Identity Impersonation Detection White Paper Read Now

The numbers

The state of help desk identity attacks

Last updated July 2026

Attackers have shifted from breaking in to signing in, and the help desk is where they get the credentials. These figures track help-desk social engineering, deepfakes, and account takeover. Each one links to its source.

01

The help desk is the front door

$100M+
Knocked off MGM Resorts' quarterly results in 2023 after attackers reset an employee's access through a call to its IT help desk.
MGM Resorts, Q3 2023 Form 10-Q SEC Verify
£300M
Marks & Spencer's estimated hit to 2025/26 operating profit. Reporting traced the breach to social engineering of a third-party IT service desk.
M&S results, via CNBC, May 2025 Verify
+442%
Rise in vishing (voice phishing) from the first to the second half of 2024, the tactic used to talk help desks into password and MFA resets.
"Reset passwords, disable MFA"
What CISA says attackers do by impersonating IT help desk staff. The advisory calls for stronger identity verification at the desk.
CISA advisory AA23-320A, updated 2025
02

Deepfakes beat what agents can see and hear

$25.6M
Stolen from engineering firm Arup after an employee joined a video call with a deepfaked chief financial officer and colleagues.
via CNN, May 2024
30%
Of enterprises will stop trusting identity verification and authentication in isolation by 2026, Gartner predicts, because AI deepfakes defeat it. Biometric injection attacks rose 200% in 2023.
Gartner press release, Feb 2024 Verify
1 in 6
Breaches in 2025 that involved attackers using AI. Of those, 35% used deepfake impersonation and 37% used AI-generated phishing.
$40B
Deloitte's projection for US generative-AI fraud losses by 2027, up from $12.3B in 2023. A projection, not a measured loss.
Deloitte Center for Financial Services, 2024
03

Identity is the attack surface

79%
Of initial-access intrusions in 2024 used no malware. Attackers signed in with stolen identity instead of breaking in.
62%
Of breaches involved a human element such as social engineering or error. Social engineering appeared in 16% of breaches.
Verizon 2026 DBIR Verify
$4.8M
Average cost of a breach that started with phishing, the most common entry vector in 2025 at 16%. The global average breach reached $4.44M.
$20.9B
Reported cybercrime losses in the US in 2025, including $3.04B from business email compromise.
Figures cite the most recent report editions available as of July 2026. The "Verify" tag marks a figure drawn from a primary document that blocks automated reading; confirm it against the linked source before reuse. See how Trusona verifies identity at the IT help desk.
Trusona
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.