Service desks around the world are increasingly becoming a target for sophisticated social engineering attacks, thanks in part to the growing use of artificial intelligence (AI) by malicious actors. A recent report found that 16% of data breaches studied involved attackers using AI tools, with phishing and deepfake impersonation attacks being among the most common tactics employed. For organizations, this has significant implications for their security posture, particularly when it comes to onboarding new employees.
The service desk is a natural target for social engineering because it provides a convenient entry point for attackers who can convince agents that they are legitimate users in need of assistance. With AI-powered tools at their disposal, these attackers can create highly convincing emails, chat messages, and even voice or video recordings designed to impersonate real employees. This makes it increasingly difficult for service desk agents to accurately judge whether a request is genuine or not.
One of the key ways that AI aids in these attacks is by making impersonation more convincing. By using generative AI, attackers can create polished and realistic communications in seconds, including emails, chat messages, and even voice recordings. This allows them to pose as new employees or familiar colleagues, making it harder for service desk agents to distinguish between legitimate and malicious requests.
AI also accelerates the reconnaissance and personalization phase of these attacks. Threat actors can use AI to scrape information from public sources such as LinkedIn profiles, company websites, job posts, and social media. This information is then used to create a believable story that sounds convincing even to seasoned service desk agents. By incorporating details about the employee’s role, department, location, and internal tools, attackers can make their requests seem routine and therefore more likely to be approved quickly.
Furthermore, AI enables attackers to scale these types of attacks by creating multiple phishing email variations and testing different pretexts in a matter of seconds. This makes it challenging for service desks to keep up with the sheer volume of malicious requests, especially when attackers use urgency and persistence to make their requests seem like just another routine task.
To prevent AI-enabled service desk attacks, organizations need to adopt specialized solutions that can help secure the onboarding process from start to finish. One such solution is Specops Secure Onboarding, which provides a robust and compliant way to ensure that agents have the tools they need to confidently verify identities and prevent malicious requests from slipping through.
In conclusion, AI-powered service desk attacks are becoming increasingly sophisticated, making it essential for organizations to take proactive steps to protect themselves. By recognizing the tactics used by attackers and adopting specialized solutions to secure the onboarding process, organizations can reduce their risk of falling victim to these types of attacks.
Source: Bleeping Computer — 2026-07-08