While multi-factor authentication strengthens account security, attackers are increasingly exploiting password recovery and authentication reset processes. Stronger identity verification at service desks is now critical to block social engineering attacks.
Multi-factor authentication has made direct account takeovers significantly harder, but security researchers have identified a major vulnerability: the account recovery process.
Cybercriminals are shifting tactics to target password resets and authentication method changes—paths that often require minimal verification. By convincing support staff to approve recovery requests through social engineering, attackers can bypass MFA entirely.
The risk stems from inconsistent identity verification practices at help desks. Many organizations lack robust protocols to confirm a user's legitimacy before granting access changes, leaving recovery processes as an attractive entry point for attackers.
Security firm Specops emphasizes that stronger identity verification measures are essential. Organizations should implement multi-step verification for recovery requests, require additional documentation, and train support staff to recognize social engineering attempts.
As MFA adoption increases, the battle shifts from breaking authentication to exploiting the human-dependent processes that support it. Securing account recovery is now as important as securing login itself.
Two major US law firms have fallen victim to cyber extortion attacks, with threat actors obtaining and publishing private client documents. The incidents highlight ongoing security vulnerabilities in the legal sector.
U.S. cybersecurity and intelligence agencies have identified six Chinese AI companies conducting large-scale distillation attacks on American frontier AI models since late 2024, extracting billions of tokens in the process.
Healthcare technology company Veradigm disclosed a data breach after a ransomware attack on a third-party vendor exposed patient personal information. A cybersecurity incident at the vendor compromised data stored on Veradigm's systems.
A group of US lawmakers spanning both parties has called on the government to ban three Indian companies accused of running hacking operations to steal information for litigation purposes.