Beyond MFA: Securing the Identity Lifecycle from Onboarding to Recovery
While multi-factor authentication (MFA) and conditional access have strengthened login security, attackers are increasingly targeting the less fortified points of the identity lifecycle: onboarding and account recovery. Social engineering tactics, often leveraging sophisticated impersonation, are exploiting service desks to gain unauthorized access. This article explores the evolving threats and crucial strategies for bolstering identity verification during these high-risk events.

Security teams have invested significant effort in hardening authentication, making controls like multi-factor authentication (MFA) and conditional access standard practice. While these measures effectively combat traditional credential theft, they don't address every identity-related vulnerability.
Trust is established or re-established at several critical junctures in the identity lifecycle:
* When a new employee joins.
* When an individual loses access to their account.
* When a password or MFA factor requires a reset.
* When the service desk is asked to make a sensitive change to an account.
Rather than attempting to steal credentials or bypass MFA directly, threat actors are increasingly opting to socially engineer service desk personnel, exploiting legitimate processes by impersonating account holders. This strategy places immense pressure on organizations to secure not only the login process but also the procedures surrounding account creation and recovery.
## How Attackers Exploit Identity at Onboarding and Recovery
In late July 2026, the US Department of State, alongside allies including Japan, Canada, and the UK, issued a joint alert warning of North Korean IT workers impersonating foreign nationals to secure employment. Their tactics involve falsifying identity documents, such as using images provided by a third party in another country to register accounts, with the North Korean then performing the actual work.
These workers typically target technology companies, highlighting that while the specific campaign may vary, onboarding always presents a critical moment for establishing initial trust. If identity checks fail at this stage, attackers can gain seemingly legitimate access to an organization's environment.
The same vulnerability arises during the account recovery process. Threat actor groups like **Scattered Spider** are highly skilled in social engineering, impersonating employees and contacting service desks to reset passwords, thereby gaining unauthorized account access. This tactic was linked to the **2025 M&S ransomware breach**, which reportedly contributed to an estimated $400 million hit to the retailer's operating profit due to lost sales.
In these scenarios, the fundamental security question remains: how confidently can an organization verify that the person making the request is indeed who they claim to be?
## Strong Authentication Still Depends on Strong Identity Checks
When a user contacts the service desk claiming a forgotten password or lost authenticator, the agent must be able to confidently verify the caller's identity. However, many organizations still rely on relatively weak signals for identity checks. A service desk might ask for an employee ID or phone number, and security questions about a first pet or school are still common.
The problem is that much of this information can be easily researched, stolen, or manipulated. Attackers can leverage data breaches or social media to find personal details. Even when stronger checks are in place, campaigns like those involving North Korean remote workers demonstrate how identity documents and other evidence can be altered or fabricated.
Furthermore, AI is making impersonation more convincing. Attackers can utilize synthetic profiles, manipulated images, cloned voices, and deepfake video to support false identities or enhance the believability of social engineering attempts. All these factors make it increasingly difficult for agents to act with confidence. As verifying users during onboarding and recovery events is crucial, organizations need more robust measures to ensure accurate verification.
## Strengthen Verification During High-Risk Identity Events
Solutions such as **Specops Verified ID** introduce an additional layer of assurance, enabling service desk agents to confidently confirm identity before sensitive actions are taken. This is achieved by combining government document scanning and validation with biometric liveness detection.
Document checks verify the legitimacy of the presented ID, while liveness detection confirms that a real, present person is completing the process, rather than relying on a static image or replayed evidence. During onboarding, this provides organizations with a stronger method to verify new employees before granting access to corporate systems. This can significantly reduce the risk posed by fraudulent applicants and impersonation attempts, including the tactics observed in North Korean remote worker campaigns.
This same approach can be applied whenever high-assurance verification is necessary, such as for password resets of privileged accounts. Instead of adding complexity to every identity event, **Specops Verified ID** applies stronger verification where the consequences of an error are highest.
## Protect Your Service Desk with Specops
While strong authentication remains essential, attackers will continue to seek alternative routes around the most robust controls. Increasingly, this means targeting the processes used to establish or recover identity, rather than directly attacking the login itself.
Whether an organization is onboarding a new employee or assisting an existing one with account recovery, the core challenge is ensuring that the correct person is granted access. **Specops Verified ID** enhances these high-risk identity events with government ID validation and biometric liveness detection, empowering organizations to make these critical decisions with greater confidence.