
Security teams have spent years hardening authentication, with controls like multi-factor authentication (MFA) and conditional access now commonplace. While stronger authentication can make traditional credential theft less effective, it doesn’t solve every identity problem.
There are several points in the identity lifecycle where trust is established or re-established:
- When a new employee joins.
- When someone loses access to their account.
- When a password or MFA factor needs to be reset.
- When the service desk is asked to make a sensitive change to an account.
Rather than stealing credentials or bypassing MFA, an attacker can instead try to convince the service desk that they are the account holder, using social engineering to exploit legitimate processes.
That puts greater pressure on organizations to secure both the login as well as the processes around account creation and recovery.
How Attackers Exploit Identity at Onboarding and Recovery
In late July 2026, the US Department of State and allies including Japan, Canada and the UK issued a joint alert warning that North Korean IT workers were impersonating foreign nationals to secure employment.
Their tactics focus on falsifying identity documents, such as using images supplied by a third party based in another country to register accounts. The North Korean then carries out the actual work.
These workers typically target technology companies, so the important point is not that every organization should expect the same type of campaign. It is that onboarding creates a moment when trust is established for the first time.
If identity checks fail at that stage, the attacker can enter the environment with access that appears legitimate.
The same issue can occur during the recovery process. Threat actor groups like Scattered Spider are proficient at social engineering, impersonating employees and calling the service desk to reset passwords that gift access to an account.
This tactic was linked to the 2025 M&S ransomware breach, which contributed to an estimated $400 million hit to the retailer’s operating profit through lost sales.
The security question in these scenarios is the same: how confidently can the organization verify that the person making the request is who they claim to be?
Verizon’s Data Breach Investigation Report found stolen credentials are involved in 44.7% of breaches.
Effortlessly secure Active Directory with compliant password policies, blocking 6+ billion compromised passwords, boosting security, and slashing support hassles!
Strong Authentication Still Depends on Strong Identity Checks
When someone calls the service desk claiming that they’ve forgotten their password or lost access to their authenticator, the agent needs to be able to confidently verify the person calling is the real account owner.
However, in many organizations identity checks can still rely on relatively weak signals. A service desk might ask for an employee ID or phone number. Security questions are still common, asking the caller the name of their first pet or where they went to school.
The problem is that many of these checks can be researched, stolen or manipulated. Attackers can find personal information through data breaches or social media.
Even in instances where stronger checks are in place, the North Korean remote worker campaigns demonstrate how documents and other identity evidence can be altered or fabricated.
AI is making impersonation more convincing, too. Attackers can use synthetic profiles, manipulated images, cloned voices and deepfake video to support a false identity or make a social engineering attempt more believable.
All of these make it harder for agents to act with confidence. As it’s vital for organizations to verify users during onboarding and recovery events, they need stronger measures to deliver that verification.
Strengthen Verification During High-Risk Identity Events
Solutions like Specops Verified ID add another layer of assurance and helps service desk agents confidently confirm identity before sensitive actions take place.
It does this by combining government document scanning and validation with biometric liveness detection.
Document checks help confirm that the ID being presented is legitimate, while liveness detection helps verify that a real, present person is completing the process rather than relying on a static image or other replayed evidence.
During onboarding, this gives organizations a stronger way to verify new employees before granting access to corporate systems. That can reduce the risk posed by fraudulent applicants and impersonation attempts, including tactics seen in North Korean remote worker campaigns.
The same approach can be applied when high-assurance verification is needed, such as password resets for privileged accounts.
Rather than adding complexity to every identity event, Specops Verified ID applies stronger verification where the consequences of getting it wrong are highest.
Protect Your Service Desk with Specops
Strong authentication remains essential, but attackers will continue looking for ways around the controls that are hardest to break. Increasingly, that means targeting the processes used to establish or recover identity rather than attacking the login itself.
Whether an organization is onboarding a new employee or helping an existing one recover their account, the challenge is ensuring the right person is granted access.
Specops Verified ID adds government ID validation and biometric liveness detection to these high-risk identity events, helping organizations make that decision with greater confidence.
If you’re interested in learning more about how Specops can strengthen identity verification at the service desk, contact us today to speak to an expert.
Sponsored and written by Specops Software.
