Security Glossary

What is Help Desk Social Engineering?

Help desk social engineering targets your support staff — not your executives. Attackers impersonate employees and persuade agents to reset MFA, enroll a new device, or unlock accounts. Good OSINT makes the caller sound like a tired coworker who just needs to get into email.

How a Help Desk Social Engineering Attack Works

1

Collect employee details

Names, titles, manager names, and office locations come from LinkedIn and directories.

2

Learn help desk patterns

Public IT portal docs and job posts reveal tools and verification steps.

3

Call or chat as the employee

Urgency plus accurate personal details overwhelm weak verification.

4

Capture the reset

A new MFA device or password is enrolled under attacker control.

Real-World Example

An attacker reset MFA on a salesperson's account after correctly naming their manager, CRM, and a recent company all-hands — all from public posts. The help desk followed an incomplete identity checklist.

How AiVERSARY Detects Help Desk Social Engineering Risk

AiVersary surfaces how much employee and IT-tool detail is public — the script material used against help desks — so you can tighten verification before the call comes.

Is your organization exposed to help desk social engineering?

AiVERSARY scans your public footprint and identifies the exact data attackers would use against you. $499 per report.

Get Your Threat Report

Related Terms

Pretexting

Pretexting is when an attacker creates a fabricated scenario — a "pretext" — to trick someone into sharing information or performing an action they normally wouldn't. Think of it as method acting for criminals: they invent a believable character and situation, then play that role convincingly enough to bypass your team's natural skepticism. The quality of the pretext depends entirely on how much real information the attacker can gather beforehand.

MFA Fatigue

MFA fatigue is an attack where a criminal who already has your password repeatedly triggers multi-factor authentication prompts — the push notifications on your phone — until you approve one just to make them stop. It exploits the very security measure designed to protect you by turning it into an annoyance that people instinctively dismiss. This technique has been used in several high-profile breaches.

Vishing

Vishing — short for "voice phishing" — is when attackers use phone calls instead of emails to manipulate people into sharing sensitive information or taking harmful actions. Phone calls create a sense of immediacy and personal connection that emails can't match, and they bypass all of your email security filters. With AI voice cloning now widely available, attackers can even impersonate specific people your team knows and trusts.

Social Engineering

Social engineering is the practice of manipulating people into giving up confidential information or taking actions that compromise security. Instead of breaking through firewalls and encryption, attackers exploit trust, authority, urgency, and helpfulness — basic human instincts that no software patch can fix. It is the foundation of nearly every major breach.