Blog/Phishing

Helpdesk Phishing: Attackers Calling Your IT Team

Attackers call IT helpdesks pretending to be employees who need a password reset or new two-step device. How helpdesk social engineering works and the verification that stops it.

CyberWatch AI1 October 2026 · 2 min read
An IT support worker with a headset at his desk

Most phishing targets employees. Helpdesk phishing targets the people who can reset their accounts. An attacker calls the IT helpdesk pretending to be a staff member: "I'm travelling, I lost my phone, and I need my two-step verification reset right now for a client meeting." If the helpdesk complies, the attacker has the account.

How it works

  1. The attacker researches an employee's name, role, manager and location from public profiles.
  2. They call the helpdesk, often at busy times, with an urgent, plausible story.
  3. They ask for a password reset, a new two-step device, or to remove two-step verification.
  4. With access, they move through email, files and systems, sometimes leading to ransomware or fraud.

Verification that stops it

  • Call back the employee on a number already on record, not one given on the call.
  • Manager confirmation for resets of two-step methods.
  • Identity checks using systems the attacker cannot see, such as in-person or video verification against an ID on file.
  • Extra steps for high-privilege accounts, such as administrators and executives.
  • Phishing-resistant sign-in, such as passkeys and security keys, with well-controlled recovery. See security keys.
  • Alerts to the real user whenever their password or two-step method is changed.

Urgency is the attacker's tool. Helpdesk staff should be backed by policy to slow down and verify, whoever the caller claims to be.

For employees

  • Expect the helpdesk to verify you, and support it.
  • If you get a notice that your password or two-step method changed and you did not request it, report it immediately.

Got an unexpected account change alert? Paste it into CyberWatch AI Scan for a free check, then contact IT.

For more, read the complete guide to phishing.

Frequently asked questions

Why target the helpdesk instead of the employee?

Because helpdesks can reset passwords and two-step methods. One successful call can hand an attacker a working account.

How do attackers sound convincing?

They research names, roles and managers from public profiles and company sites, and often call at busy times with urgent stories.

What verification works?

Call-backs to a number on record, manager confirmation, identity checks through systems attackers cannot see, and extra checks for high-privilege accounts.

Sources

  1. Multifactor Authentication, US Cybersecurity and Infrastructure Security Agency
  2. Small business guide: cyber security, UK National Cyber Security Centre
  3. Cyber Essentials, US Cybersecurity and Infrastructure Security Agency
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.