TechNewsReel
Live

Attackers Target Identity Verification Gaps in Onboarding and Recovery

Cybercriminals are bypassing hardened MFA by exploiting the human-led processes used to establish and reset corporate identities.

TechNewsReel Newsroom · August 25, 2026

Cybersecurity attackers are shifting their focus away from bypassing login authentication toward exploiting the processes used to establish and recover digital identities. This strategic pivot targets the identity lifecycle, turning onboarding and account recovery into primary entry points for corporate networks.

This trend manifests in two primary vectors: the use of falsified documentation to secure employment and the social engineering of service desks. North Korean IT workers have been found impersonating foreign nationals using forged identity documents to gain employment at technology firms. Simultaneously, the threat actor group Scattered Spider has successfully used social engineering to impersonate employees, tricking service desk personnel into resetting passwords and granting unauthorized access.

The Vulnerability of the Identity Lifecycle

This shift occurs as organizations harden perimeter defenses with multi-factor authentication (MFA) and conditional access. As these technical barriers become more difficult to breach, attackers target the 'identity lifecycle'—the moments when a user is first onboarded or when they lose access to their account.

Many corporate service desks still rely on weak verification signals, such as employee IDs, phone numbers, or security questions that can be easily researched or found in previous data breaches. These human-led processes create a critical gap where a service desk agent becomes the primary attack vector, inadvertently granting legitimate credentials to an impostor.

High-Stakes Consequences

When identity verification fails during onboarding or recovery, the resulting breach is particularly dangerous because the attacker enters the network with legitimate credentials. This renders traditional authentication defenses ineffective, as the system recognizes the attacker as a trusted user.

The financial stakes of these vulnerabilities are immense. A 2025 ransomware breach at Marks & Spencer (M&S) serves as a stark example of the potential fallout. The attack resulted in statutory profit losses of more than £300 million (approximately $400 million), with profits plummeting from £391.4 million the previous year to just £3.4 million in 2025.

The Role of AI and Future Risks

The effectiveness of these impersonation attacks is being amplified by artificial intelligence. AI is increasing the success rate of these schemes through the creation of synthetic profiles, cloned voices, and deepfake video, making it harder for service desk agents to distinguish between a real employee and an attacker.

Organizations must now look beyond MFA to secure the human elements of identity management. The focus is shifting toward more robust, cryptographically verified identity proofing and the elimination of knowledge-based authentication in account recovery processes to prevent further high-impact breaches.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.