TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

ESET WeLiveSecurity

IT service desks: The security blind spot that may put your business at risk

2025-10-15 · Read original ↗

ATT&CK techniques detected

4 predictions
T1078Valid Accounts
72%
"able to reset passwords, enroll new devices, elevate user privileges and even disable multi - factor authentication ( mfa ) for users. that ’ s basically a list of most, if not all the things a threat actor needs to gain unauthorized access to network resources and move laterally…"
T1566.004Spearphishing Voice
44%
"home working and corporate pressure. this can also be exploited by seasoned vishers. - adversaries may employ tactics that even experienced service desk staff may not be able to spot, such as using ai to impersonate senior company leaders who ‘ urgently need their help ’. the ser…"
T1566.004Spearphishing Voice
39%
"able to reset passwords, enroll new devices, elevate user privileges and even disable multi - factor authentication ( mfa ) for users. that ’ s basically a list of most, if not all the things a threat actor needs to gain unauthorized access to network resources and move laterally…"
T1598.004Spearphishing Voice
32%
"home working and corporate pressure. this can also be exploited by seasoned vishers. - adversaries may employ tactics that even experienced service desk staff may not be able to spot, such as using ai to impersonate senior company leaders who ‘ urgently need their help ’. the ser…"

Summary

Could a simple call to the helpdesk enable threat actors to bypass your security controls? Here’s how your team can close a growing security gap.