When the security routine becomes the attack itself

A call from “IT”. A request to register a new passkey. Everything looks like normal security procedure, and that is exactly why it works.

Today’s social engineering attacks are increasingly not based on employees doing the wrong thing. Attackers are increasingly using legitimate tools, familiar processes, and human trust to get in.

This raises a new question for every organization: can your security routines be followed straight into an attack?

From suspicious emails to credible calls

For a long time, security work around the human factor has focused on teaching employees to recognize what looks suspicious. To pay attention to the misspelled email, the strange link, and the unknown sender. That work has delivered results.

As a result, attackers are finding new approaches. According to Mandiant’s M-Trends 2026, phone-based phishing, known as vishing, accounted for 11 percent of initial intrusions in 2025, making it the second most common entry point. At the same time, email phishing decreased from 14 to 6 percent. Verizon’s Data Breach Investigations Report 2026 shows that the human factor was involved in 62 percent of data breaches, and that mobile-based attacks via text messages and calls had a 40 percent higher success rate than traditional email phishing.

The shift is clear: from the written message, which can be reviewed calmly, to the phone call where someone with authority wants you to do something now.

When the attacker plays the helper

During 2026, several campaigns have followed the same pattern. Between January and April, security company Palo Alto Networks Unit 42 mapped a campaign in which attackers created external Microsoft Teams accounts with names such as “ITProtectionDepartment” and “MandatoryNetworkMonitoring”.

More than 150 employees at over ten companies were contacted. After an initial chat, an “IT technician” called and asked the employee to start Microsoft’s built-in remote assistance tool, Quick Assist. A successful call took 10 to 15 minutes.

A similar campaign, tracked by Sophos under the name STAC4749, led to ransomware attacks against several organizations. The calls usually took only two to two and a half minutes. In one case, the files were encrypted within 17 hours.

When multi-factor authentication becomes part of the fraud

Multi-factor authentication, MFA, is still one of the most important protections an organization can have. But attackers have learned that instead of bypassing the protection, they can get the user to open the door themselves. There have been several recent cases of this.

In September, Microsoft described how the service EvilTokens, which appeared in February 2026, has been used to compromise more than 12,000 inboxes across more than 10,000 organizations.

The method exploits a legitimate sign-in flow that is actually intended for devices such as smart TVs and conference equipment. The user receives a code and is asked to enter it on Microsoft’s real website. No fake login page, no stolen password, but the attacker still gets a fully authenticated session.

Another example is Okta, which in July warned about a campaign where attackers call users and urge them to register a new password. Passwords are difficult to phish during login, but the registration process itself becomes a new weak point if someone can be persuaded to complete it on behalf of the attacker.

The same logic applies to account recovery. In May, Canada’s national cybersecurity center warned about actors calling help desks. During the call, they pretend to be employees and get MFA reset or a new device linked to the account.

It is not about carelessness, but about human reflexes

It is easy to describe someone who is deceived as careless. But these attacks are not aimed at carelessness. They target qualities we normally want to see in employees.

They rely on trust in the IT department and in the tools the organization itself has introduced. On respect for authority, listening to someone who sounds knowledgeable and says that something needs to be done. In many cases, they also rely on the willingness to help, especially among people working in support roles.

How to build routines attackers cannot misuse

The solution is not to distrust every call from IT, but to ensure that routines can withstand a fraud attempt.

  1. Make it clear what IT never does. Communicate simply and repeatedly that IT will never call and ask employees to start remote assistance, approve an MFA notification, read out a code, or register a new sign-in method.
  2. Verify in the other direction. An incoming call should never be enough for verification. Hang up and call back using a known number, or open a ticket through the normal channel.
  3. Strengthen account recovery routines. MFA resets and new devices should require stronger identity verification, preferably with approval from a manager or a second person for accounts with elevated privileges.
  4. Close legitimate paths that are not needed. Restrict external Teams contacts, remote assistance tools, and sign-in flows such as device codes where they do not serve a clear purpose.

The human factor is often described as the weakest link. But that also makes people a crucial part of the defense, provided the organization gives them the right conditions.


Read more articles here