Security

Cyber-crime

Stop social engineering at the IT help desk

How Secure Service Desk thwarts social engineering attacks and secures user verification


Sponsored Post Ransomware can hit any organization at any time, and hackers are proving adept at social engineering techniques to gain access to sensitive data in any way they can.

A case in point can be seen in the attack on MGM Resorts International recently, which proved to be a very expensive incident for the company. Reports suggest the attack will cause an estimated US$100m hit to its revenue after the hotel and gambling firm was forced to shut down its IT systems to contain the damage after customer contact information, gender, date of birth, social security, passport and driver's license numbers were stolen.

But rather than attacking the IT systems itself, the hackers used social engineering tactics to persuade an employee to reveal sensitive user credentials over the telephone. These were then used to circumnavigate MGM's cyber security defences and log in as an administrator before escalating the access privileges and letting loose the ransomware.

Nor was the incident the only example of hackers impersonating legitimate users when talking to the IT helpdesk. The same thing reputedly happened to a UK-based energy firm which fell victim via an AI voice impersonation of the parent company's chief executive, and games company EA Electronic Arts which was tricked into granting an attacker access to the company's internal network.

So how can any organization be sure that the person who is making a request for access to company systems, data and applications is actually who they say they are? Especially when pretty much anybody can so easily harvest the information they need to help them conduct a convincing impersonation from the masses of data freely available on social media?

Specops reckons it has the answer in the form of its Secure Service Desk, which uses dynamic multi factor authentication – something you know, something you have, something you are (biometrics) – to reduce the risk of hackers successfully using social engineering to fool staff on the help desk. The solution offers various identity verification options, including mobile or email codes, and integration with commercial Identity Access Management (IAM) tools like Duo Security, Okta and PingID.

You can learn more about how Secure Service Desk authenticates and securely verifies the identity of callers to IT helpdesks and request a free trial or demo of the software here.

Sponsored by Specops.

Send us news

Android iMessage app Beeper releases working update of blue-bubbled tool

Dev claims to have fixed 'issue that caused messages not to be sent or received'

Kernel kerfuffle kiboshes Debian 12.3 release

A mis-merged patch causing corruption on ext4 volumes is to blame

BlackBerry squashes plan to spin out its IoT biz

Board and incoming CEO decide reorganizing is better than splitting

British train system is getting another excuse for delays - solar storms

Let's choo-choo-choose safety, folks

Interpol moves against human traffickers who enslave people to scam you online

Scum lure folks with promises of good jobs in crypto and then won't let them leave

ByteDance slides around Indonesian social commerce ban with $1.5 billion buy

Takes huge stake in local superapp Tokopedia, for the good of the small business community

China's SpaceX wannabe recycles a rocket after just 38 days

Interstellar Glory Space Technology gets a boost – even though it's yet to reach orbit

Epic decision sees jury find Google's Play store is illegal monopoly

Fortnite dev hails 'a win for all app developers and consumers around the world'

Proposed US surveillance regime would enlist more businesses

Expanded service provider definition could force cafes and hotels to spy for the feds

Broadcom halves subscription price for VMware's flagship hybrid cloud suite

Also kills perpetual licenses, adds a vSphere bundle for smaller users

Boffins fool AI chatbot into revealing harmful content – with 98 percent success rate

This one weird trick works every time, most of the time

Microsoft partners with labor unions to shape and regulate AI

Redmond reassures AFL-CIO workers they won't be pushed out by technology