Your employees are connecting AI to everything. Now what?
ChatGPT and Claude don't just answer questions anymore. Employees are connecting them directly to Notion, Linear, Jira, and the rest of your stack. The AI can read, write, and take actions on company data. Most IT and security teams have no visibility into any of it.
Harmonic Security Connectors changes that. It sits inline with every AI-to-app connection, so you see each call, control what data moves, and block destructive actions before they happen. Employees notice nothing different.
See what's actually running across your business in a live demo.
This is the first issue built specifically for people working IT support right now, especially anyone wondering whether cybersecurity is a realistic next step. Short answer: it is, and you already use part of the skill set today. This issue is about the part you may not realize counts.
In September 2023, a major hospitality company lost an estimated $100 million and ten days of normal operations because of a single help desk phone call. No malware kicked things off. No exploited server. Someone called, sounded like they belonged, and asked for help getting back into their account.
The lesson here is not "help desks are dangerous." It is "the verification step you already do every day is a security control, not just a formality."
Real attack breakdown: the call that got into MGM
In September 2023, the threat actor group tracked as Scattered Spider gained initial access to MGM Resorts' systems, and the entry point was about as low-tech as it gets.
The attackers used LinkedIn to identify a real MGM employee.
They called MGM's IT help desk, impersonating that employee, and asked for help logging into their account.
The call lasted around ten minutes.
By the end of it, the attackers had administrator-level access to MGM's Okta and Azure environments.
From there, the impact spread fast. MGM's systems were disrupted for about ten days: online reservations, digital room keys, slot machines, and public websites were all affected. MGM disclosed the incident in SEC filings and estimated roughly $100 million in impact for the quarter. A data breach notification the following year confirmed that personal information for a large number of customers, including names, contact details, dates of birth, driver's license numbers, and Social Security numbers, had been exposed.
No password was cracked. No zero-day was exploited. A help desk process trusted a caller's claimed identity, and that was enough.
Why this matters right now
This was not a one-off. CISA and the FBI issued a joint advisory on Scattered Spider naming IT help desks specifically as a primary target. The group is described as skilled in social engineering: phishing, vishing, MFA prompt-bombing, and SIM-swapping, frequently starting with a phone call to a help desk, not a technical exploit.
Here is why this issue exists in this newsletter, specifically: the gap that let this happen was not a missing patch. It was a process gap, in a task that IT support handles constantly. Password resets. MFA re-enrollment. "I'm locked out, can you help." These are routine tickets, which is exactly why they are a target. An attacker does not need a vulnerability scanner. They need a convincing story and a busy afternoon.
If you work IT support, you already do identity verification every day, even if you have not thought of it that way. The difference between a routine ticket and a $100 million incident is whether that verification step is a real, non-negotiable process or a formality that a confident enough voice can talk past.
Practical fixes you can apply this week
For help desk and IT support staff
1. Verify identity through a channel the caller does not control. Anything a caller tells you, name, employee ID, department, can be learned from LinkedIn or a company directory. Confirm identity through something separate: a callback to a number already on file, a known manager, or an established verification process.
2. Treat urgency as a normal-sounding request, not proof of legitimacy. "I need this fixed right now" is what a real employee says, and it is also exactly what an attacker says. Urgency does not skip verification. It is a reason to be more deliberate, not less.
3. Know that escalating costs you a few minutes, and skipping verification can cost a lot more. If something feels off, or a request involves resetting MFA or account access, escalate. Nobody gets in trouble for double-checking a password reset. Companies get into serious trouble when nobody does.
For admins and IT managers
4. Write down the verification protocol, and make it non-negotiable. If your identity verification process for password and MFA resets lives only in an employee's memory or "use your judgment," it is not a process. Document a specific, callback-based verification step that applies regardless of how convincing the request sounds.
5. Train your team on this specific pattern. The CISA/FBI advisory on Scattered Spider is free and describes exactly how these calls work. Use it as actual training material, not just a headline.
6. Monitor for the pattern, not just the outcome. Unusual MFA re-enrollment requests, access changes shortly after a password reset, or a spike in help desk contact for the same account are all worth a second look before, not after, something breaks.
This Week in "Please Don't Do That"
Someone, somewhere, is about to reset an account's MFA because the caller "sounded really stressed and just needed to get into a meeting."
Please do not let a stressed voice be your entire verification process. Real employees get locked out constantly, and so do attackers who did their homework on LinkedIn.
If your callback number and your caller ID number are not the same thing, that is not a coincidence you should ignore.
Tool worth knowing: the NIST NICE Framework and Cyber Career Pathways Tool
If this issue has you wondering what a move from IT support into cybersecurity actually looks like, this is where to start.
The NICE Framework, built by NIST, is the standard reference for cybersecurity work roles, and what knowledge and skills each one actually requires. Paired with it, the free Cyber Career Pathways Tool lets you explore specific cybersecurity roles, see how they relate to each other, and get a realistic picture of what skills you already have and what you would need to build.
It will not tell you "get this certification and you are done." What it does is turn "I think I want to do security" into an actual map, so you can see which roles are closest to where you already are.
Checklist tie-in
This issue maps directly to the identity and access verification habits in the SecureByDefault 25-Point Security Checklist. If your organization does not have a documented, callback-based verification step for password and MFA resets, that is worth fixing before anything else in this issue.
One question for you
If someone called your help desk right now, confidently claiming to be a locked-out employee, what would actually stop them from getting in?
Hit reply and tell me. If the honest answer is "the person's voice sounding believable," that is worth fixing this week, not eventually. I read every one.
Talk soon,
Ron
Cloud and Cybersecurity Engineer, SecureByDefault
Sources
MGM Resorts SEC 8-K filings (September and October 2023) · BleepingComputer and SecureWorld reporting on the financial and operational impact, cross-confirmed by Dark Reading, Netwrix, and Cymulate · CISA/FBI joint advisory AA23-320A, "Scattered Spider" · NIST NICE Framework Resource Center; CISA/NICCS Cyber Career Pathways Tool · SecureByDefault 25-Point Security Checklist

