Attackers Are Skipping the Login and Going After the Hiring Desk

Criminals have figured out that faking a new hire or a password reset is easier than cracking a password. Identity verification is now the soft spot.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal news-editorial image of a generic smartphone held in shadowed hands against a deep blue background, the screen showing an abst
Share

Key points

  • Attackers are shifting away from stealing passwords and instead targeting the moments when a company first sets up or recovers a worker's account.
  • Fake job candidates, some backed by North Korean operations, have been hired into real remote roles at Western companies in 2023 and 2024.
  • Help desk staff tricked into resetting an executive's password have become one of the most reliable ways into a corporate network.
  • Stronger identity checks at hiring, onboarding and account recovery close the gap that multi-factor login alone cannot.

Here is a quiet shift worth paying attention to. The criminals breaking into company networks this year are, more and more, not bothering with your password at all.

They are going after the moments around the password: the day a new hire gets their laptop, the phone call to the help desk when someone is "locked out", the identity check that decides whether a stranger becomes an employee. Get those moments wrong and the attacker walks in through the front door with a valid badge.

Specops, an identity security vendor, laid out the pattern in a piece carried by BleepingComputer this week. The short version: multi-factor authentication, which is the extra code or app prompt you get after typing your password, has made straight password theft harder. So attackers moved.

How are attackers actually getting in?

They are attacking the process that creates or restores an account, not the login screen. Two techniques dominate right now.

The first is the fake worker. A candidate applies for a remote job. The video interview looks fine. References check out on paper. The laptop gets shipped to an address, and a real person starts collecting a salary and, more importantly, sitting inside the corporate network with legitimate access.

US authorities have spent the last two years warning that North Korean IT workers have run this exact scheme at hundreds of American companies, funnelling wages back to the regime and, in some cases, stealing data on the way out. The FBI and Treasury have published guidance for employers on spotting the tells.

The second is help desk social engineering, which is a fancy phrase for phoning up IT support and lying convincingly. The attacker pretends to be a senior employee locked out of their account. They ask for a password reset or for the multi-factor prompt to be moved to a new phone. If the help desk agent obliges without a real identity check, the attacker now owns that executive's account.

This is not theoretical. It is how criminals got into MGM Resorts in 2023, grounding slot machines and hotel systems for days. It is how Scattered Spider, a loose group of English-speaking extortionists, has broken into retailers and insurers throughout 2024 and 2025.

What does a stronger identity check actually look like?

It looks like proving who you are with something more than a friendly voice and a birth date. In practice that means checking a government ID against a live selfie during hiring, tying every account recovery request back to a verified device the employee already registered, and forcing high-risk resets (executives, IT admins, finance) through a second human approver.

Weak spot What attackers do Stronger control
Hiring Submit fake or stolen identity, pass video interview Live ID document check with liveness detection
Onboarding Get laptop shipped to a drop address Verify shipping address against payroll and tax records
Password reset Call help desk, impersonate staff member Require verified device or manager approval
MFA re-enrolment Ask for prompt to be moved to attacker's phone Cool-down period plus out-of-band confirmation

What should ordinary employees take from this?

If you work anywhere with an IT help desk, expect the questions to get harder. That is the point. A reset that takes an extra two minutes and a video call is a reset an attacker cannot fake from a burner phone in another country.

And if you are hiring remote staff, slow down at the identity step. The résumé is not the control. The ID check is.

© 2026 Threat Vectr