IT support and service desk teams sit on the front line of a growing type of cybercrime. This is one that doesn’t rely on technical hacking to get through firewalls or exploiting vulnerabilities in software. Instead, it targets people. Social engineering has been behind some of the most damaging UK cyberattacks in recent years, and IT support staff are often the specific target. Here’s what social engineering is, why it matters and what IT teams can do to help prevent it.
WHAT IS SOCIAL ENGINEERING?
Social engineering is a technique used by cybercriminals to manipulate people into handing over information or access, rather than trying to hack their way in through technical means. This can include tricking someone into sharing personal information such as passwords and login credentials, or financial details like bank account information, that criminals can then exploit.
Attackers may try to get this information directly, by persuading someone to share it themselves, or indirectly, by getting them to download malicious software or visit a fraudulent website. In every case, the target is human trust and behaviour rather than a system weakness.
WHY DOES THIS MATTER TO IT SUPPORT TEAMS?
According to Verizon’s 2026 Data Breach Investigations Report, the human element was present in 62% of breaches, and social engineering was the third most common breach pattern, accounting for 16% of all breaches. Phone-based social engineering is a particular concern, with the report finding that mobile-centric vectors such as voice and text messaging saw success rates around 40% higher than email.
IT helpdesks are an attractive target because they are set up to help people quickly, often verifying identity and resetting access under time pressure. This makes them a common route into an organisation’s wider network.
This isn’t a hypothetical risk for UK organisations. In April 2025, Marks & Spencer and the Co-op were both hit by major cyberattacks. In both cases, attackers used social engineering rather than technical hacking to gain their initial access. At the Business and Trade Sub-Committee’s oral evidence session in July 2025, M&S chairman Archie Norman described the breach as stemming from what is now commonly called social engineering, which he called “a euphemism for impersonation”. The Co-op’s Chief Digital Information Officer, Rob Elsey, said attackers were able to impersonate a colleague and answer security questions to get an account reset. The Cyber Monitoring Centre, which classified the two incidents as a single systemic cyber event, noted that the initial access vector in both cases likely involved compromised credentials and the abuse of IT helpdesk processes, with the combined financial impact estimated at between £270 million and £440 million. The National Cyber Security Centre (NCSC) subsequently issued guidance urging organisations to review their helpdesk password reset processes, particularly for accounts with administrator-level access.
WHAT ARE THE RISKS OF SOCIAL ENGINEERING?
If an attacker succeeds in a social engineering attempt, the consequences can be severe. Risks include:
- Identity theft, where personal information is used to impersonate someone else
- Financial fraud, including credit card fraud or unauthorised transactions
- Ransomware and wider cyberattacks, where initial access is used to install malicious software and target an organisation’s broader network
- Extortion, where attackers threaten to release stolen data unless a payment is made
- Data theft, including the loss of sensitive customer or company information
As seen in the M&S and Co-op incidents, what starts as a single deceptive phone call or message can escalate into weeks of operational disruption and significant financial cost.
WHAT DO IT SUPPORT TEAMS NEED TO KNOW?
Cybercriminals frequently target IT helpdesks directly, posing as a genuine user in order to gain access to passwords or login credentials. They often come prepared with believable stories designed to pressure staff into deactivating multi-factor authentication (MFA) or resetting an account without following full verification steps.
Voice phishing, or “vishing”, has also become more common, and the rise of AI tools means attackers can now convincingly impersonate senior members of staff over the phone, making these calls harder to spot as fraudulent.
HOW CAN IT SUPPORT HELP PREVENT SOCIAL ENGINEERING ATTACKS?
There are several practical steps IT support teams can take to reduce the risk of falling victim to social engineering:
- Monitor logs for unusual activity, such as unexpected password resets or MFA deactivations, especially on accounts with administrator privileges or logins from new or unrecognised locations.
- Set up alerts in security platforms for suspicious activity, such as a new IP address or an unfamiliar device, so teams can respond quickly.
- Review and stick to identity verification processes, particularly when a request involves a temporary password, an MFA deactivation, or a caller wanting to use a personal email address or unverified phone number.
- Be alert to urgency and pressure. A common tactic involves a plausible, high-pressure scenario, such as someone claiming to be locked out just before an important client meeting. Callers may sound stressed, angry or frustrated in an attempt to rush staff into skipping normal checks.
Consistent, well-followed verification processes, even when a request feels urgent or the caller seems senior, remain one of the most effective defences against social engineering.
BUILDING STRONGER CYBERSECURITY AWARENESS
Social engineering shows that strong cybersecurity isn’t only about technical systems, it’s also about people, processes and vigilance. For IT support teams, understanding these tactics and knowing how to respond is an increasingly essential part of the role.
Want to build a career equipped to tackle threats like these? Explore Baltic’s cybersecurity apprenticeships and find out how structured, expert-led training can help you or your team develop the skills to keep organisations secure.