The images in this article were generated with artificial intelligence. How we publish
The 2025 incidents that affected several large UK chains and the recent case of Carnival Corporation recall an uncomfortable truth for corporate cybersecurity: it is not always necessary to violate a software to enter a network, it is enough to deceive the person in charge of opening the door. Social engineering for service desk exploits operational confidence and pressure to solve rapid problems, making support equipment a high impact and low cost vector for attackers.
These attacks work because they combine public and filtered information with improved performance techniques: calls with forged numbers, use of RR data. HH. or LinkedIn profiles to validate identities, and urgent narratives that pressure agents to perform sensitive actions. When an agent can re-establish passwords, disable MFA or create privileged accounts, the attacker gets legitimate access that usually goes unnoticed by traditional technical controls.

The consequences are varied and serious: from data theft and industrial espionage to the installation of ansomware or the creation of persistent access accounts. In addition, by using legitimate credentials, attackers often draw signature-based detections and trigger less alerts, allowing them to move laterally and scale privileges before being discovered.
In this context, the response should be separated into three fronts: prevention, detection and resilience. In prevention, It is essential to reassess identity verification policies in the service desk: the foreseeable personal questions are not enough, and the replacements must require confirmation by an independent channel or the approval of a second responsible for high-risk accounts. It is also recommended to apply minimum access principles and to segregate functions so that an agent does not have unilateral capacity over administrative accounts.
In order to improve detection, organizations should implement specific alerts on service desk activity - for example, spikes of reset, MFA changes or account creation with privileges - and correlate them with abnormal identity signals. Behaviour analysis solutions (UEBA) and SIMS configured with rules focused on support processes can shorten the investigation time and contain incidents before they become mass leaks or encryption.
Operational resilience requires continuous exercises: telephone and chat simulations that reproduce vishing and smithing, table tests (tabletop) with external suppliers and contractual reviews that require minimum verification standards. Subcontracting support does not exempt the company from responsibility: processes, training and audits must be defined and must be required contractually.
From a technical point of view, strengthen MFA with methods resistant to SIM exchange and ensure that certain critical changes require physical presence or approval of multiple factors reduces risk. Implement privileged access control (PAM) for administrative sessions and keep unchanging records of changes both prevent abuse and rebuild the chain of events after an incident.

Sectoral evidence shows that attacks using human credentials remain prevalent. Research reports such as Verizon's on gaps point to the frequent participation of stolen credentials in incidents, and recent news confirms that criminal groups continue to exploit the technical support path to access corporate environments. See global incident report: Verizon DBIR and examples of public notices and technical coverage of recent campaigns: DarkReading about vishing and criminal groups and the notification of Carnival Corporation: PR PRNewswire.
For CISUS and operational managers the immediate practical recommendation is to implement a 90-day plan: review service desk privileges, define and apply approval flows for sensitive changes, deploy specific alerts in monitoring systems and run social engineering exercises with learning monitoring. In addition, long-term decisions are to reapply the zero trust principle to identity management and to require third-party auditable controls.
Social engineering on service desk will not disappear as long as it works; therefore the correct strategy combines technology, processes and culture. Investing in robust verification, clear operational limits and tuned detection not only reduces technical risk, but protects operational confidence and business continuity. The teams that understand and adapt their support model will be much less attractive to the attackers who seek the simplest route to critical infrastructure.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...