Laptop lock

Security teams have spent years hardening authentication, with controls like multi-factor authentication (MFA) and conditional access now commonplace. While stronger authentication can make traditional credential theft less effective, it doesn’t solve every identity problem.

There are several points in the identity lifecycle where trust is established or re-established:

  • When a new employee joins.
  • When someone loses access to their account.
  • When a password or MFA factor needs to be reset.
  • When the service desk is asked to make a sensitive change to an account.

Rather than stealing credentials or bypassing MFA, an attacker can instead try to convince the service desk that they are the account holder, using social engineering to exploit legitimate processes.

That puts greater pressure on organizations to secure both the login as well as the processes around account creation and recovery.

How Attackers Exploit Identity at Onboarding and Recovery

In late July 2026, the US Department of State and allies including Japan, Canada and the UK issued a joint alert warning that North Korean IT workers were impersonating foreign nationals to secure employment.