AI Is Making Service Desk Attacks Scarier — Here’s How to Fight Back

IBM’s 2025 Cost of a Data Breach Report found that 16% of studied breaches involved attackers using AI tools, mostly for phishing or deepfake impersonation. For security teams, the service desk is ground zero.

Why? Because an attacker who convinces a service desk agent they’re a legitimate user doesn’t need to break technical controls. They just ask for help getting around them. AI makes that easier.

Three ways AI is powering these attacks:

1. Better impersonation. Generative AI lets attackers create polished emails, convincing chat messages, and realistic call scripts in seconds. In targeted attacks, they can even use AI-generated voice or video to impersonate employees. The M&S, MGM Resorts, and Clorox breaches all started with a simple question to the service desk: “Can you help me get access?”

Onboarding is especially vulnerable. New employees aren’t yet known to IT. First-day access issues are routine. An attacker posing as a new hire can sound credible, reference the right department, and create enough urgency to push a request through.

2. Faster reconnaissance. More personal info is publicly available than ever. Job ads name the systems a company uses, LinkedIn shows team structures, welcome posts name new employees. Attackers scrape all of this with AI, then turn those details into believable scripts. Names, roles, departments — it all makes a malicious request look routine.

3. Scale. Attackers don’t need to build campaigns from scratch anymore. AI generates dozens of phishing variations, tests different pretexts, and adapts on the fly. They can hit the same request across multiple channels or agents until someone approves the reset.

How to prevent it: Don’t rely on agents making perfect judgment calls under pressure. Use secure enrollment links instead of sending passwords via email or SMS. Deploy biometric liveness detection to confirm a real person is present during verification — not a recording or deepfake. And enforce strong identity verification before any sensitive action like a password reset for privileged accounts.