iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A service desk can undo strong multi-factor authentication (MFA) if it lets someone replace an authenticator after weak identity checks. In Serguey Shinder’s personal account, the caller did not defeat the existing second factor: they persuaded support to reset it and help enroll a new device. The distinction matters because stronger sign-in does not fix an insecure recovery process.
How a help-desk reset became an MFA bypass
Shinder recounts a caller posing as a regional sales manager who says a new handset has left them without their authenticator while a customer is waiting. The analyst accepts personal and contextual details as proof, resets the factor, and helps enroll another device. According to Shinder, the information was available or discoverable, and the service desk followed the process it had been given. This is a personal account, not an independently verified incident report. Source
The weakness was not a flaw in the authenticator. It was the path for replacing it: a convincing story and information about a person’s role or colleagues stood in for evidence tied to an established recovery method. Once support reset the factor and enrolled a device for the caller, the attacker could potentially authenticate as the account holder.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Why recovery needs its own security controls
Authentication and account recovery solve different problems. NIST’s current digital identity guidance, SP 800-63B-4, treats recovery as a distinct process for a subscriber who has lost control of their authenticators. It recognizes recovery codes, recovery contacts, and repeated identity proofing; application-specific methods such as interaction with a credential service provider’s agent may also be used when supported by risk analysis and documented. NIST says an account recovery event should trigger a notification to the subscriber or designee. NIST SP 800-63B-4
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
That means a recovery policy should define in advance what evidence is acceptable, who may approve a reset, how the request is recorded, and how the account holder is alerted. Letting a caller select the questions or channels used to prove their identity can undermine the process: an attacker may have gathered the same details or may steer the interaction toward a weak check.
What Shinder says his organization changed
Shinder describes changes intended to distinguish ordinary resets from requests affecting accounts with privileged or financial access. These are the organization’s measures as he recounts them, not a universal NIST prescription; organizations should adapt recovery controls to their identity architecture and risk policy. Shinder’s account
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Use an established callback channel for higher-impact accounts. His example requires calling a number held in the HR record rather than one supplied during the request.
- Require an additional approval. His account describes line-manager confirmation for accounts with privileged or financial access.
- Move routine resets to self-service tied to an enrolled device. This can reduce reliance on an analyst accepting a caller’s story, provided the existing device remains available and the self-service flow is itself appropriately secured.
- Allow analysts to refuse and escalate. Staff should have explicit authority to pause a request when it cannot be verified or when pressure is being used to bypass normal controls.
Build a recovery process around risk, evidence, and notification
A practical policy can turn those lessons into controls without assuming that every reset carries the same risk:
- Classify the account’s impact. Identify which accounts can authorize payments, access sensitive data, administer systems, or affect other users. Set verification and approval requirements according to the consequences of an unauthorized reset.
- Specify acceptable evidence before a request arrives. Use recovery methods established for the account, such as a recovery code, recovery contact, or an approved identity-proofing process. Do not treat a plausible biography, knowledge of coworkers, or knowledge of a customer as a substitute for that evidence. NIST allows application-specific recovery methods when supported by risk analysis and documented. NIST SP 800-63B-4
- Use channels already on file. A callback is useful only if it goes to a trusted number recorded before the request, not a number the claimant provides during the interaction. Apply the same principle to other recovery contacts and approval channels.
- Record the basis for the decision. Keep an auditable record of the evidence checked, approvals obtained, the reset performed, and any escalation. This makes exceptions visible and helps the organization review whether the policy is working.
- Notify the account holder or designated contact. Recovery notifications give the legitimate user a chance to detect an unexpected reset. NIST SP 800-63B-4 calls for notification after an account recovery event. NIST SP 800-63B-4
- Provide a safe route to pause or escalate. A request that cannot meet policy should not become an exception simply because the caller claims an urgent business need. Analysts need a defined escalation path and authority to refuse completion while verification is unresolved.
How to handle urgency without treating it as proof
Distress, confusion, and coercion are relevant signals for trained staff to notice, but none proves by itself that a request is fraudulent. NIST SP 800-63A discusses social engineering as a threat in identity proofing and includes such indicators in training for trusted referees. In a service-desk interaction, urgency should prompt the analyst to follow the established checks and escalate when necessary—not to skip verification, and not to assume guilt based on demeanor alone. NIST SP 800-63A
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Why phishing-resistant MFA is not enough on its own
CISA recommends that businesses aim to use phishing-resistant MFA and identifies physical security keys as its strongest option among the methods compared in its guidance. Such a key strengthens ordinary sign-in, but it cannot independently stop a support agent from binding an attacker’s new authenticator through an insecure recovery process. Strong authentication and secure recovery must work together. CISA business guidance NIST SP 800-63B-4
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What this account can—and cannot—show
Shinder’s account illustrates how a weak reset workflow can undermine MFA, but the sources cited here do not establish how often this specific attack occurs or independently validate the incident’s details. NIST and CISA provide identity and security guidance, not measurements of service-desk MFA-reset attacks. The practical lesson is therefore about process design: do not let a caller’s narrative replace previously established evidence, and scale recovery controls to the impact of the account.
Quick Recap
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

