Social engineering has moved beyond email. Defenders need controls for SMS, voice calls, QR codes, push fatigue, executive impersonation, and help-desk reset abuse.

- Treat account recovery and help-desk resets as high-risk security workflows.
- Cover SMS, voice, QR, push fatigue, chat messages, and executive impersonation in reporting paths.
- Use phishing-resistant MFA and stronger reset verification for privileged, finance, and executive users.
Social engineering is no longer just email
Email phishing still matters, but attackers increasingly use SMS, voice calls, QR codes, chat messages, fake support workflows, and help-desk pressure. The goal is usually the same: get a user to approve access, reveal a code, install a tool, or persuade support to reset an account.
The defense needs to cover the whole recovery and approval path, not only the inbox.
Treat account recovery as a high-risk workflow
Many strong authentication programs fail at recovery. If an attacker can call support, claim a lost phone, answer weak verification questions, and reset MFA, the primary factor does not help much.
Help-desk reset procedures should include:
- strong identity verification
- manager or secondary approval for high-risk users
- no reset based only on caller ID or personal details
- ticket evidence for every reset
- extra controls for executives, finance, administrators, and help-desk staff
- post-reset notification to the user and manager
The reset path should be harder to abuse than the login path.
Reduce push and approval fatigue
Users should not be trained to approve prompts they did not initiate. Number matching, phishing-resistant MFA, device trust, and risk-based policies help reduce blind approvals.
For privileged users, finance teams, executives, and help-desk staff, use stronger authentication where possible:
- FIDO2 security keys
- passkeys with controlled recovery
- certificate-based authentication
- privileged access workstations
- separate administrator accounts
SMS and voice codes may still appear in some workflows, but they should not be the preferred control for high-risk access.
Prepare for QR and mobile-first attacks
QR phishing can move the user from a monitored email environment to a personal mobile browser. SMS and chat messages can do the same.
Controls should include:
- awareness examples that include QR, SMS, and voice
- reporting paths from mobile devices
- browser and DNS protection where possible
- blocked or warned access to known phishing domains
- conditional access policies for risky locations and devices
- logging that ties mobile sign-ins back to the user and device
Do not assume the security stack sees the attack just because the first message arrived in corporate email.
Give executives a separate plan
Executives are common targets because they have authority, urgency, public context, and access to sensitive decisions. Their assistants, finance contacts, and IT support paths may also be targeted.
Executive protection should cover:
- travel procedures
- payment and wire verification
- account reset rules
- secure contact paths during incidents
- personal device risk
- suspicious call escalation
This does not need to be theatrical. It needs to be practiced.
Measure the controls that matter
Track more than training completion. Track reset volume, reset exceptions, failed social engineering reports, unrecognized MFA prompts, QR reports, SMS reports, and time from report to containment.
Social engineering defense improves when the organization can see where people are being pressured and which process attackers are trying to exploit.

Identity work should show how far one compromised user, admin, or recovery workflow can move.

MFA quality depends on phishing resistance and the recovery path around the factor.

Access reviews need owners for joiner, mover, leaver, privilege, and exception cleanup.
How to use this social engineering guidance
SMS phishing, voice phishing, QR phishing, push fatigue, help-desk account recovery, executive impersonation, and high-risk payment workflows.
The organization can review MFA methods, reset workflows, help-desk procedures, phishing reports, and high-risk user groups.
Get specialist help when attackers target executives, finance, help desk, privileged users, or account recovery workflows.
- MFA prompts, factor resets, help-desk tickets, suspicious SMS or voice reports, and risky sign-ins.
- Recovery procedures, executive verification paths, finance approval workflows, and support exceptions.
- Conditional access results, new device enrollments, session revocations, and mobile reporting paths.
DefendArm Recovery Abuse Review
Evaluate whether attackers can bypass strong login controls by pressuring users or support teams through recovery and approval workflows.
- Prompt: identify where users are asked to approve access or reveal codes.
- Recover: test how MFA and passwords can be reset.
- Verify: strengthen support and payment verification for high-risk users.
- Detect: monitor reset abuse, suspicious prompts, and mobile-first reports.
- Practice: rehearse executive, finance, and help-desk escalation paths.
- Questions to ask ITWhich systems, identities, data paths, and owners are involved, and where would an attacker or mistake create business impact?
- Signals to verifyConfirm access changes, policy exceptions, logging coverage, risky events, and any gaps that would slow investigation.
- Artifacts to produceCreate a short control map with owner, evidence, exception, review date, and the decision needed from leadership.
- Owner to assignAssign one technical owner, one business owner, and one person accountable for evidence and follow-up.
- Training only for email while attacks move to SMS, voice, QR, and chat.
- Deploying MFA without hardening reset and recovery workflows.
- Letting caller ID, personal details, or urgency drive help-desk decisions.
- Failing to give mobile users an easy way to report suspicious messages.
Use these references for the article's social engineering guidance on phishing-resistant authentication, reset abuse, mobile reporting, and help-desk verification.
Turn this identity guidance into a review of MFA strength, privileged access, lifecycle controls, and audit visibility.