ClickCerts
Back to all posts

They Didn’t Hack In. They Called the Help Desk.

August 6, 2026ClickCerts Team
They Didn’t Hack In. They Called the Help Desk.

Why your fastest-growing security gap might be the person who answers the phone — and what the Marks & Spencer attack should teach every company under 500 people.

In April 2025, attackers walked into one of Britain’s largest retailers without a single piece of malware. They didn’t find a zero-day. They didn’t send a phishing email. They picked up the phone, called the IT help desk, impersonated an employee, and talked support into resetting a password.

That was enough. With working credentials in hand, the group known as Scattered Spider moved through Marks & Spencer’s network and deployed ransomware. Online orders were frozen for roughly six weeks, and the UK’s Cyber Monitoring Centre estimated the total financial impact at £270 million to £440 million. The same crew hit Co-op and went after Harrods in the same stretch. M&S’s own chairman later told a parliamentary committee the breach came through a sophisticated social-engineering attack involving a third party — not a technical failure.

No firewall stopped it, because no firewall was ever attacked. A person was.

This isn’t new, and it isn’t only retail

The help-desk call is becoming the entry point of choice. The same group ran the same playbook against MGM Resorts and Caesars in 2023. A phone call to support, an impersonated employee, multi-factor authentication talked around rather than broken. MGM’s cleanup ran into the tens of millions. Google’s threat researchers later warned the crew had moved on to U.S. retailers and insurance companies using the same approach.

The throughline never changes. Attackers go after the people who can grant access — the help desk, the front desk, a new hire, anyone who can reset a credential or wave a request through. Manipulating a person is faster, cheaper, and more reliable than defeating a security stack.

Why your company is the easy version of this target

If you’re under 500 people, you are not too small for this — you’re the convenient version of it. You probably don’t have a 24/7 security operations center. Your “help desk” might be one or two overworked IT employees or an outsourced provider (MSP). And your culture is almost certainly built on being helpful and moving fast. Attackers count on every one of those things. They don’t need M&S-scale effort to work at a company your size; they need one friendly, unprepared person and a plausible story.

Your training was probably built for the wrong attack

Most security awareness training is built around the inbox: don’t click the link, check the sender, hover before you tap. That’s still worth teaching — but the inbox is only one door, and the phone is standing wide open. A growing share of the worst breaches now starts with a voice: a fake IT call, a help-desk impersonation, a “quick” password reset, and increasingly an AI-cloned voice that sounds exactly like your CFO or your IT lead. If your training never mentions the phone, your people are walking into the most effective attack of 2026 with no preparation at all.

What a trained team actually does differently

The fix isn’t complicated, but it has to be taught and reinforced. A prepared team knows that a caller’s number proves nothing, that caller ID is trivially spoofed, and that the right response to any request to reset a credential or grant access is to verify the person through a separate, known channel first — a callback to a number on file, a confirmation in a system the caller doesn’t control. They know that real IT will never ask them to read back a one-time code, approve an unexpected prompt, or share a password, and that urgency and authority in a request are the manipulation, not a reason to comply. Most importantly, they know it’s safe to slow down. The employee who says “let me verify that and call you back” is doing their job well, not being difficult.

The honest part

Training reduces the odds. It does not eliminate them. People are people, and a good enough attacker on a bad enough day can still fool a well-trained employee. That’s exactly why awareness training is one layer and not the whole wall — it pairs with process: verification protocols, multi-factor authentication, least-privilege access. What training does is make your people meaningfully harder to manipulate and far more likely to report something the moment it feels wrong. It is not a force field, and anyone selling it as one is overselling.

Where ClickCerts fits

ClickCerts delivers quarterly, certificate-based training that covers social engineering as it actually happens now — including phone-based and help-desk impersonation and AI-voice fraud — refreshed as the tactics change rather than frozen at whatever was true three years ago. Every employee who completes a course gets a serial-numbered certificate with a public verification page, so when an auditor or your cyber-insurance carrier asks whether your people were actually trained, you can prove it in a click. It’s $18 per user per year for small teams, dropping to $12 for larger ones, with branded company portals and Microsoft 365 single sign-on included.

To be clear about what it isn’t: ClickCerts is not a help-desk-security tool or an identity-verification product. You’ll still want verification procedures and MFA on the technical side. ClickCerts handles the human-awareness layer — the part that decides whether the person on the phone hands over the keys.

The M&S attackers weren’t geniuses. They were prepared, and they found someone who wasn’t. The fix isn’t a bigger firewall — it’s a team that understands the phone is an attack surface, has been trained recently on what manipulation looks like, and feels safe saying “let me verify and call you back.”

Email sales@clickcerts.com to see how a quarterly training program covers social engineering in practice. Related reading: “Watch for Typos and Bad Grammar. (And Other Phishing Advice That’s Now Wrong.)” for how AI has rewritten these attacks, and “60% of Breaches Start with a Click. Here’s How to Stop Yours.” for the underlying threat data.

Subscribe

Updates that don’t suck.

A short note when we ship something worth knowing about. No spam, no drip campaigns.