ConstraintCognitive automation2025-07-29
US and allied cyber agencies warn that a criminal group calls help desks first to learn the steps for a password reset, then poses as employees to get passwords reset and MFA moved
IT support specialist / helpdeskoccupation page →Event date / reported
2025-07-29
Evidence stage
ConstraintFailure, rollback, regulation or cost is suppressing adoption. Can lower an assessment or widen its uncertainty.
Tasks this bears on
Being the one who says no
Refusing the access request that should not be granted, spotting the call that is a social-engineering attempt, and deciding what a person is allowed to do to their own machine.
Still human-led✓ Evidence-backed
Where this applies
A joint advisory by US and allied government cyber agencies on a criminal group's methods. It says the group's social engineering attempts are designed first to learn what steps are needed to conduct password resets from help desks, then to gather the reset information for a targeted employee, often over several calls; and, in the July 2025 update, that its members posed as employees to convince IT or help-desk staff to provide sensitive information, reset the employee's password and transfer the employee's MFA to a device they control. Its mitigations recommend phishing-resistant MFA and training against voice phishing; it does not prescribe how a help desk should verify callers, and it describes one group rather than how often desks are fooled.
What this means
The most capable criminal group of recent years treats the help desk's password-reset procedure as the thing to learn first. Whatever steps the desk follows, written down or automated, become the script attackers rehearse — which is why the call on an odd request is a judgement, not a checklist.
What it does not yet show
It describes one group's methods, not how often help desks are fooled, and it does not say what verification works.
What you can check
Open CISA advisory AA23-320A ("Scattered Spider") and find "designed to first learn what steps are needed to conduct password resets from helpdesks".
Does it change the assessment?
No. The impact index is never moved by a single event. Nor did this record change a layer: all 1 linked judgement above already rested on earlier evidence. This one adds to them.
Source
CISA, FBI and partner agencies (RCMP, ASD's ACSC, AFP, CCCS, UK NCSC) — Joint Cybersecurity Advisory AA23-320A, "Scattered Spider" (first published 16 November 2023; last revised 29 July 2025) · verified 2026-09-28 · Claude (VOLO agent) · interpreted 2026-09-28 · Claude (VOLO agent)
Primary source — published by the party that did this, or the authority of record. No co-signature needed.