
October 2, 2026
Hacker Hub - October 2026
A single phone call to an IT help desk cost TfL a reported £29 million. Here's how help desk impersonation works and how to stop it.
Read MoreIn July, two young men were each sentenced to five and a half years in prison for the 2024 cyber attack on Transport for London. The attack knocked out more than 140 systems and cost TfL a reported £29 million. It didn't start with clever malware or a zero-day exploit. It started with a phone call.
The attackers rang the IT help desk, pretended to be a member of staff, and persuaded someone to reset a password. That was enough. This month we look at how help desk impersonation works, why smaller businesses are just as exposed, and the simple process changes that stop it.
It's social engineering aimed at the people who control access, rather than the people who use it. The attacker calls your IT support posing as an employee who is locked out, has a new phone, or needs their MFA reset urgently before a meeting.
They come prepared. Names, job titles, managers and reporting lines are easy to find on LinkedIn, your website and social media. By the time they call, they often know enough to sound completely genuine.
Once the password or MFA is reset, the attacker is logging in as a real user. To your security tools, that looks like normal activity. From there the usual path is raising privileges, stealing data and, in many cases, deploying ransomware.
TfL isn't alone. In 2025, Marks & Spencer and the Co-op were both breached after attackers tricked help desk staff into resetting passwords. M&S lost online ordering for weeks. The NCSC responded by urging organisations to review how their help desks check a caller's identity before resetting credentials.
This isn't going away either. Security researchers have reported that groups linked to these attacks are actively recruiting English-speaking callers to run scripted impersonation calls against service desks.
Most SMEs don't have a service desk. They have someone in accounts who "knows computers", an office manager with admin rights, or an outsourced IT provider. As far as an attacker is concerned, each of those is a help desk.
Smaller teams can actually be easier to fool. Everyone wants to be helpful, nobody wants to hold up a director who says they're locked out before a client call, and there's rarely a written process to fall back on. If a convincing caller can get a password reset with nothing more than a name and a job title, you have a gap.
The good news is that fixing this costs very little. It's mostly process, not technology.
Not on its own. If the attacker convinces your help desk to reset MFA, they simply register their own device and MFA then works in their favour. MFA needs to be backed by a strict process for resetting it.
Treat it as a security incident straight away. Lock the account, sign out all active sessions, check for new MFA devices or suspicious mailbox rules, and contact your IT or security provider.
If you're not sure how your team would handle a confident caller asking for a reset, it's worth finding out before an attacker does. We can review your password and MFA reset process and help you close the gaps. Get in touch with Vorago Security for a no-obligation chat.

October 2, 2026
A single phone call to an IT help desk cost TfL a reported £29 million. Here's how help desk impersonation works and how to stop it.
Read More
August 24, 2026
AI has made phishing emails harder to spot by sight. Here's what's changed, and the checks that still work.
Read More
August 16, 2026
Small businesses aren't too small to be targeted. They're often the preferred target. Here's why the 'we're too small' mindset is one of the most dangerous in business.
Read More