Legal

Your newest hire is the easiest person to impersonate

Microsoft published research last month on an attack that starts with a phone call to an employee's personal cell.

1 min readOriginally posted on LinkedIn

Microsoft published research last month on an attack that starts with a phone call to an employee's personal cell.

The caller says they're from IT. They need you to finish setting up your sign-in — a passkey, a multifactor prompt, something routine. There's urgency. Do it now or you lose access.

Think about who's most likely to go along with that. Not your fifteen-year veteran. Your new hire on day three, who's already been handed four logins and has no idea yet what normal looks like. Attackers know this. Microsoft's researchers found they pull names and org charts off professional networking profiles first, so they know exactly who just started.

Here's the part that stings: the passkey story is only the setup. What they're actually after is the sign-in session itself. Once they have it, they quietly register their own authentication method — a key to the building that doesn't disappear when you change the password.

For a law firm, that looks like weeks of quiet file access before anyone notices, and a conversation with clients you really don't want to have.

Two fixes that cost nothing. Give every new hire one verified way to reach IT on day one, and tell them plainly that nobody else will ever call them about their login. And require whoever resets a password or an MFA method to prove who they're talking to, every single time.

Worth sorting out before your next cyber renewal.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions