Help-desk and MFA manipulation attacks don't bother with malware: an attacker calls IT support pretending to be a locked-out employee, or floods a target's phone with MFA push prompts until one gets approved out of fatigue. This family covers the run of 2021-2023 breaches, including Uber, EA, Caesars and Microsoft, that made this the defining enterprise social engineering pattern of its era.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT to get one approved.
HARussia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power.
HAScattered Spider's ten-minute vishing call to MGM's help desk reset MFA and seized identity systems, an incident Moody's called credit-negative.
HAA single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository.
HAJLR's five-week production halt and record £1.9bn UK economic hit were first blamed on helpdesk-vishing by a criminal collective calling itself.
HABetween 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
HAHackers bought a $10 stolen Slack session cookie, used it to reach EA's internal Slack.
HAThe Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom in 2023.
MGM Resorts, Caesars Entertainment, and Jaguar Land Rover were all breached after an attacker called IT support and talked a help-desk agent into resetting credentials or approving access for someone who was not who they claimed to be.
Uber in 2022 was breached after a contractor was flooded with MFA push prompts and eventually approved one out of fatigue, EA Games suffered a Slack and MFA social engineering breach the year before, and the Microsoft LAPSUS$/DEV-0537 source-code intrusion followed the same push-fatigue and social engineering pattern.
The 2015 Ukraine power grid attack by Sandworm and BlackEnergy showed the same social engineering foothold techniques used against industrial control systems, while the FTC pretexting sweep against telephone record sellers showed regulators treating pretext-based access as a distinct enforcement priority.