Attackers Are Skipping the Login and Going After the Hiring Desk

Criminals have figured out that faking a new hire or a password reset is easier than cracking a password. Identity verification is now the soft spot.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
A corporate HR office setup with an employee onboarding desk displaying new hire forms and identity verification documents, with a computer screen showing a pas
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Attackers are shifting away from stealing passwords and instead targeting the moments when a company first sets up or recovers a worker's account.
  • Fake job candidates, some backed by North Korean operations, have been hired into real remote roles at Western companies in 2023 and 2024.
  • Help desk staff tricked into resetting an executive's password have become one of the most reliable ways into a corporate network.
  • Stronger identity checks at hiring and account recovery close the gap that multi-factor login alone cannot.

The criminals breaking into company networks this year aren't bothering with your password. They're going after the moments around it: the day a new hire gets their laptop, the call to the help desk when someone's "locked out", the identity check that decides whether a stranger becomes an employee. Get those moments wrong and the attacker walks in through the front door with a valid badge.

Specops, an identity security vendor, laid out the pattern in a piece carried by BleepingComputer this week. Multi-factor authentication, the extra code or app prompt you get after typing your password, has made straight password theft harder. So attackers moved.

How are attackers actually getting in?

They're attacking the process that creates or restores an account, not the login screen. Two techniques dominate right now.

The first is the fake worker. A candidate applies for a remote job, the video interview looks fine, references check out on paper. The laptop gets shipped to an address, and a real person starts collecting a salary while sitting inside the corporate network with legitimate access.

US authorities have spent the last two years warning that North Korean IT workers have run this exact scheme at hundreds of American companies, funnelling wages back to the regime and stealing data on the way out. The FBI and Treasury have published guidance for employers on spotting the tells. We reported on 11 August on researchers who set up a fake crypto company and hired three suspected North Korean operatives, recording every keystroke on the laptops they issued.

Help desk social engineering is the second technique: phoning IT support and lying convincingly. The attacker pretends to be a senior employee locked out of their account, asks for a password reset, or requests that the multi-factor prompt move to a new phone. If the agent obliges without a real identity check, the attacker owns that executive's account.

This isn't theoretical. MGM Resorts fell this way in 2023, with slot machines and hotel systems down for days. Scattered Spider, a loose group of English-speaking extortionists, has broken into retailers and insurers throughout 2024 and 2025 using the same playbook.

What does a stronger identity check actually look like?

It means proving who you are with something more than a friendly voice and a birth date. In practice: check a government ID against a live selfie during hiring, tie every account recovery request to a verified device the employee already registered, and route high-risk resets for executives, IT admins and finance staff through a second human approver.

Weak spot What attackers do Stronger control
Hiring Submit fake or stolen identity, pass video interview Live ID document check with liveness detection
Onboarding Get laptop shipped to a drop address Verify shipping address against payroll and tax records
Password reset Call help desk, impersonate staff member Require verified device or manager approval
MFA re-enrolment Ask for prompt moved to attacker's phone Cool-down period plus out-of-band confirmation

What should ordinary employees take from this?

If you work anywhere with an IT help desk, expect the questions to get harder. A reset that takes an extra two minutes and a video call is one an attacker can't fake from a burner phone abroad.

If you're hiring remote staff, slow down at the identity step. The résumé isn't the control. Your ID check is.

© 2026 Threat Vectr