The Attacker Did Not Break In. They Asked for a Reset.
Account recovery is a login too, and usually the weakest one you have.
Executive Summary
Businesses have spent years hardening the front door with strong passwords, multifactor authentication, and better email filtering. Far fewer have looked at the back door, which is how a locked out employee gets back in. That process is a login. It grants the same access, and in most small companies it is guarded by a familiar voice and a willingness to help. Federal advisories now describe criminal groups whose main technique is a phone call to support asking for a password reset. Here is why the old identity checks stopped working, and what a sound process looks like.
Every Account Has Two Doors
The front door is the one you think about. A password, a code, a prompt on a phone. The second is account recovery, and it exists because people lose phones and get locked out on the road. It has to exist. Most companies built it for convenience, back when everyone who called was someone they knew by name.
Recovery grants exactly what the front door grants. If someone talks their way into a password reset and a new authentication device, every control you bought is now working correctly on the attacker’s behalf. No malware to detect, no failed login to alert on. The session is real, the account is real, and the process that handed it over worked as designed.
The Questions We Used to Ask Are Now Public
Employee ID. Date of birth. The last four of a Social Security number. A manager’s name. These were reasonable checks when that information was hard to come by. Years of breaches put personal records on sale in bulk, professional profiles publish reporting lines, and an attacker can profile your employee in an afternoon.
Two developments made it worse. Caller ID can be set to any number, so a call that appears to come from an employee’s mobile proves nothing. And a short clip of someone speaking is now enough to clone their voice well enough to fool a colleague. Recognizing the voice is no longer verification. It is a feeling.
In a Small Business, the Help Desk Is Someone Who Likes You
Large companies have a service desk with scripts and a supervisor. Small businesses have an office manager, an owner, and an outsourced IT provider, often all three depending on the day. The person doing resets is usually the most accommodating one in the building, which is precisely the trait the attack exploits. Then add pressure. The caller is traveling. The caller is with a client. The caller is the CFO and the payment run closes at five. Urgency is the whole play, built to make following the process feel like obstruction.
What a Sound Reset Process Looks Like
None of this requires software you do not own. It requires a rule agreed to in advance, while nobody is panicking.
- Write it down, and apply it to everyone. One page covering password resets, authentication changes, and new device enrollment. The exception for senior people is the exact hole attackers aim at, so there is no exception.
- Verify through a channel the caller did not choose. Call back the number in the employee record, or confirm with their manager. An attacker controls the call they placed. They do not control the one you return.
- Stop treating facts as proof. Anything an attacker can buy or read is not verification. Use something the business controls: a code to a device already registered to that employee, a short video call with someone who knows them, or approval from the manager on record.
- Treat a new authentication device as a bigger event than a password. A password can be reset again in minutes. An authentication method bound to an attacker’s phone is a durable key. That request gets the strongest check you have, every time.
- Put the rule in your IT provider’s contract, then test it. Ask what happens today if someone calls them claiming to be your employee. A vague answer is your answer.
- Make the slow path the safe path. Whoever performs resets must be free to follow the process without being overruled by rank or urgency. If following the rule can get someone in trouble, the rule does not exist.
Watch What Happens Next
Resets are normal, so the goal is not to flag every one. It is to notice the sequence that follows a bad one. A new authentication method is added, then a sign in from an unfamiliar device, then a mailbox rule quietly forwarding messages, then files touched in volumes nobody can explain. Those events are visible in Microsoft 365 and Google Workspace today, and they are worth alerting on.
One cheap control catches a surprising amount: tell the employee. An automatic notice whenever their password or authentication method changes turns a silent takeover into a phone call that starts with four useful words. I did not do that.
The Takeaway
You cannot remove account recovery, and you should not want to. You can decide in advance, in writing, what proof it takes to let someone back in. Attackers are not defeating multifactor authentication nearly as often as they are persuading somebody to hand over a new key to it. Decide who may say yes, and what they must see first.
How Simulint Helps With BlueSphere
BlueSphere’s AI generated phishing, vishing, and smishing simulations cover the scenario that matters here: the urgent caller claiming to be a locked out executive, and the text that arrives first to make the call feel expected. The point is not to catch people out. It is to make the request feel familiar before it is real, so following the process becomes the reflex.
BlueSphere Shield covers the other half, watching the identity events that follow a reset around the clock and acting on them instead of filing them. Learn more: https://lnkd.in/eE9HTaw8
