For years, one of the service desk’s defenses against social engineering has been the person answering the phone.
Agents are trained to listen for warning signs that break normal process or a caller who simply doesn’t sound quite right. While that training is still important, it is becoming a dangerous place to put the final identity decision.
AI is changing what a convincing impersonation looks and sounds like, which creates a problem training alone cannot solve. Relying on service desk staff to distinguish genuine employees from increasingly sophisticated impersonations, often while under pressure to resolve an access problem quickly, is an increasingly tougher ask in this threat landscape.
The better question isn’t how to make agents better at spotting a fake. It’s why we are asking them to make that judgement at all.
Vishing has Become an Identity Security Problem
Social engineering at the service desk is hardly a new problem. What has changed is how difficult it now is to tell a convincing attacker from the person they claim to be.
Skilled social engineers have always sounded plausible, able to create urgency while using the right information to support their story. Scattered Spider are well-known for these tactics; the last few years have seen the group launch attacks against multiple major organizations like Marks & Spencer and MGM Resorts, starting with a phone call to the service desk. By impersonating employees, they tricked agents into resetting passwords or transferring multi-factor authentication (MFA) to their own devices, and from there escalated to deploy ransomware and cause widespread disruption.
AI adds another layer of realism to vishing scams because some of the signals agents might instinctively trust can now also be manufactured. The FBI has warned of malicious campaigns using AI-generated voices to impersonate real people, including senior US officials, noting that cloned voices can sound nearly identical to the genuine speaker.
Why Agent Training Reaches a Limit
Service desk agents should know how to spot unusual requests, manufactured urgency, attempts to bypass normal processes, and suspicious reset requests. Training helps an agent ask: does this interaction seem suspicious? Does this person sound legitimate? Does their story make sense?
However, if an attacker can reproduce a colleague’s voice and respond naturally to questions, the agent is being asked to make a security decision based on signals that can increasingly be faked. In effect, that turns service desk staff into human deepfake detectors.
They are expected to assess tone, speech patterns, confidence, context, and personal knowledge, often while trying to resolve an urgent access problem quickly. Even experienced agents can be put in a position where there is no obvious giveaway.
The answer is not to abandon training. It is to stop treating human judgement as the final authentication control.
The Service Desk is Where Strong Authentication Can Weaken
Organizations have spent years strengthening authentication with MFA, passwordless access, conditional access policies, and phishing-resistant credentials. But every authentication system needs a recovery path.
People lose devices and forget passwords. If they buy a new phone, their authenticators might stop working. Eventually, someone has to help them regain access. And if that recovery process is easier to defeat than the authentication controls protecting the account, attackers can undermine much of that investment.
Put simply: your strongest authentication control may ultimately depend on the weakest recovery process behind it.
NIST treats account recovery as a distinct identity security process rather than just another login attempt, which is an important distinction for the service desk. A password or MFA reset can change the credentials or authenticators an organization relies on to establish identity.
So, the security question should not be whether an agent followed the right script. It should be whether the recovery process provides enough assurance that the person asking for access is genuinely entitled to it.
Remove the Judgement Call from Identity Verification
Securing the service desk against AI impersonation means removing judgement calls from the process. Instead of asking an agent to decide whether someone seems genuine, the process should require the user to prove their identity before the action can continue.
In other words, the safest service desk workflow makes verification a prerequisite, not a recommendation.
This is the principle behind solutions like Specops Secure Service Desk. It places identity verification directly in front of unlocking accounts and password reset requests, so an agent cannot proceed until the user has successfully verified their identity. Agents can make use of any combination of more than 15 MFA factors and ensure that any user, whether they have a mobile device or not, can be securely verified.

An agent doesn’t need to work out whether they are hearing a cloned voice or decide whether an employee knows “enough” personal information to be genuine. And an attacker cannot improve their chances simply by gathering more background information before making the call.
The same requirement applies regardless of which agent answers, how busy the service desk is or how convincing the caller appears. Specops Secure Service Desk also exports events to your SIEM or analytics platform, providing a clear audit trail that shows that verification took place before a sensitive action was completed.
Mitigate the Risk of AI Impersonation at the Service Desk
AI will make impersonation attempts more convincing, but that doesn’t mean service desk agents have to become experts at spotting every new deepfake or vishing technique.
By requiring identity verification before agents carry out high-risk requests like password resets, you can remove the judgement call and protect against even highly convincing impersonations.
If you’re reviewing how your service desk handles identity verification and account recovery, Specops can help. Book a demo today to see how our solutions can secure your service desk against the latest threats.
