical presence or approval of multiple factors reduces risk. Implement privileged access control (PAM) for administrative sessions and keep unchanging records of changes both prevent abuse and rebuild the chain of events after an incident.

Social engineering at the service of cybercrime: when service desk is the key
Image generated with IA.

Sectoral evidence shows that attacks using human credentials remain prevalent. Research reports such as Verizon's on gaps point to the frequent participation of stolen credentials in incidents, and recent news confirms that criminal groups continue to exploit the technical support path to access corporate environments. See global incident report: Verizon DBIR and examples of public notices and technical coverage of recent campaigns: DarkReading about vishing and criminal groups and the notification of Carnival Corporation: PR PRNewswire.

For CISUS and operational managers the immediate practical recommendation is to implement a 90-day plan: review service desk privileges, define and apply approval flows for sensitive changes, deploy specific alerts in monitoring systems and run social engineering exercises with learning monitoring. In addition, long-term decisions are to reapply the zero trust principle to identity management and to require third-party auditable controls.

Social engineering on service desk will not disappear as long as it works; therefore the correct strategy combines technology, processes and culture. Investing in robust verification, clear operational limits and tuned detection not only reduces technical risk, but protects operational confidence and business continuity. The teams that understand and adapt their support model will be much less attractive to the attackers who seek the simplest route to critical infrastructure.

Coverage

Related

More news on the same subject.