IBM’s 2025 Cost of a Data Breach Report found that 16% of breaches studied involved attackers using AI tools, most often for phishing or deepfake impersonation attacks. For security teams, that has direct implications for the service desk.
The service desk is a natural target for social engineering, as an attacker that convinces an agent they are a legitimate user may not need to bypass technical controls. They can simply ask for help getting around them. AI makes that easier, helping attackers sound more credible by personalizing their approach.
Onboarding is particularly exposed in a threat landscape where AI enables more convincing social engineering attacks.
New employees need fast access, but the organization may not yet have strong familiarity with who they are. Attackers can exploit that gap, so service desk agents need better ways to prove identity before they hand over credentials, reset MFA or approve sensitive changes.
Three ways AI aids service desk attacks









