Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Iran claims to have attacked 10 ships near strait of Hormuz after US strikes | Iran

    September 9, 2026

    Andy Burnham: National security can’t come at expense of social security

    September 9, 2026

    I spent an hour riding inside Tesla’s steering-wheel-free Cybercab

    September 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Iran claims to have attacked 10 ships near strait of Hormuz after US strikes | Iran
    • Andy Burnham: National security can’t come at expense of social security
    • I spent an hour riding inside Tesla’s steering-wheel-free Cybercab
    • MFA’s Weakest Link: Account Recovery Is the New Attack Path
    • 10 Crypto Mysteries That Still Have No Good Answer
    • NASA Names Two Artemis II Astronauts to Emeritus Program
    • Hutu and Tutsi: The history behind the divide | News
    • Le Pen’s National Rally fires security volunteer over racist remarks caught on tape – POLITICO
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    MFA’s Weakest Link: Account Recovery Is the New Attack Path

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 9, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    For years, security teams have been making account takeover harder. Multi-factor authentication (MFA) added crucial protection to password-only authentication, while conditional access and device trust add further checks before users can reach sensitive systems.

    However, these controls give attackers a reason to look for another route. Some attacks that are becoming increasingly common target the processes around authentication mechanisms, in particular account recovery. After all, why steal a user’s second factor if you can convince someone with the rights to manage it to replace it for you?

    That makes the service desk more than a support function. It makes it part of the organization’s identity security boundary.

    MFA Has Raised the Cost of Account Takeover

    Even if an attacker captures a user’s credentials, MFA means a second authentication factor still stands between them and the account.

    Further strengthening that barrier is the fact that many organizations are moving away from weaker factors such as SMS and toward authenticator apps, FIDO security keys and passkeys. Phishing-resistant authentication can make credential theft considerably harder to turn into account access, while conditional access and device trust add further checks based on factors such as the device, location and context of a login.

    None of this means that MFA has failed. In many cases, the opposite is true: MFA works well enough that attackers have an incentive to find ways around it rather than attack it head-on.

    That can mean stealing session tokens, abusing existing authenticated sessions or targeting authentication processes that sit outside the normal login flow. And one of the most important processes is account recovery.

    Every strong authentication system still needs an answer to a routine problem: what happens when a legitimate employee loses access to it? At that point, the security of the account may depend less on the MFA technology protecting it and more on the process used to reset it.

    Verizon’s Data Breach Investigation Report found stolen credentials are involved in 44.7% of breaches. 

     

    Effortlessly secure Active Directory with compliant password policies, blocking 4+ billion compromised passwords, boosting security, and slashing support hassles!

    Try it for free

    When the Recovery Path Becomes the Attack Path

    Employees replace phones, lose security keys, change numbers, damage devices, and forget credentials. Sometimes an authenticator simply becomes unavailable.

    When self-service recovery is no longer possible, the service desk typically becomes the route back into the account.

    Depending on the organization and the user’s privileges, an agent may be able to reset a password or MFA, remove an existing authentication method, issue temporary credentials, approve registration of a new authenticator, or otherwise restore access.

    While these are necessary support functions, from a security perspective, they are also sensitive identity-management actions. That makes the verification step before the reset critical. If a user normally must satisfy multiple authentication factors to access an account but only has to answer a handful of questions to replace those factors, the recovery process can become the weaker path to the same identity.

    This is increasingly being treated as an identity assurance problem rather than a conventional help desk problem. Microsoft, for example, now describes account recovery in Entra ID as a “high-assurance” process and contrasts traditional question-based help desk recovery with stronger identity verification designed to re-establish trust before access is restored.

    The principle is simple: the process used to replace an authentication method should provide confidence that the person requesting the change is the person who owns the account. If it doesn’t, the recovery path can quickly become the attack path.

    Recent Attacks Highlight the Risk

    The tactics employed by hacking collective Scattered Spider are a clear example of the challenge service desks face. A joint advisory from CISA, the FBI and international partners say the group has posed as employees to persuade IT and help desk staff to reset passwords and transfer MFA to attacker-controlled devices.

    The same advisory notes that attackers may spend several calls learning about an organization’s password-reset process before attempting the takeover.

    The 2025 attack on Marks & Spencer shows how damaging sophisticated impersonation can be. Scattered Spider impersonated an employee to trick a third-party contractor into resetting their password to gain access. From there, the group compromised more accounts and eventually deployed ransomware across the retailer’s network.

    M&S chairman Archie Norman told Parliament that the incident was expected to reduce profit by around £300 million before recoveries, underlining how a successful identity-focused social engineering attack can become a major business incident.

    Make Identity Verification Part of the Service Desk Workflow

    Closing this gap means moving the service desk away from questions such as “Does this person sound legitimate?” or “Can they answer our verification questions?” and toward a stronger one: Can this person securely prove they are the employee associated with the account?

    That is where Specops Secure Service Desk fits. It makes identity verification a required part of sensitive service desk workflows, helping reduce reliance on easily guessed or phished information and judgement that a social engineer may be able to manipulate.

    Specops Secure Service Desk can use existing identity data in Active Directory or Entra ID and integrate with authentication services such as Duo, Okta, PingID and Symantec VIP. With support for more than 15 MFA factors, service desks can verify different types of users without introducing a separate enrollment process.

    Crucially, verification sits directly in front of high-risk actions. Agents can reset passwords, unlock accounts and require a password change at the next logon only after the caller has been successfully verified. Verification events can also be exported to SIEM and analytics platforms to support audit and SOC workflows.

    Secure Your Service Desk with Specops

    Strong authentication only works if the process used to reset or recover it is just as secure. Treating service desk verification as part of the identity security process helps reduce the risk of social engineering without making legitimate support harder.

    Specops helps organizations put stronger identity verification in front of high-risk service desk actions such as password resets and account unlocks.

    Contact Specops today to see how you can strengthen identity verification and secure your service desk

    Sponsored and written by Specops Software.

    account attack link MFAs path recovery Weakest
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy

    US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

    SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise

    New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

    New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

    Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Iran claims to have attacked 10 ships near strait of Hormuz after US strikes | Iran

    September 9, 2026

    Andy Burnham: National security can’t come at expense of social security

    September 9, 2026

    I spent an hour riding inside Tesla’s steering-wheel-free Cybercab

    September 9, 2026

    MFA’s Weakest Link: Account Recovery Is the New Attack Path

    September 9, 2026
    Latest Posts

    Justice Dept. Subpoenas Times Freelancer in Effort to Identify Sources

    August 1, 2026

    Michigan joins Minnesota in reporting cyberattacks, with FBI investigating | Cybercrime News

    August 1, 2026

    Tiny aerosol particles could supercharge tropical storm clouds

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Iran claims to have attacked 10 ships near strait of Hormuz after US strikes | Iran

    September 9, 2026

    Andy Burnham: National security can’t come at expense of social security

    September 9, 2026

    I spent an hour riding inside Tesla’s steering-wheel-free Cybercab

    September 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.