Threat Intelligence

Social Engineering Beyond Phishing: Vishing, Pretexting and Help-Desk Attacks

Phishing receives the overwhelming share of awareness training, and that is reasonable given its volume. But attackers use whichever channel works, and several of the most effective techniques never touch email at all. The help desk in particular has become a favoured route, because it is designed to be helpful to people who cannot access their accounts.

Social Engineering Beyond Phishing: Vishing, Pretexting and Help-Desk Attacks

The channels in use

  • Vishing (voice) — a phone call impersonating IT support, a supplier or an executive. Voice conveys urgency and authority far more effectively than text, and leaves no artefact to analyse afterwards.
  • Smishing (SMS) — text messages carrying a link or a request, often exploiting the fact that mobile interfaces make it harder to inspect a destination.
  • Pretexting — constructing a plausible scenario and identity in advance, then sustaining it across several interactions to build credibility before the actual request.
  • Help-desk manipulation — persuading support staff to reset a password or register a new MFA device, which bypasses even strong authentication entirely.
  • Physical entry — tailgating, or arriving as a contractor, delivery driver or auditor with enough props to look routine.
  • Removable media — leaving devices where curiosity will do the rest.
  • Multi-channel combinations — an email that mentions a follow-up call, then the call arriving as promised, which makes both far more credible than either alone.

Why the help desk is targeted

A help desk is measured on speed and satisfaction, staffed by people trained to be accommodating, and exists precisely to assist users who cannot authenticate. That combination is exactly what a social engineer needs.

The attacker typically has partial genuine information — a real name, job title, manager and start date, assembled from public sources — which makes the request feel legitimate. Where verification relies on details of that kind, it verifies nothing.

The help desk exists to help — that is the vulnerability
The help desk exists to help — that is the vulnerability

Verification that actually verifies

  1. Never accept knowledge-based answers that appear on professional networking profiles, company websites or public records.
  2. Use a callback to a number already held in the HR record, never a number supplied during the interaction.
  3. Require manager approval, initiated through a separate channel, for high-risk actions such as MFA re-registration.
  4. For sensitive resets, use an in-person or video check against a known photograph where practical.
  5. Introduce a deliberate delay for the highest-risk requests. Urgency is the attacker's primary tool, and a mandatory pause removes it.
  6. Give staff explicit authority to refuse and escalate without fear of a complaint — a policy that makes people afraid of being unhelpful is a policy that will be bypassed.
  7. Log and review resets and MFA registrations as security events rather than routine tickets.

Making training realistic

Annual slide-based awareness training has limited effect on these techniques. What helps is exposure to realistic scenarios in the relevant channel, aimed at the roles most likely to be targeted — help desk, finance, HR and executive assistants.

Simulated calls are far more instructive than simulated emails for this purpose, though they need careful design and clear internal authorisation. The objective is not to catch people out; a programme that humiliates staff produces concealment rather than reporting, which is the opposite of what you need.

Verification must not rely on discoverable information
Verification must not rely on discoverable information

Reporting is the real metric

The most useful measure is not how many people were fooled but how quickly an attempt gets reported, because a single report lets defenders warn everyone else while the campaign is still running.

That requires reporting to be effortless, acknowledged, and never punished — including when the person already clicked, answered, or approved. People who fear consequences delay reporting, and delay is what converts an attempted attack into a successful one.

Related from TechBiz Security

Sources & further reading

Frequently asked questions

What is vishing?
Vishing is voice-based social engineering — a phone call in which the attacker impersonates IT support, a supplier or a colleague to extract information or trigger an action. Voice conveys urgency and authority effectively and leaves little forensic evidence.
Why are help desks a common target?
Help desks are designed to assist users who cannot authenticate, are measured on responsiveness, and often verify identity using information an attacker can research publicly. That makes them an effective route around otherwise strong authentication.
How should a help desk verify identity properly?
By using factors an attacker cannot research: a callback to a number already in the HR record, manager approval obtained through a separate channel, or a visual check against a known photograph. Knowledge-based questions about role, manager or start date are not sufficient.
Does security awareness training actually reduce social engineering?
Generic annual training has limited effect. Role-specific, realistic, repeated exercises in the relevant channel work better, and the most valuable outcome is fast reporting — which requires a culture where reporting is easy and never punished.

Related reading

0 comments

Leave a comment

Comments are moderated before appearing.