A help desk agent takes a call from someone who sounds stressed, locked out ahead of a big meeting. The caller knows the employee's title, their manager, their start date. The agent resets MFA to a new device. Eight minutes later that device is approving logins for an attacker. Years of investment in authentication, bypassed at the one layer that still runs on human judgment.
The help desk is tuned for two things security teams rarely optimize for: speed and empathy. Verification leans on knowledge that is cheap to gather — a name, a badge number, an org chart reconstructed from LinkedIn. Every check that would slow an impostor also slows the forty legitimate lockouts that came in that day. So the checks stay light, and the reset becomes the one privileged action almost anyone can trigger with a convincing story.
What the Impostor Can't Fake
The caller can rehearse the story. What they can't rehearse is what the account does next. A freshly reset identity that enrolls a new device, signs in from an unfamiliar location, and reaches for systems the real employee rarely opens is behaving like someone else wearing the name.
Where the Signal Actually Lives
Abnormal baselines what normal looks like for each identity — the devices, locations, and systems a person actually uses — so the reset that looked routine to the help desk reads as a sharp break from the person's own history. The call was social engineering, a judgment the agent had to make under time pressure. What the account does afterward is a pattern that either matches the real person or doesn't.
The help desk will always answer the phone. The question is whether anything is watching what the reset unlocks.
See the latest from Abnormal's product and engineering teams.

