Executive Summary

Multi-factor authentication has significantly raised the cost of account takeover attacks, forcing threat actors to pivot toward alternative attack vectors. Cybercriminal groups like Scattered Spider are increasingly targeting account recovery processes, using social engineering to manipulate help desk staff into resetting passwords and transferring MFA tokens to attacker-controlled devices. High-profile incidents include the 2025 Marks & Spencer breach, where attackers impersonated an employee to trick a third-party contractor into resetting credentials, ultimately deploying ransomware and causing an estimated £300 million in damages. This trend represents a fundamental shift in attack methodology, where the security of accounts depends less on MFA technology and more on the processes used to reset authentication factors.

The emergence of account recovery as a primary attack vector reflects the evolving threat landscape where traditional credential theft methods are becoming less effective. As organizations strengthen their authentication mechanisms with phishing-resistant factors and conditional access controls, attackers are adapting by targeting the human elements of identity management processes.

Why This Matters Now

Account recovery processes have become the new battleground for cybercriminals as traditional MFA bypass techniques become less effective. Organizations must urgently reassess their help desk verification procedures as these processes now represent critical identity security boundaries that attackers are actively exploiting.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Threat actors like Scattered Spider use social engineering to impersonate employees and manipulate help desk staff into resetting passwords and transferring MFA tokens to attacker-controlled devices.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely have constrained the social engineering attack's progression by limiting lateral movement and reducing the blast radius of compromised credentials. Segmentation and identity-aware controls could have contained the attacker's reach across the retailer's network infrastructure.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Identity-aware access controls would likely have limited the scope of compromised credentials by enforcing contextual authentication policies and device trust verification for administrative account access.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation policies would likely have constrained privilege escalation by limiting compromised account access to only explicitly authorized resources and preventing lateral privilege expansion across network segments.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Workload-to-workload inspection would likely have detected and blocked unauthorized lateral movement attempts, constraining the attacker's ability to traverse between network segments and access additional retail systems.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility across cloud environments would likely have detected anomalous communication patterns and unauthorized command channels, constraining the attacker's ability to maintain persistent control over compromised retail infrastructure.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely have constrained unauthorized data transfers by blocking suspicious outbound traffic patterns and limiting the volume of sensitive retail data that could be exfiltrated.

Impact (Mitigations)

While ransomware deployment may still have occurred on initially compromised systems, the constrained lateral movement would likely have reduced the overall impact scope and limited encryption to fewer critical retail operations and customer-facing systems.

Impact at a Glance

Affected Business Functions

  • Identity and Access Management
  • IT Service Desk Operations
  • Multi-Factor Authentication Services
  • Account Recovery Processes
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $300,000,000

Data Exposure

Employee credentials, authentication factors, and potentially sensitive corporate data accessible through compromised accounts. In the Marks & Spencer case, attackers gained network-wide access leading to ransomware deployment affecting business operations.

Recommended Actions

  • Implement Zero Trust Segmentation with identity-based policies to limit lateral movement even after initial account compromise
  • Deploy Multicloud Visibility & Control to detect anomalous authentication patterns and service desk interactions across hybrid environments
  • Enable Egress Security & Policy Enforcement to prevent data exfiltration and unauthorized outbound communications during ransomware deployment
  • Establish Threat Detection & Anomaly Response capabilities to baseline normal service desk behavior and alert on suspicious password reset patterns
  • Strengthen account recovery processes with high-assurance identity verification that matches the security level of primary authentication methods

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image