Attackers exploit account recovery to bypass multi-factor authentication

Security experts warn that attackers are increasingly targeting account recovery processes to bypass multi-factor authentication. These processes, often handled by service desks, can be exploited through social engineering to reset passwords and authentication methods. The article emphasizes the need for stronger identity verification at the service desk to prevent account takeover.
The report indicates that while multi-factor authentication has successfully deterred direct credential theft, malicious actors are now pivoting to intercepting active session tokens or exploiting already-authenticated sessions. This strategic shift underscores that the security of an identity is heavily dependent on the procedures used to restore access when a legitimate user is locked out.
Service desk personnel possess the authority to reset passwords or enroll new authentication devices, making their verification protocols a vital security boundary. Microsoft has formally categorized account recovery within Entra ID as a "high-assurance" task, advocating for robust identity re-confirmation rather than relying on traditional knowledge-based questions.
The shift toward targeting recovery processes could place a heavier burden on IT support teams, potentially slowing down legitimate account restorations for employees. Conversely, organizations that fail to adopt stronger verification at the service desk may experience a surge in successful account takeovers, leading to broader data breaches. This dynamic could ultimately reshape corporate security policies, forcing a trade-off between user convenience and robust identity assurance, affecting both employees and the customers whose data they handle.