Social engineering attacks don’t exploit software. They exploit people. An attacker who can convince a help desk agent to reset a password, or persuade an employee to approve an MFA request, bypasses every technical control in place. No vulnerability was needed. No malware was deployed. The breach happened because someone was convinced.
This guide covers the most common social engineering techniques targeting enterprise authentication, how each one works in practice and why the solution is not better training.
Pretexting is the construction of a false scenario to extract information or access.
An attacker researches the target before making contact. They learn the name of the IT manager, the ticketing system the company uses, the date of the last software rollout. The more specific the pretext, the more convincing the request.
A common enterprise scenario: the attacker calls an employee posing as IT support conducting a routine system update. The call sounds expected, the detail is credible and the request is small. Could you just confirm your login so we can verify the account is set up correctly? The victim complies because there is no obvious red flag to catch.
Pretexting works because it does not ask people to do something suspicious. It asks them to do something routine.
Vishing is voice phishing. The attacker calls rather than emails, and uses the immediacy of a live conversation to bypass the caution a written message might trigger.
Several factors work in the attacker’s favour simultaneously. A live voice creates social pressure that an email does not. Urgency is easier to convey and harder to verify in real time. Caller ID can be spoofed to display a trusted number. The victim has seconds to decide whether the request is legitimate, not minutes.
In MFA bypass scenarios, the attacker already has the victim’s username and password from an earlier breach or phishing campaign. The vishing call’s only purpose is to obtain the OTP or MFA approval that the attacker’s login attempt has already triggered.
The help desk is designed to be helpful. That is what makes it the most reliable target in enterprise social engineering.
An attacker who calls the help desk does not need the victim’s cooperation. They need to convince IT support that they are the victim. If the identity verification process relies on information available through public sources or earlier reconnaissance, the impersonation succeeds.
Once a help desk agent resets an account or issues a new credential, the attacker’s access is legitimate. It is not a stolen session. Not a relay. The new credential is genuinely theirs.
This is why strong primary authentication is not enough on its own. The recovery path around it determines the real security floor.
The Allianz Life breach followed one of two paths. Either an employee was convinced to hand over an MFA credential directly, or an attacker successfully impersonated that employee to a help desk agent and had a password reset issued.
Either way, the technical authentication controls in place were bypassed entirely. Not cracked. Not exploited. Walked around through a conversation.
The breach is not unusual. It is representative. Social engineering has become the dominant initial access method for enterprise breaches because it is cheaper, faster and more reliable than finding a software vulnerability.
Training employees to spot social engineering improves awareness but does not eliminate the risk. Research consistently shows that even trained users approve requests they should not under the right conditions. Urgency, authority and familiarity are powerful levers. Attackers use all three simultaneously.
The structural problem is that any authentication system where a human can be convinced to approve access on behalf of an attacker is not phishing-resistant. Push notifications can be approved under social pressure. Codes can be shared. Help desk resets can be social-engineered.
Removing the human decision point from authentication is the only reliable answer. An authenticator that requires a live biometric match and generates a credential bound to a specific domain produces nothing that can be transferred, approved or handed over.
There is no code to share, no push to approve and no password reset that grants entry.
Another day. Another preventable breach. This time it’s a major UK based insurance company, Allianz Life, and the attackers didn’t need zero-day exploits or complex malware. They just talked their way in.
According to BBC reporting, the compromise happened through classic social engineering. The attackers either convinced an employee to hand over a multi-factor authentication credential or successfully impersonated that employee to reset a password through the help desk.
This is not new. It’s happening everywhere. And the problem is simple. Most authentication still relies on human fallibility. If someone can convince a person to click approve, or trick IT support into resetting a password, they are in. Game over.
This is exactly why most forms of MFA and authenticator apps are failing. They were never designed to stand up to a clever voice, a spoofed email, a relay attack or a little pressure from someone who sounds legitimate.
Now for the part that matters most.
None of this works if you are using TokenCore™ Wearable or TokenCore™ Portable.
No device. No login. No compromise.
These are physical biometric authenticators that require the user to be present. The authentication is cryptographic and bound to the actual website domain. Even if a hacker knows every password, they cannot log in without your unique Token and your fingerprint.
The breach discussed in the BBC article is just one more in a long list. From healthcare to retail to defense, attackers are bypassing the front door by simply asking to be let in. Legacy MFA lets them. Token does not.
The security industry is spending millions on detection and response. That is important, but let’s be honest. It is a second line of defense. The first line is authentication. If you get that wrong, everything else becomes harder, slower, and more expensive.
If you want to stop breaches like this, you do not need more alerts. You need certainty. You need identity that cannot be faked, phished, or manipulated.
That is what Token provides.
It is time to stop pretending that legacy MFA is enough. It is not. The attackers know it. The victims know it. Now it is time the rest of us admit it and act.
No Token. No entry. That is how we win.