How Should My Employees Verify Someone's Identity Before an MFA Reset?

The Quick Answer

 A voice on the phone is not proof of identity anymore. Inexpensive tools can now clone a convincing one from a short clip of someone talking. If your employees, from the shop floor to the top floor, still trust a caller because they sound right, that instinct is exposed. Every identity change, in either direction, needs to be verified on a channel the caller cannot control, not settled inside the call itself.

Here's how we see this happening in the real world:
It is 9:40 on a Tuesday night and second shift is running.

A machine operator steps away from his cell to take a call on his personal phone. The caller ID shows the company help desk. The voice is calm, a little rushed, and says his multi-factor authentication expires at midnight. If he does not re-enroll now, he will not get into the terminal at start of shift.

He has worked here four years. He has never met anyone from IT.

He has no company laptop and no company phone. He signs into a shared terminal at the end of the line, and the only place an authentication prompt has ever appeared is the phone in his pocket. So a call about that phone, from that number, does not feel strange.

The caller texts him a link. The page looks like the sign-in page he sees every morning. He enters his password and approves the prompt that follows.

The call takes six minutes. He tells no one, because as far as he can tell, nothing went wrong.

You find out Thursday, when a vendor calls asking why the remit-to information on their invoice changed.

MFA closed the door. That was the assumption.

Most of us have carried the same quiet belief for years.

Multi-factor authentication was the hard project. A year of change management, a dozen exceptions for the plant floor, at least one production escalation. When it was finally on, account takeover moved off the top of the list.

The assumption underneath that: an attacker who does not have the second factor cannot get in. Everything downstream of identity, from email to the enterprise resource planning (ERP) system to the file shares, sits on that one sentence.

It held because it was true, and because it worked better than almost anything else we bought that decade.

  • Password spraying stopped working. Reused credentials from someone's old breach stopped working.
  • The attacks that remained were noisy and generated alerts your team could act on.
  • Auditors and insurers accepted it as a real control, which made it easy to fund.

That is a genuine win, and it should be said plainly. MFA did the job it was bought to do.

It is also why it became useful to somebody else.

The enrollment became the target, not the factor.

Attackers stopped trying to defeat the factor. They started trying to be the person who sets it up.

On August 6, 2026, Google's Threat Intelligence Group (GTIG) published an update on UNC6671, a group that has run under several extortion brands this year. The tradecraft has stayed consistent across all of them.

  • Callers pose as IT help desk staff carrying out a mandatory, urgent security migration.
  • They reach employees on personal mobile numbers, outside every control your team manages. In recent cases they have spoofed the real help desk number.
  • The pretext is enabling passkeys or updating MFA enrollment. The security upgrade is the story.
  • The link goes to a lookalike enrollment page, where adversary-in-the-middle infrastructure captures the password and the authentication token in real time and establishes a session that persists.

Read that list again with your own rollout in mind. The domains registered for these campaigns are named things like registerpasskey and passkeyhelpdesk. They are named after the project on your roadmap.

This is also not a financial-sector problem that will stay there. Between April and May of this year, that same infrastructure was aimed at manufacturing, real estate, healthcare, and insurance, before shifting to technology and then to private equity and law firms by July.

Manufacturing was not spared. Manufacturing was first.

The early-August wave that hit Citadel, Point72, Millennium, and Two Sigma on the same day is the same playbook. Those firms have dedicated security teams and full-time identity staff, and Two Sigma said it stopped the attempt.

The point is not that they were unprepared. It is that the preparation had to live in the workflow, because it could not happen on the call.

The same call runs in both directions.

The scenario above is outbound: someone calls your people pretending to be your help desk.

The inbound version is older and just as effective: someone calls your help desk pretending to be your people.

  • The attacker builds a profile from LinkedIn, the company directory, and whatever HR data has leaked, then calls and asks for a password reset or a new MFA device.
  • The agent taking that call is measured on resolution time. Being helpful quickly is the job.
  • When Marks and Spencer's chairman testified to Parliament about how that breach began, he described sophisticated impersonation of an employee and a password reset that went through a third party. Not a vulnerability. A conversation.

If your help desk is co-managed, outsourced, or shared with a parent company, both directions are in play and neither one is fully yours.

The help desk is not a support function anymore. It is an access control.

Here's what it costs when it lands in a plant.

A valid session in your tenant does not look like an intrusion. It looks like an employee working late.

  • The purchasing mailbox gets read. Vendor banking details change on the next invoice, and nobody questions it because the request came from inside.
  • Drawings, quality records, and customer specifications get pulled out of SharePoint by script. In the access logs that reads as normal activity unless someone is watching volume.
  • Applications outside single sign-on go next, taken over through password resets run from the compromised mailbox.
  • Then the confirmations get deleted. GTIG documented these operators systematically removing password-reset emails, security notifications, and the alerts generated when MFA settings change.

That last one deserves a beat. The alert you built the process around is the thing they delete first.

So the honest cost is not the six minutes on the phone. It is the three weeks between the call and the day a vendor or a bank tells you something is wrong, with the record you would use to reconstruct it cleaned up on the way out.

Then comes the part nobody scopes for. The customer who wants a written explanation before releasing the next purchase order (PO). The carrier who wants to know what your identity verification procedure said on the day of the call.

The voice is not the credential.

Here is the thing we never wrote down, because it never needed writing down.

For decades, a voice was good enough. If the caller sounded like your controller, knew the plant manager's name, and used the right words for the right systems, that was treated as proof. It was never proof. It was just expensive to fake.

It is not expensive anymore. Cheap, widely available tools clone a usable voice from a short clip of someone talking, and the accent and phrasing that used to give a foreign caller away are gone. Training people to listen harder is training them to rely on a signal that no longer carries information.

The voice is not the credential.

Which means identity changes cannot be settled inside a conversation. They have to be settled where the caller has no control:

  • Verification on a channel the caller did not choose and cannot intercept.
  • A record that exists independently of anyone's memory of the call.
  • Authentication bound to a device and a domain, so a convincing lookalike page has nothing to capture.

None of that asks your machine operator to become suspicious. That is the point. He should not have to be the control.

How InsITe approaches it

When we build identity workflows for a manufacturer, three rules do most of the work.

  1. No MFA change, passkey enrollment, or password reset is ever completed on a call the company did not initiate.

  2. Verification happens through a callback to a number published in the directory, never a number the caller supplies.

  3. When the helpdesk is contacted, every identity change opens a ticket, so the record exists whether or not anyone remembers the conversation.

Second shift is where this gets tested, because that is where the help desk is thinnest and the people are furthest from anyone they have met.

MFA is not broken. It stopped being the last word on identity the moment attackers realized the process for setting it up was easier to reach than the technology itself.

The voice is not the credential. It never was. It was just hard enough to fake that we let it stand in for one.

Two questions worth sitting with this week.

  • If someone called your second shift tonight and said MFA was expiring, what in your process would stop it? Not what a well-trained person would do. What the process would do.

  • Who at your company can change the way a person proves who they are? Write down every name. If that list is longer than you expected, or if it includes someone who does not work for you, that is the finding.

ABOUT INSITE BUSINESS SOLUTIONS:

Most West Michigan manufacturers know they need to connect their shop floor systems with their business systems. But figuring out how to bridge that gap is like playing vendor roulette. They often end up picking either an IT shop or an automation house, or a combination of both. 

InsITe has IT and OT engineers on staff. One call, one team, one point of accountability across the full tech stack. Before we recommend anything, we walk your shop floor and then design the solution, execute the implementation, and own the outcome through managed services, security, and ongoing support. 

If you're looking for IT or OT help from people who understand the ins and outs of manufacturing, we can help. 

Talk to an Advisor Today →

Back to Blog