How Incode Identity Verification for ServiceNow ITSM eliminates help desk fraud
Most enterprise security teams spend millions hardening their perimeter: firewalls, endpoint detection, zero trust architecture. And yet the most common way attackers get inside is a phone call.
Social engineering attacks targeting IT help desks have become the attack vector of choice for sophisticated threat actors. The reason is simple: your help desk agents are trained to be helpful. They want to solve problems quickly. And when someone calls in distress saying they're locked out and need access restored urgently, the instinct is to help.
Attackers are weaponizing that instinct.
The 2023 MGM Resorts breach, which cost the company roughly $100 million in third-quarter earnings by MGM's own regulatory filing, started with a phone call to the IT help desk that the attackers claimed took just 10 minutes. There was no malware and no zero-day exploit, just an attacker who had looked up an employee on LinkedIn and convinced a help desk agent they were who they said they were.
Any help desk can be targeted this way. The question is whether you have anything in place to stop it.
In this article, I cover how these attacks work and how Incode Identity Verification for ServiceNow ITSM closes the gap with a biometric check inside the ticket.
A new standard for identity assurance at the help desk
Knowledge-based verification ("What's your employee ID? What's your manager's name?") was never secure, but it was the only available option. That's no longer true.
Incode Identity Verification for ServiceNow ITSM brings biometric identity assurance directly into your incident and service request workflow. Agents get a definitive, objective answer to the question "Is this really who they say they are?" in under two minutes without leaving ServiceNow.
Who this is for
This integration was built for IT Service Management leaders and help desk managers at mid-to-large enterprises who:
- Run a ServiceNow ITSM environment for employee IT support
- Handle sensitive requests like password resets, VPN access, device provisioning, or privileged account changes
- Are concerned about social engineering attacks targeting their help desk team
- Need to meet compliance requirements around identity verification for sensitive access requests
- Want to improve security without disrupting agent workflows or frustrating employees
If your team processes more than 50 service requests per day and any of those involve granting access to sensitive systems, this integration was built for you.
How it works
The integration embeds directly into your ServiceNow incident and service request forms. There's no separate application to open, no browser tab to switch to, no manual lookup in another system.
For the agent
- A service request or incident arrives in ServiceNow as usual
- The agent opens the ticket and sees the Incode Identity Verification widget embedded in the form
- They enter the employee's corporate email address, used to match against your IAM directory
- They select a delivery method: SMS for employees who are locked out of corporate systems, email for standard requests
- They click Send verification link
That's it: the agent's job is done. Results typically arrive in less than two minutes.
For the employee
- A link arrives on their phone via SMS or email
- They tap the link and complete a biometric liveness check and a face match against their verified ID on file
- The result posts back to the ServiceNow ticket automatically
For the audit trail
Every verification (pass, fail, or flagged for review) is logged in the ticket with a session ID, identity ID, timestamp, and outcome, so no manual documentation is required.
The business case
The case for biometric verification at the help desk rests on four things: it closes the social engineering gap, satisfies auditors, leaves agent workflows intact, and stays fast for employees.
Security that can't be gamed
Biometric liveness detection defeats every social engineering technique that works against knowledge-based verification. An attacker can research your employee's manager, employee ID, and last four digits of their SSN. They cannot produce a live face that matches your employee's verified biometric on file.
Incode's AI-powered liveness detection is specifically engineered to defeat spoofing attempts, including printed photos, screen replay attacks, and deepfake video.
Built for compliance
For organizations subject to SOC 2, ISO 27001, HIPAA, PCI-DSS, or financial services regulations, auditable identity verification at the help desk is increasingly a hard requirement. Every Incode verification produces a cryptographically signed session record that can be retrieved for forensic review, compliance reporting, or audit response.
Zero workflow disruption
The integration maps to your existing ServiceNow ticket states and assignment groups. There's no workflow engine reconfiguration required. Agents learn the new process in minutes, and most prefer it, because it removes the anxiety of making a judgment call on a suspicious caller.
Employee-friendly by design
Employees complete verification on their personal phone. There is no app to install, no enrollment appointment, and no waiting on hold. The experience is designed to feel like a simple selfie check, because that is essentially what it is.
Key features
Five capabilities do the work, from the biometric check itself to the audit trail it leaves behind:
- Biometric liveness detection and face match: powered by Incode's AI platform, it defeats photos, videos, and deepfakes and returns results in seconds.
- Flexible delivery: send verification links via SMS or email. Agents choose the right channel based on the employee's situation.
- Real-time ticket updates: verification results post to the ServiceNow ticket automatically, with no polling and no refresh required.
- Complete audit trail: session ID, identity ID, employee email, timestamp, and outcome are logged in every ticket, ready for compliance review.
- Authenticated webhooks: verification results are delivered via webhook with shared secret authentication, ensuring only legitimate Incode events can update your tickets.
How it compares
Most help desks already verify identity one of three ways. Here is how each method holds up against biometric verification on security, effort, and auditability:

Getting started
The integration requires an active Incode Workforce account. Contact your Incode account manager or visit incode.com to get started.
Full setup documentation is available at developer.incode.com/docs/servicenow. ServiceNow is just one of many integrations available through the Incode Integrations Marketplace. All integrations are available to review at https://incode.com/integrations/.
Ready to protect your help desk from social engineering, or explore how Incode's deepfake detection goes deeper than a document check? Request a demo.