Highlights
Understand Incode’s approach to age assurance Accept US mobile driver's licenses from every wallet 3 years in a row named a Leader First to achieve iBeta Level 3 on iOS and Android Introducing GovFaceMatch
01/05
01/05
Back to webinars

Webinars

Attackers don’t break in, they call in

Social engineering moves faster than traditional help desk checks can keep up. By verifying callers with a live selfie, government-issued ID, and company directory data, organizations can stop impersonation attacks before a password or MFA reset gives fraudsters access.

On demand · September 29, 2026

A growing number of attacks start with a phone call. An attacker calls the IT help desk, pretends to be an employee who is locked out, and asks for a password or multifactor authentication (MFA) reset.

A successful call can be very costly. In 2023, attackers got through MGM Resorts' help desk and caused a shutdown that lasted several days and cost more than $100 million. That same year, 27 of Retool's customers were compromised.

The weakness behind these attacks is the same across industries. Attackers find names, job titles, and reporting lines on LinkedIn and other social media. They use AI to clone voices. Then they add urgency to push agents, who are measured on speed and empathy, into skipping steps.

A central theme of Incode's webinar Attackers don't break in, they call in was that most caller checks rely on information or devices an attacker can get or fake. Security questions, callback numbers, push notifications, and an agent's judgment all fall into this group.

So how can IT and security teams confirm who is really calling without slowing down the help desk? The session covered exactly that and included a live demo of the Incode integration for ServiceNow.

Key takeaways

  • The help desk is a prime target for social engineering. Attackers combine public profile data, AI voice cloning, and pressure to get past agents trained to be helpful.
  • Knowledge-based checks no longer work. One customer found that employee ID numbers and org charts were visible to anyone in Slack. Answers like a first pet's name are easy to find online, and callback numbers are easy to spoof. Employees also approve push notifications just to make them stop.
  • Manager approval is secure but doesn't scale. Getting the employee and their manager on a video call takes three people's time, and it breaks down when the manager is out.
  • Verify the person, not the phone or inbox. The agent sends a secure link straight from the ServiceNow ticket. The caller takes a selfie and scans their ID. Deepsight analyzes the video frame by frame to detect deepfakes, and the legal name on the ID is matched against the company's identity provider, such as Okta or Microsoft Entra ID. Results appear in the ticket in real time. A full check takes less than 60 seconds, and a repeat face check takes about 10 seconds.
  • Self-service recovery takes calls off the help desk. With integrations for Okta, Microsoft Entra ID, Active Directory, and Ping Identity, employees can reset their own passwords or MFA by verifying their identity. This approach deflects more than 60% of help desk calls.

Watch this webinar on demand

Tell us who you are and we'll share the full recording.