Zero Assumptions #3: Your helpdesk just let the attacker in.


Zero Assumptions · Week 3 of 25

Your helpdesk just verified the attacker.
Then reset their password.

KBA and a Zoom check are the most reliably social-engineered controls in your environment. Deepfake audio and video are now commodity tools — purpose-built to defeat them.

In weeks 1 and 2 we covered what happens when an attacker blinds your EDR from inside the endpoint, and how AiTM toolkits intercept your OTP codes in real time. This week we step back further — to the moment before any of that. The moment an attacker calls your helpdesk and asks for a password reset.

The assumption your helpdesk team is making: knowledge-based authentication and a visual Zoom check are sufficient to verify identity before resetting credentials.

The reality: your helpdesk recovery workflow is the most consistently targeted bypass point in the enterprise identity chain — and deepfake technology has made the visual check meaningless.

87%

Of organisations hit by AI-based attacks encountered some form of audio or video deepfake — making synthetic media the dominant format among AI-enhanced identity threat actors.

Source: HYPR / S&P Global — State of Passwordless Identity Assurance 2026

How the helpdesk bypass actually works

The threat group Scattered Spider established helpdesk social engineering as a primary initial access technique years before AI-generated media became widely available. Their operators called helpdesks, impersonated employees convincingly enough to pass verbal verification, and obtained password resets — compromising major enterprises protected by multi-million-pound security stacks without touching a single piece of malware.

The Zoom check — added by security teams specifically in response to voice-only social engineering — is itself now compromised. Real-time video deepfake technology overlays a convincing synthetic face and voice onto a live video stream. A fraudulent Zoom meeting using deepfake participants defrauded a multinational of $25 million in early 2024. That capability has only improved since.

43%

Of AI-attack victims encountered deepfake audio on live calls. 45% encountered pre-recorded deepfake video. Both are now standard components of enterprise identity impersonation campaigns.

Source: HYPR / S&P Global — State of Passwordless Identity Assurance 2026

The KBA layer fails independently of the deepfake problem. Challenge questions — mother's maiden name, first car, childhood street — are trivially answerable from OSINT gathered from LinkedIn, Facebook, and data broker aggregators. For senior employees whose professional history is extensively documented online, a motivated attacker can answer a full KBA challenge without a single phone call.

The blueprint — three-layer cryptographic recovery

Layer 1 — Hardware token binding: If the employee's security key is present, recovery proceeds with minimal friction. No human judgment required.

Layer 2 — Biometric liveness detection: When the registered device is unavailable, AI-driven identity proofing with active liveness detection replaces the human call. Dynamic challenges no pre-recorded deepfake can replicate.

Layer 3 — Out-of-band manager attestation: For high-privilege accounts, a cryptographically signed attestation through a separate authenticated channel provides a second signal.

The human agent doesn't disappear — they shift from making authentication trust decisions to managing the recovery queue. Average handle time drops 35–50%. The attack surface disappears entirely.

Series recap — where we are

Week 1 — The endpoint illusion: Your EDR is blind for 2–4 days during a live attack. Remove the credential as a target.
Week 2 — Network-delivered codes: AiTM toolkits capture your OTP session. FIDO2 origin binding eliminates the category.
Week 3 — The helpdesk open door: KBA and Zoom checks are defeated by deepfakes. Cryptographic recovery closes the gap.
Week 4 (next): Not all FIDO2 tokens are equal. The supply chain of your hardware key determines whether it is a control or a liability.

Coming up next week

Week 4 — Sovereign hardware risk
Every FIDO2 token passed the same protocol compliance test. That test does not cover the chip supply chain, firmware integrity, or manufacturer data residency. We'll publish the full certification comparison table.

Week 5 — The hybrid infrastructure blindspot
Your cloud SSO is hardened. Your on-premises legacy systems are not. Attackers target the seam between them.

Free passwordless audit

Is your helpdesk recovery process still KBA-based?

In a free 30-minute passwordless audit we'll review your current authentication stack, identify your top three identity exposure points, and tell you in plain terms what your helpdesk recovery workflow looks like to an attacker.

No sales deck. No follow-up cadence unless you ask. Just a clear picture of where you stand.

The helpdesk is not a security control. It is a human process running inside a security environment. The fix is to remove the human judgment call from the authentication decision — and replace it with a cryptographic proof.

Mikael Rodin
Managing Director, Ciptor

P.S. If this week's volume made you think about your own helpdesk process — book a free 30-minute passwordless audit. We'll tell you in plain terms what your current recovery workflow would look like to an attacker. No pitch, no obligation.

New to the series? Start from Vol. 1 at ciptor.com/zero-assumptions/zero-assumptions-vol-1/

Kungsporten 4A, 427 50 Billdal, Sweden
Unsubscribe · Preferences

Ciptor

The 2026 threat landscape doesn't care about your 2024 budget. It only cares about your vulnerabilities. Join 10,000+ infrastructure leaders securing the future.

Read more from Ciptor

Zero Assumptions · Week 9 of 25 · Pillar 2: Software stack & contextual risk Your SIEM fired an alert at 09:14.Your EDR caught the same attack at 09:24. Two tools. Same attacker. Ten minutes apart. Neither told the other. Your analyst saw two separate alerts in two separate consoles and triaged them as two separate incidents. The attacker had already moved. In weeks 6, 7, and 8 we covered the operational gaps between assessment cycles, session windows, and board oversight. This week we move...

Zero Assumptions · Week 8 of 25 · Pillar 2: Software stack & contextual risk Your board approved the security budget.That means they've fulfilled their NIS2 obligation. NIS2 Article 20 does not ask your board to approve a budget. It requires management bodies to oversee, be trained in, and be personally liable for your organisation's cybersecurity risk management. Most boards have done none of these things. Most CISOs have not told them. In every previous volume of this series, the assumption...

Zero Assumptions · Week 7 of 25 · Pillar 2: Software stack & contextual risk Your morning login was legitimate.So the session running at 17:00 must be too. Session tokens are hijacked, not phished. Once an attacker has your token, they don't need your password, your MFA, or your hardware key. They already passed authentication. The question is whether your SOC finds them before they find what they came for. Last week we covered identity drift — the entitlement state that diverges from policy...