{
  "slug": "help-desk-mfa-reset-attack",
  "title": "The help desk can be fooled. The signature can't.",
  "summary": "Social-engineering the IT help desk into an MFA reset opened the door at MGM (~$100M). Training the help desk isn't working. Make the reset itself require a signature.",
  "lede": "Talking the IT help desk into resetting MFA was the entry point for the MGM breach (~$100M) and is now the dominant enterprise ransomware vector. You can train the help desk forever; the process itself is the hole. Close the process.",
  "date": "2026-06-15",
  "reading_time": "5 min read",
  "category": "Security",
  "tags": [
    "Scattered Spider",
    "help desk",
    "MFA reset",
    "account recovery",
    "ransomware"
  ],
  "image": "https://cdn.twc.sh/images/igcache/Help%20Desk%20MFA%20Reset%20Attack/1200_630/blog.jpg",
  "url": "/blog/help-desk-mfa-reset-attack.html",
  "wordcount": 505,
  "related": [
    "contact-center-voice-deepfake",
    "your-okta-weakest-link",
    "kill-switch-design"
  ],
  "schema": "Article"
}