**AI-Powered Service Desk Attacks: The Growing Threat**
A recent report from IBM found that a staggering 16% of breaches involve attackers using AI-powered tools, with phishing and deepfake impersonation attacks being the most common. This trend has significant implications for security teams, particularly when it comes to the service desk. As a critical entry point for users seeking assistance, the service desk is an attractive target for social engineering attacks, and AI makes it easier than ever for attackers to sound convincing.
**Why Service Desks are Vulnerable**
The service desk’s primary function is to provide timely support to employees who encounter technical issues or need access to company systems. However, this openness also creates a vulnerability, particularly during the onboarding process. New employees often require rapid access to company resources, but may not yet be familiar to IT teams, making it difficult for agents to verify their identity.
**How AI Aids Service Desk Attacks**
Attackers are now using AI to create sophisticated social engineering campaigns that can convincingly impersonate legitimate users. Here are three ways AI is being used to power service desk attacks:
AI-powered impersonation makes it increasingly difficult for agents to determine whether a request is genuine or not. Attackers can use generative AI to craft polished emails, convincing chat messages, and realistic call scripts in seconds, making them nearly indistinguishable from legitimate requests.
In targeted attacks, attackers can also use AI-generated voice or video to impersonate employees, further blurring the lines between what’s real and what’s not. This creates a high-risk scenario for onboarding, where new employees are often less familiar with company procedures and may be more susceptible to these types of attacks.
AI accelerates reconnaissance by helping attackers gather personal information from public sources like LinkedIn profiles, job adverts, and company websites. This information can then be used to create convincing scripts that sound legitimate, making it harder for agents to verify the authenticity of requests.
Furthermore, AI enables attackers to scale their efforts more efficiently, creating multiple phishing email variations, testing different pretexts, and adapting their wording to tailor their approach. This creates a perfect storm for service desks, which are built to respond quickly but may not have the necessary tools or expertise to detect these sophisticated attacks.
**Securing Your Service Desk**
Preventing AI-enabled service desk attacks requires more than just relying on agents’ judgment calls under pressure. Organizations need specialized solutions that can help secure the onboarding process and provide a robust defense against social engineering attempts.
One such solution is Specops Secure Onboarding, which helps secure onboarding end-to-end and beyond by providing tools for confident identity verification. By taking proactive steps to address this growing threat, organizations can reduce their risk of falling victim to AI-powered service desk attacks.
Source: Bleeping Computer — 2026-07-08