The helpdesk believed the caller. Or the employee typed the code while the stranger stayed on the line.
Either finish works. Across 2021 through 2025 public cases, attackers used LinkedIn recon, urgency scripts, and phone pressure to reach workforce identity. Sometimes they impersonated employees to service desks and walked out with password resets, MFA factor resets, or a swapped phone number on the enrolled factor. Sometimes they steered employees onto fake VPN or IdP pages and harvested passwords plus one-time codes or push approvals in real time. The product is always a secret a human can still produce.
This page is the rolling “what happened” hub for that class. The August 2026 five-week spoofed-login wave aimed at more than 200 organizations is a sibling campaign story, not a rewrite of every older helpdesk case: five-week vishing harvested MFA codes at 200 orgs. Prevention-side mechanics live on the companion: phishing-proof MFA stops workforce MFA vishing.
How the call finishes before anyone notices
Start with reconnaissance. Public IR write-ups on Scattered Spider-style activity describe callers who already know names, managers, last four of SSN, or “new phone” cover stories. Mandiant’s UNC3944 reporting (June 2024) frames the helpdesk as the door: claim a lost device, pass soft identity checks, reset password and MFA, then ride Okta or SSO into SaaS.
Corporate filings fill in company names without needing Hollywood detail. MGM Resorts’ September 2023 disclosures sit next to IR claims of a short helpdesk call after LinkedIn recon. Clorox’s later complaint against Cognizant alleges callers posing as employees obtained password and MFA resets from an outsourced service desk on 11 August 2023. Okta’s Cross-Tenant Impersonation advisory shows the privileged end of the same idea: reset MFA for Super Admins, then abuse inbound federation.
The other costume is coached login. Twilio’s 2022 employee voice-phishing notice, Cisco Talos’s MFA fatigue plus vishing write-up, GuidePoint’s VPN portal harvest campaign, and Princeton’s 2025 OIT-themed fake sign-on plus Duo push all rhyme. The employee is on a live call. The page looks right enough. The second factor is something they can still approve or type. The attacker spends it on the real service.
Why “we have MFA” still lost on the phone
MFA that an employee can read aloud, paste into a form, or tap Approve under urgency is still a transferable proof. MFA that a helpdesk can reset after a persuasive story is still a recoverable secret. Attackers do not need to break cryptography. They need a human who can complete the ceremony for them.
Push bombing shows up as a sibling tactic in some cases (Cisco 2022). The fatigue softens the victim. The voice call supplies the trust. Neither step requires malware on a corporate laptop for the initial identity win. Later ransomware, Salesforce connected-app abuse, or payroll diversion is whatever access that identity already bought.
Session cookies and cloud tokens appear after the phishable step succeeds. Stealing a cookie from a machine that already held a good login is a different, harder path. The phone script usually never needs that path.
Years of the same playbook, different logos
Archive seed incidents on this hub’s Updates list are not a complete victim census. They are evidence the class repeats: EA IT social engineering for an MFA token (2021), Robinhood support-employee vishing (2021), Twilio and Cisco (2022), Okta Cross-Tenant and Clorox and MGM (2023), Michigan Medicine and TfL and Seyfarth (2024), Marks & Spencer, Co-op, UNC6040 Salesforce vishing, and Okta’s payroll-pirates helpdesk pattern (2025).
CISA and FBI’s AA23-320A advisory on Scattered Spider put the helpdesk MFA-reset pattern in government language. That does not mean every later retailer incident is the same actor. It means defenders keep meeting the same human door.
A fix exists for the transferable-factor problem. The companion on mfa2point0.com covers prevention without retelling every filing here.
FAQ
How does workforce MFA vishing usually work?
Workforce MFA vishing usually works by putting a live coach on the phone who either talks helpdesk staff into resetting passwords and MFA factors or walks an employee through a fake login that collects passwords plus one-time codes or push approvals. Public cases from MGM-style helpdesk resets to spoofed VPN and IdP pages show the same class: a human still holds a secret the attacker can spend.
Did every named company in this hub use the same MFA product?
No. Public reporting often leaves the MFA method unnamed. The shared weakness is the factor class (resettable or transferable proofs), not a single brand.
Is helpdesk impersonation different from employee code harvest?
They are two finishes of the same social-engineering class. Helpdesk impersonation abuses recovery and issuance. Coached code harvest abuses the login ceremony. Both need a transferable factor. Some campaigns use both.
What should readers do with the August 2026 200-org wave story?
Read it as a campaign-specific hub for a multi-week spoofed-login code harvest. Use this page for the multi-year helpdesk and coaching pattern.
Where is the prevention write-up?
The prevention companion is on mfa2point0.com: phishing-proof MFA stops workforce MFA vishing. This page stays on what the calls actually did.
Updates
2025-12-15: Threat intel pattern
Okta Threat Intelligence documented “payroll pirates” who socially engineer IT helpdesks to reset employee passwords, enroll attacker MFA methods, then alter payroll banking in HR apps.
Source: Okta Newsroom, Payroll pirates target help desks
2023-09-12: Named victim filing
MGM Resorts disclosed a major September 2023 cybersecurity incident in SEC filings amid public reporting of helpdesk social engineering against workforce identity.
Source: SEC EDGAR, MGM Resorts 8-K
2023-08-14: Named victim filing
Clorox’s 14 August 2023 Form 8-K disclosed unauthorized activity and operational disruption later tied in public reporting to service-desk social engineering.
Source: SEC EDGAR, Clorox 8-K
2023-07-29: Vendor advisory
Okta’s Cross-Tenant Impersonation advisory documents social engineering of IT service desks to reset MFA factors for highly privileged Super Administrator users, then abuse inbound federation to impersonate users across the tenant.