Account Recovery: The New Backdoor for MFA Bypass Attacks
Cybercriminals are bypassing strong authentication by social engineering IT service desks into resetting security tokens.
Cybercriminals are increasingly bypassing Multi-Factor Authentication (MFA) by targeting the human-operated account recovery processes managed by IT service desks. This shift transforms a standard support function into a critical vulnerability in the identity security boundary.
Attackers use sophisticated social engineering to impersonate employees and convince support staff to reset passwords or transfer MFA tokens to devices controlled by hackers. The hacking collective known as 'Scattered Spider' specifically targets these service desks to persuade staff to facilitate these transfers. In one high-profile 2025 incident, Scattered Spider impersonated an employee to trick a third-party contractor into resetting a password and MFA token. This breach led to a network-wide ransomware deployment by the DragonForce group at Marks & Spencer, an attack expected to reduce the company's profit by approximately £300 million before recoveries.
The Shift to Identity Assurance Gaps
This trend emerges as organizations adopt more robust, phishing-resistant MFA tools, such as passkeys and FIDO security keys, alongside conditional access policies. While these technical barriers have raised the cost and difficulty of direct account takeovers, they have pushed attackers toward 'identity assurance' gaps. These gaps exist in the manual processes used when legitimate users lose access to their authentication methods.
Traditionally, account recovery relied on low-security methods, such as answering basic security questions. As these methods fail, the service desk has effectively become a primary target. The logic for attackers is simple: why steal a user’s second factor if you can convince someone with the rights to manage it to replace it for you?
The Administrative Backdoor
This vulnerability demonstrates that technical security controls are only as strong as the administrative processes supporting them. If a user must provide multiple factors to log in but only a few easily phished or researched answers to reset those factors, the recovery process becomes a functional backdoor. This allows social engineers to circumvent state-of-the-art MFA and deploy ransomware, resulting in massive financial and operational losses.
Strengthening the Perimeter
In response to these threats, industry leaders are redefining how identity is verified during recovery. Microsoft now classifies account recovery within Entra ID as a 'high-assurance' process. This designation distinguishes it from traditional recovery by requiring stronger identity verification, such as the use of biometrics and government-issued identification.
Security professionals are now urged to watch for the professionalization of social engineering targeting help desks. The focus is shifting toward implementing strict, non-bypassable verification protocols for any request that alters a user's security credentials, ensuring that the human element does not remain the weakest link in the security chain.