VOLOVLOAutomation risk & transition, task by task
AskOccupationsMajorsBusinessFoundersChangesNotesMethod
Search occupations, majors…
EN
  • English
  • 简体中文
  • 日本語
  • Español
  • Português
  • Français
VLO
VOLO

Understanding how automation changes work — task by task, with the evidence shown and the uncertainty admitted.

AskOccupationsMajorsBusinessFoundersChangesNotesMethodWill AI replace my job?AboutRole diagnosisOpen dataOntologyVOLO ProPrivacyTerms
© 2026 VOLO
Guides
Ask VOLOFor businessFor foundersRecent changesNotesRole diagnosisFirst AI experimentVOLO ProMethod & evidenceAboutFollow an occupationSearch
Occupations
All occupations
AI / software
Translator / InterpreterBank tellerCopywriterContent moderatorCustomer service representativeAdministrative assistantSoftware tester / QA engineerGraphic designerParalegalVideo editorAccountant / BookkeeperMarketing specialistFrontend developerTax preparer / tax agentVoice actorMedical coderData analystInsurance claims handlerTechnical writer / documentation engineerJunior software developerInsurance underwriterHR / recruiterLoan officer / credit officerFinancial analystProcurement / supply chain specialistJournalistSales / account managerReal estate agentIT support specialist / helpdeskAuditorManagement consultantBackend developerAI researcherProduct / UX designerBusiness systems ownerE-commerce operations specialistActuaryRadiologistData engineerProject managerLawyerMedical assistant / clinic assistantQuantity surveyorMachine learning engineerExperienced software engineerDevOps / platform / SRE engineerProduct managerPharmacistPartnerships / channel managerSecurity analyst (SOC)Financial adviser / financial plannerCompliance officerLibrarianArchitectFirst-line manager / team supervisorCounsellor / therapistRetail salesperson / shop assistantCivil / structural engineerSecurity guardBus driverInsurance agentSchool teacherGeneral practitioner / primary care doctorAirline pilotWaiter / restaurant serverRadiographer / radiologic technologistAuto mechanic / vehicle technicianPolice officerSonographerAir traffic controllerVeterinarianPhysiotherapist / rehabilitation therapistDentistConstruction workerSocial workerRegistered nurseCare worker / nursing assistantPlumberAI implementation lead
RPA / self-service
Government service clerkOperations coordinatorMetro train driverReceptionist / front desk
Robotics
Retail cashier / shop assistantContainer port workerWarehouse workerAssembly line workerMedical laboratory technicianWelderChef / cookCleaner / janitorFarmerFirefighterCabin crewElectrician
Autonomous driving
Ride-hail / taxi driverTruck driverDelivery rider / courier
Majors
All majorsEnglish / Foreign languagesComputer scienceAccountingPsychologyJournalism / CommunicationFinanceLawVisual communication designMarketingNursingBusiness administrationEducation and teacher trainingArchitecturePublic administrationMedicineHospitality and tourism managementEconomicsInformation systems
Enter as:I have a jobI am studyingI run a companyI am building something
Recent changes›IT support specialist / helpdesk›2025-07-29
ConstraintCognitive automation2025-07-29

US and allied cyber agencies warn that a criminal group calls help desks first to learn the steps for a password reset, then poses as employees to get passwords reset and MFA moved

IT support specialist / helpdeskoccupation page →
Event date / reported
2025-07-29
Evidence stage
ConstraintFailure, rollback, regulation or cost is suppressing adoption. Can lower an assessment or widen its uncertainty.
Tasks this bears on
Being the one who says no
Refusing the access request that should not be granted, spotting the call that is a social-engineering attempt, and deciding what a person is allowed to do to their own machine.
Still human-led✓ Evidence-backed
Where this applies
A joint advisory by US and allied government cyber agencies on a criminal group's methods. It says the group's social engineering attempts are designed first to learn what steps are needed to conduct password resets from help desks, then to gather the reset information for a targeted employee, often over several calls; and, in the July 2025 update, that its members posed as employees to convince IT or help-desk staff to provide sensitive information, reset the employee's password and transfer the employee's MFA to a device they control. Its mitigations recommend phishing-resistant MFA and training against voice phishing; it does not prescribe how a help desk should verify callers, and it describes one group rather than how often desks are fooled.
What this means
The most capable criminal group of recent years treats the help desk's password-reset procedure as the thing to learn first. Whatever steps the desk follows, written down or automated, become the script attackers rehearse — which is why the call on an odd request is a judgement, not a checklist.
What it does not yet show
It describes one group's methods, not how often help desks are fooled, and it does not say what verification works.
What you can check
Open CISA advisory AA23-320A ("Scattered Spider") and find "designed to first learn what steps are needed to conduct password resets from helpdesks".
Does it change the assessment?
No. The impact index is never moved by a single event. Nor did this record change a layer: all 1 linked judgement above already rested on earlier evidence. This one adds to them.
Source
CISA, FBI and partner agencies (RCMP, ASD's ACSC, AFP, CCCS, UK NCSC) — Joint Cybersecurity Advisory AA23-320A, "Scattered Spider" (first published 16 November 2023; last revised 29 July 2025) · verified 2026-09-28 · Claude (VOLO agent) · interpreted 2026-09-28 · Claude (VOLO agent)
Primary source — published by the party that did this, or the authority of record. No co-signature needed.
All changes for IT support specialist / helpdesk →All recent changes →How events become evidence →