When the Help Desk Becomes the Front Door: AI-Assisted Social Engineering Hits Onboarding

IBM's 2025 breach data puts AI-assisted attacks at 16% of cases studied. A growing share of those start with a phone call to the service desk, and new-hire onboarding is where defences are thinnest.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
Illustration: an empty modern IT help desk workstation at night
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • IBM's 2025 Cost of a Data Breach Report found 16% of breaches studied involved attackers using AI tools, chiefly for phishing or deepfake impersonation.
  • High-profile intrusions at Marks & Spencer, MGM Resorts, Clorox and others all began with a call to the IT help desk requesting access.
  • New-employee onboarding is the weakest moment because agents often have no prior familiarity with the person calling.
  • Defenders are being urged to add biometric liveness checks, where a camera confirms a real person is present, before resetting passwords or issuing credentials.

There's a boring truth behind a lot of glamorous-sounding AI attacks. The criminal doesn't hack anything. They phone the help desk and ask nicely.

That's the through-line in a new writeup from Specops Software, flagged this week by BleepingComputer, on how generative AI is sharpening one of the oldest tricks around: social engineering, the practice of tricking a human into doing something they shouldn't.

IBM's 2025 breach study puts AI-assisted attacks at 16% of cases examined. Most of that was phishing (fake messages designed to fool staff) and deepfakes (AI-generated voices or video of real people).

Why is the service desk suddenly the problem?

Because it's designed to say yes. Help desks exist to unblock employees fast. An attacker who sounds legitimate doesn't need to defeat firewalls or crack passwords. They can just ask an agent to reset one.

The pattern isn't new. What's changed is how convincing the impersonation has become.

High-profile intrusions at Marks & Spencer, MGM Resorts, Clorox and others all started, according to public reporting, with a small variation of the same request: can you help me get access? From there, attackers moved into real accounts and racked up damages measured in millions. We covered the broader help-desk vulnerability in "The Service Desk Is the New Phishing Inbox" on 24 June, and the picture has only sharpened since.

AI is greasing the wheels in three specific ways.

First, it makes impersonation sound right. Generative AI produces clean emails, natural chat messages or phone scripts in seconds. In targeted cases, attackers use AI-cloned voices or video to stand in for a specific employee. Think of it as caller ID spoofing (an old trick where the number on your screen is faked) except now the voice is faked too.

Second, AI speeds up reconnaissance. Attackers pull details from LinkedIn, job listings and press releases, then let a model stitch them into a believable story: right manager, right team, right internal tool. A request packed with correct-sounding detail feels routine, and routine requests move fast.

Third, AI lets attackers scale. One pretext becomes fifty variations. If agent A pushes back, agent B gets a reworded version an hour later. It's the same volume game that made credential stuffing (trying huge lists of stolen passwords across many sites) so effective on the web.

What actually helps?

Not lectures about being careful. Under pressure, in a queue of tickets, careful isn't a strategy.

The practical fixes look mundane, and that's the point. Stop sending new-hire passwords by SMS or email, both of which can be intercepted. Send an enrollment link instead and let employees set their own credentials. It's the same logic as a bank never emailing your PIN. Our earlier piece "First-Day Passwords Are Still IAM's Soft Underbelly" from 15 June found temporary onboarding credentials turning up repeatedly in breach forensics, which makes this a well-documented gap rather than a theoretical one.

Add biometric liveness detection for sensitive actions like resetting privileged-account passwords. Liveness checks use a camera to confirm a real person is present, not a photo, a recording or a deepfake video. This matters most for remote onboarding, where agents will never meet the new hire face to face.

Require that identity check before the agent clicks reset, not after.

None of this is exotic. It's the same principle a good bank teller applies when someone claims to be a customer: verify first, help second. AI hasn't changed that rule. It's just made the person at the counter a lot better at lying.

© 2026 Threat Vectr