Plain definitions for the words that come up when attackers target the help desk. Each entry explains the term and why it matters to account takeover.
- Account takeover (ATO)
- An attacker gains control of a legitimate user's account and uses it for fraud or to reach deeper systems. The entry point is often a stolen password, a social-engineering call to a help desk, or a SIM swap that intercepts one-time codes.
- Social engineering
- Manipulating a person into breaking a security procedure. A common form targets the IT help desk: the caller poses as an employee or customer and talks an agent into resetting a password or changing account access.
- SIM swap (port-out fraud)
- An attacker moves a victim's phone number to a SIM card they control by deceiving or bribing a mobile carrier. Calls and text codes then reach the attacker, which defeats any check that trusts the phone number.
- Deepfake attack
- Use of AI-generated audio or video to impersonate a real person. On a support call it can be a cloned voice. On a video check it can be a synthetic face. Both can fool a human agent and pass a liveness test.
- Identity impersonation detection (IID)
- Confirming that a person is who they claim to be while catching forged, synthetic, or deepfaked identities. Trusona uses the term for verification against authoritative sources such as a state DMV, rather than a selfie or liveness check.
- Man-in-the-middle (MITM)
- An attacker relays or alters traffic between two parties without their knowledge. In account fraud, a real-time proxy sits between the victim and a login or verification page and captures passwords and one-time codes as the victim enters them.
- Knowledge-based authentication (KBA)
- Verifying identity with facts such as a date of birth or the last four digits of a Social Security number. Breaches have exposed most of these answers, so an attacker can often look them up before the call.
- Vishing (voice phishing)
- Phishing carried out over a phone call. Attackers call employees or help desks, build a believable pretext, and press for credentials, one-time codes, or an account reset.
- Liveness detection
- A check meant to prove a real, present person during identity verification, often a selfie with movement. Generative AI and injection attacks now pass many liveness systems with synthetic faces.
- Multi-factor authentication (MFA)
- Requiring two or more factors to sign in, such as a password plus a code or a passkey. MFA protects the login, but it cannot confirm who is on a help-desk call asking to reset that MFA.