Skip to content

Security1 publisher2 min readPublished

Scattered Spider talks help desks into moving MFA onto attacker-controlled devices

A joint CISA and FBI advisory says the group rehearses a company's password-reset process over several calls before it asks for anything. That puts factor-reset workflows in the identity boundary, not the support queue.

The Watch · Security desk

Photograph accompanying Scattered Spider talks help desks into moving MFA onto attacker-controlled devices
Photo: bleepingcomputer.com

What happened

  • A joint advisory from CISA, the FBI and international partners says Scattered Spider posed as employees to get IT and help desk staff to reset passwords and transfer MFA to attacker-controlled devices.
  • The same advisory says attackers may spend several calls learning how an organization runs its password resets before they attempt the takeover.
  • Microsoft now calls account recovery in Entra ID a high-assurance process and sets question-based help desk recovery against stronger identity verification before access is restored.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Any agent holding those five reset rights is an identity administrator for every account in their queue, which makes the strength of the enrolled factor irrelevant on that call.
  • constraint A factor migration programme cannot be counted as recovery hardening: passkeys change what a login needs and nothing about what a reset agent can hand over.
  • decision Someone has to own the verification script before a reset, and raising its assurance level trades directly against how fast a genuinely locked-out employee gets working again.
  • contradiction The one quantified figure in the material counts credential theft, so the case for recovery abuse rests on the advisory and a single named victim rather than on measured prevalence.

The mechanism rests on an asymmetry in verification strength. To reach a sensitive system, a user may have to present an authenticator app, a FIDO key or a passkey and pass checks on device, location and login context [2]. To replace that factor, the same user may only have to answer a handful of questions to an agent [3] -- the same identity, held to two very different bars.

Count what the agent on the far end of that call can do. The list runs to five distinct identity-changing actions: reset a password, reset MFA, remove an existing authentication method, issue temporary credentials, approve registration of a new authenticator [4][1]. Which of the five an agent holds depends on the organization and on the caller's privileges [4].

The reconnaissance detail in the advisory matters more than the impersonation itself. Several calls spent learning the reset script [6] is reconnaissance conducted inside a support queue, and recovery sits outside the normal login flow by design [7]. There are no failed logins to alert on. If the identity provider is the only place you are watching, the first event you see is a clean authentication from a newly enrolled factor that your own agent approved.

What the source does not carry is prevalence or cost. The single hard number in it is Verizon's Data Breach Investigation Report finding stolen credentials involved in 44.7% of breaches [9], which counts credential theft, not recovery abuse; the 55.3% remainder says nothing about the service desk either [2]. The piece also carries a vendor pitch for Active Directory password policy tooling that blocks over four billion compromised passwords [10], so read the 44.7% as framing and the CISA and FBI advisory as the evidence [5].

The Marks & Spencer example is thinner than it looks. BleepingComputer attributes the 2025 attack to Scattered Spider impersonation, but the sentence describing who was impersonated is not completed in the text [11], so what the desk actually verified before it acted is not on the record here. Nor does the material date the joint advisory [14].

This is a story about a script an agent reads, not a patch deadline or a CVE. Microsoft's move to call Entra ID recovery a high-assurance process, and to contrast it with question-based help desk recovery [8], is the vendor conceding that the reset path needs its own assurance level rather than inheriting the account's. The account is only as strong as the process used to replace its factors [13], and that process gets far less scrutiny than the login it protects.

What to watch

  • Whether the joint advisory is updated with reset-process indicators a service desk can act on, and whether it carries a date operators can align to.
  • Whether Microsoft makes high-assurance Entra ID recovery the default rather than an option, and what it requires of the agent handling the call.
  • Fuller detail on the 2025 Marks & Spencer intrusion: who was impersonated, and what the desk verified before it moved the factor.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories