08/30/2026
Modern cyberattacks are getting harder to spot because attackers no longer need to break into systems directly. Instead, they manipulate normal processes and get people to help without realizing it. Microsoft recently warned about a group using the password‑reset flow in Microsoft accounts to do exactly that.
They start with basic details like an email and phone number, trigger a real password‑reset request, then call pretending to be IT support. The victim sees a genuine authentication prompt while the caller calmly explains they need to approve it. The system is real, the notification is real, and that’s what makes it convincing.
Once approved, attackers reset the password, lock out the real user and access company data. In some cases they downloaded large amounts of shared files from OneDrive. MFA is still one of the best protections, but it only works if people understand what they’re approving. Social engineering now plays a huge role in cybersecurity because people naturally trust someone who sounds professional and helpful.
That’s why businesses need clear processes for password resets, account changes and unexpected authentication requests.
If a real authentication prompt appeared while someone claiming to be support was on the phone, would you feel confident knowing whether it was legitimate?
If your business needs stronger protection against social‑engineering attacks, Myriad Technologies can help.
Book a consultation: [https://zurl.co/Ez19Y](https://zurl.co/Ez19Y)