Onboarding and the service desk have become the new identity perimeter This article explores identity scenarios security. . In 2024, the American Hospital Association revealed that cybercriminals had amassed sufficient employee data, including corporate identifiers and partial Social Security numbers, to convincingly impersonate legitimate users.

In July 2026, the US, Japan, and South Korea issued a new alert that North Korean IT specialists are employing advanced techniques, including AI, to mask their identities and facilitate job placements.

Both methods manipulate the decision-making processes used by organizations to grant digital identities: - When targeting the onboarding process, the attacker claims, "I am your new employee; provide me with an identity." - When targeting the service desk, the attacker pretends, "I am already your employee; assist me in obtaining my identity." When targeting the onboarding process, the attacker claims, "I am your new employee; provide me with an identity."

When targeting the service desk, the attacker pretends, "I am already your employee; assist me in obtaining my identity." In both scenarios, the security breach occurs during verification.

Related: Threat Actor Generates 1 Million Personalized Fraud Emails in Just 3 Days Organizations must verify that the person claiming access is indeed the rightful account holder throughout the entire onboarding process, from account creation through service desk support. Specops Secure Onboarding is crafted to safeguard against modern AI-driven impersonation threats.