Hacker Hub - October 2026

How Hackers Talk Their Way Past Your IT Help Desk

In July, two young men were each sentenced to five and a half years in prison for the 2024 cyber attack on Transport for London. The attack knocked out more than 140 systems and cost TfL a reported £29 million. It didn't start with clever malware or a zero-day exploit. It started with a phone call.

The attackers rang the IT help desk, pretended to be a member of staff, and persuaded someone to reset a password. That was enough. This month we look at how help desk impersonation works, why smaller businesses are just as exposed, and the simple process changes that stop it.

What is a help desk impersonation attack?

It's social engineering aimed at the people who control access, rather than the people who use it. The attacker calls your IT support posing as an employee who is locked out, has a new phone, or needs their MFA reset urgently before a meeting.

They come prepared. Names, job titles, managers and reporting lines are easy to find on LinkedIn, your website and social media. By the time they call, they often know enough to sound completely genuine.

Once the password or MFA is reset, the attacker is logging in as a real user. To your security tools, that looks like normal activity. From there the usual path is raising privileges, stealing data and, in many cases, deploying ransomware.

Who has been hit?

TfL isn't alone. In 2025, Marks & Spencer and the Co-op were both breached after attackers tricked help desk staff into resetting passwords. M&S lost online ordering for weeks. The NCSC responded by urging organisations to review how their help desks check a caller's identity before resetting credentials.

This isn't going away either. Security researchers have reported that groups linked to these attacks are actively recruiting English-speaking callers to run scripted impersonation calls against service desks.

Why are SMEs exposed?

Most SMEs don't have a service desk. They have someone in accounts who "knows computers", an office manager with admin rights, or an outsourced IT provider. As far as an attacker is concerned, each of those is a help desk.

Smaller teams can actually be easier to fool. Everyone wants to be helpful, nobody wants to hold up a director who says they're locked out before a client call, and there's rarely a written process to fall back on. If a convincing caller can get a password reset with nothing more than a name and a job title, you have a gap.

How do you stop help desk impersonation?

The good news is that fixing this costs very little. It's mostly process, not technology.

  • Call back on a known number. Never verify someone using the number they called from or a number they give you. Ring them back on the number held in your staff records.
  • Use something an attacker can't research. Names, dates of birth and employee numbers can be found or guessed. A line manager confirming the request, a video call with photo ID or a code sent to a registered device are much harder to fake.
  • Treat MFA resets and admin accounts as high risk. These should need a second person to approve, every time.
  • Alert on changes. Make sure someone is notified when MFA methods change or new devices are registered. Most Microsoft 365 tenants can already do this.
  • Make "no" acceptable. Staff need to know they will never be in trouble for refusing an urgent request that doesn't follow the process. Urgency is the attacker's favourite tool.
  • Ask your IT provider. If your support is outsourced, ask how they verify callers before resetting passwords or MFA. If the answer is vague, that tells you something.

FAQ

Can MFA stop help desk impersonation attacks?

Not on its own. If the attacker convinces your help desk to reset MFA, they simply register their own device and MFA then works in their favour. MFA needs to be backed by a strict process for resetting it.

What should I do if I think a reset was fraudulent?

Treat it as a security incident straight away. Lock the account, sign out all active sessions, check for new MFA devices or suspicious mailbox rules, and contact your IT or security provider.

Could your business survive that phone call?

If you're not sure how your team would handle a confident caller asking for a reset, it's worth finding out before an attacker does. We can review your password and MFA reset process and help you close the gaps. Get in touch with Vorago Security for a no-obligation chat.

View All Posts
Blog Image

October 2, 2026

Hacker Hub - October 2026

A single phone call to an IT help desk cost TfL a reported £29 million. Here's how help desk impersonation works and how to stop it.

Read More
Blog Image

August 16, 2026

Hacker Hub - August 2026

Small businesses aren't too small to be targeted. They're often the preferred target. Here's why the 'we're too small' mindset is one of the most dangerous in business.

Read More