Security teams have spent years strengthening authentication. Controls such as multi-factor authentication (MFA) and conditional access are now standard across many organizations. While stronger authentication reduces the effectiveness of traditional credential theft, it does not eliminate every identity security risk.
Trust is established or reestablished at several points throughout the identity lifecycle, including:
- When a new employee joins the organization.
- When an employee loses access to their account.
- When a password or MFA factor must be reset.
- When the Service Desk is asked to make sensitive changes to an account.
Instead of stealing credentials or bypassing MFA directly, attackers may exploit legitimate onboarding and account recovery processes. Through social engineering, they can attempt to convince Service Desk agents that they are the legitimate account owner.
This creates significant pressure for organizations to protect not only the login process, but also the account creation, identity verification, and account recovery workflows that support it.
How attackers exploit identity verification during onboarding and account recovery
In late July 2026, the U.S. State Department and allies including Japan, Canada, and the United Kingdom issued a joint warning about North Korean IT workers impersonating foreign nationals to secure employment.
These campaigns reportedly involve falsified identity documents and images provided by third parties in other countries to register accounts and obtain jobs. North Korean operators then perform the actual work.
Although these campaigns often target technology companies, the broader security lesson applies to organizations in every industry: employee onboarding is the first point at which a relationship of trust is established.
If identity verification fails during onboarding, an attacker could gain access to corporate systems and data under seemingly legitimate credentials.
Similar risks exist during account recovery. Threat actor groups such as Scattered Spider are known for using social engineering to impersonate employees and persuade Service Desk agents to reset passwords or authentication factors.
This type of attack was linked to the M&S ransomware breach in 2025, which reportedly caused an estimated $400 million impact to the retailer’s operating profits through lost sales.
The central question in each scenario is the same: how confidently can an organization verify that the person making the request is who they claim to be?
Verizon’s Data Breach Investigations Report found that 44.7% of breaches involved stolen credentials.
Help protect your Active Directory with compliant password policies, block more than 6 billion leaked passwords, strengthen security, and reduce password-related support requests.
Strong authentication depends on strong identity verification
When someone contacts the Service Desk because they have forgotten a password or lost access to an authentication method, agents must be able to verify that the caller is the genuine account owner before making sensitive changes.
However, many organizations still rely on weak identity verification signals. Service Desk agents may ask callers to provide an employee ID, phone number, or answers to security questions such as the name of their first pet or the school they attended.
The problem is that much of this information can be discovered, stolen, or manipulated. Attackers may obtain personal details through data breaches, social media, phishing, and other sources of publicly available information.
Even stronger verification methods can be undermined. North Korea’s remote worker campaigns demonstrate how identity documents and other forms of evidence can be falsified or fabricated.
Artificial intelligence is also making impersonation attacks more convincing. Threat actors can use synthetic profiles, manipulated images, cloned voices, and deepfake videos to create false identities or make social engineering attempts appear more credible.
These threats make it increasingly difficult for Service Desk agents to verify users with confidence. Because onboarding and account recovery are high-impact identity events, organizations need stronger identity verification controls.
Strengthen identity verification for high-risk account events
A solution such as Specops Verified ID adds an extra layer of assurance, helping Service Desk agents verify identities before sensitive account actions are approved.
The solution combines government-issued identity document scanning and verification with biometric liveness detection.
Document verification helps determine whether the presented identification is legitimate. Liveness detection helps confirm that a real person is completing the process rather than an attacker using a still image, replayed video, or other reproduced evidence.
This gives organizations a stronger way to verify new employees during onboarding before granting access to corporate systems. It can help reduce the risk associated with fraudulent applicants and identity theft attempts, including tactics used in North Korean remote worker campaigns.
The same approach can be used whenever high-assurance identity verification is required, such as resetting passwords or authentication factors for privileged accounts.
Instead of adding friction to every identity-related request, Specops Verified ID enables organizations to apply stronger validation where the potential impact of an incorrect decision is greatest.
Protect your Service Desk with Specops
Strong authentication remains essential, but attackers continue to target the identity processes surrounding authentication. Rather than attacking the login directly, they may exploit the workflows used to establish, verify, or recover a user’s identity.
Whether your organization is onboarding a new employee or helping an existing employee recover access, the objective is the same: ensure that the right people receive access to the right resources.
Specops Verified ID adds government identity document verification and biometric liveness detection to high-risk identity events, helping organizations make more confident access and account recovery decisions.
Want to learn more about how Specops can improve identity verification at your Service Desk? Contact us now to speak with an expert.
Sponsored and written by Specops Software.
Source: www.bleepingcomputer.com


