When ransomware hits the headlines, the story almost always starts in the middle. We read about the eight-figure ransom demand, the casino that went dark, or the airline that grounded flights. We see the dramatic SEC 8-K filings and the carefully worded press releases. The narrative is often one of sudden catastrophe: a digital lightning strike that came out of nowhere.
But ransomware doesn't come out of nowhere. By the time the encryption routine fires, the attacker has often been inside the target environment for weeks or months. And the front door they walked through wasn't a zero-day exploit or a brilliant piece of malware. It was the humble helpdesk, where valid credentials are quietly harvested as the first step in the ransomware chain.
CrowdStrike's 2026 Global Threat Report makes the scale of this shift unambiguous.

82% percent of detections in 2025 were malware-free, up from 51% in 2020. Adversaries are operating through "valid credentials [and] trusted identity flows". In other words, they aren't breaking in. They're logging in. The use of valid stolen credentials is now the dominant mode of intrusion.
The Ransomware Attack Chain: Two Acts, One Tragedy
Most ransomware attacks have two distinct acts, performed by two distinct sets of actors, often separated by months of calendar time.
Act One: The Initial Access Broker (IAB). These specialists do one thing and do it well: they steal valid credentials into corporate networks. They don't deploy ransomware. They simply harvest access and list it for sale on dark web marketplaces.
Act Two: The Ransomware Operator. Weeks or months later, a different group purchases that access from the dark web. This is the crew that quietly logs in, escalates privileges, moves laterally, exfiltrates data, and ultimately deploys the ransomware payload. This is the group that ends up in the news.
Where the IABs Set Up Shop: Your Helpdesk
There are two well-documented techniques that IABs use to target helpdesks, and both should keep CISOs awake at night.
Technique One: The Insider Plant
The Lapsus$ group made the strategy explicit. They posted advertisements on Telegram openly recruiting insiders at call centers and helpdesks within target organizations.

Take a moment to appreciate the elegance of this attack from the adversary's perspective. Helpdesk roles have notoriously high turnover. The hiring bar is generally low. The training period is short. Most importantly, the operational delay between credential theft and ransomware deployment provides perfect cover. An insider can join, quietly harvest credentials over a few weeks and just as quietly resign and move on. They can then list them on a dark web marketplace and monetize in cryptocurrency. By the time the ransomware operator strikes, the insider is two jobs away. The listing is anonymous. The payment is untraceable. The departure looks like ordinary helpdesk attrition.
This is, as a colleague of mine likes to put it, as close to the perfect crime as modern cybercrime gets. The Coinbase attack showed how easy it was to execute, especially with outsourced call centers where the helpdesk pay is even leaner.
Technique Two: Spoofing the Helpdesk Process
The second technique requires just a phone call and a SIM-swap. The attacker calls into the helpdesk, claims to be a user with a new phone, and walks through the standard identity proofing process. Personal information that "should only be known to the user" is purchased on the dark web for a few dollars. The MFA reset link gets sent to the user's phone number. Except the attacker has already SIM-swapped that number through a bribed insider at a wireless carrier.
The MGM Casinos attack used precisely this approach, costing the company over $100 million according to its 8-K filing. More recently, the May 2026 breach of Canvas, which disrupted schools and colleges nationwide, was attributed to threat actors who specialize in exactly this kind of helpdesk spoofing combined with SIM-swap techniques ( KrebsOnSecurity).
The Identity Doom Loop
The conventional response to helpdesk-driven compromise has been to make the helpdesk's identity proofing process more rigorous. Add a video call. Require the user's manager to participate. Demand additional knowledge-based questions. Implement a callback procedure. Each of these adds friction, adds cost, and adds operational drag.
But here's the problem: none of them meaningfully address the underlying vulnerability. All these extra processes won't stop an insider agent from quietly stealing credentials.
This is what I've come to call the identity doom loop: ever-worsening security at ever-increasing costs. Each new control adds operational expense and user friction without changing the fundamental fact: an insider can simply steal credentials and defeat all the added processes.
The Strategic Shift: Remove the Helpdesk from Credential Issuance
Here is the central plank of any serious strategy to fix the insider problem in 2026: the helpdesk must be removed from the credential issuance process.
This isn't about devaluing helpdesk teams or eliminating support functions. It's about acknowledging the reality that giving an agent the ability to issue credentials invites IABs to infiltrate the organization.
The helpdesk sits in the critical path where identity is concerned. Every other control downstream is contingent on the integrity of a phone call. That is a foundation that no amount of MFA, conditional access, or zero-trust architecture can fully redeem.
Vercrio's Identity Fabric: PeerProofing™ and LucidAuth™
Vercrio has re-imagined the identity architecture. It treats identity proofing and daily authentication as what they actually are — a single, continuous fabric rather than two disconnected silos. The Vercrio Identity Fabric (VIF) consists of two components: PeerProofing and LucidAuth.
PeerProofing™: Identity Verification by the People Who Actually Know You
When a user needs to be proofed after a phone change, the process works like this:
1. The Selfie-Video. The user records a brief selfie-video on the Vercrio app, stating their name. The video is collected in a way that resists deepfake injection, and the system can screen for deepfake artifacts before the video is ever shown to peers.
2. The Peer Network. Vercrio's algorithm pulls from the corporate directory and randomly selects a set of the user's actual peers. The people they work with every day, the ones who know what they look and sound like.
3. The Verification. Those peers see the video on their own Vercrio app. If they recognize their colleague, they approve. If any peer rejects the request, the process halts immediately. Multiple positive endorsements are required before the proofing succeeds.
There is no helpdesk or call center in this process. There is no recitation of personal information that has been breached, sold, and resold a hundred times over. There is no possibility of compromise via a SIM-swap. There is no busy manager being asked to be a on a zoom call.
And critically, because the peer set is selected randomly at the moment of the request, there is no insider attack surface. An adversary cannot bribe "the person who handles MFA resets" because there is no such person. The set of potential endorsers is large, and the selection is unpredictable. Combined with a multi-vote requirement, the math works strongly against the attacker.
For initial onboarding, people who have interacted with the candidate such as their interviewing team or their HR manager can be called upon instead of the peer group. The same process runs but with this group providing the endorsement. And because The process is just as secure, and no helpdesk is needed.
LucidAuth™: Two Strong Factors, Zero Passwords
Once PeerProofing is complete, Vercrio has two independent, high-confidence authentication factors derived from the proofing event itself:
1. Something the user has: the phone on which the endorsed video was recorded, now bound to the verified identity.2. Something the user is: biometrics derived from the endorsed video, stored securely on the device.
LucidAuth™ uses these two factors for everyday authentication. Logins take seconds. There are no passwords to remember, type, rotate, or reset. There are no SMS codes to wait for.
This matters for two reasons. First, it eliminates a major attack vector — credential phishing, password spraying, and credential stuffing all depend on there being passwords to steal. Second, it dramatically improves user satisfaction. Vercrio's user survey data indicates shows that users overwhelmingly prefer Vercrio logins to password-based logins.
The CISO's Mandate
The CrowdStrike data is unambiguous about where the threat is heading. AI-enabled adversaries increased attacks by 89% year-over-year. Sophisticated threat actors are coupling AI capabilities with valid stolen credentials in the overwhelming majority of attacks. Breakout times are collapsing toward the speed of automated systems.
In that environment, the strategic question for every CISO is no longer "how do we make our helpdesk more secure?" That question leads inexorably back into the doom loop. The strategic question is: "How do we get the helpdesk out of the trust path entirely?"
Vercrio offers a concrete, deployable answer to that question. PeerProofing replaces the vulnerable insecure manual proofing process with automated, peer-driven verification that is structurally immune to the insider and spoofing attacks driving today's ransomware ecosystem. LucidAuth replaces passwords with two strong, independent factors derived from a verified identity event. Together, they remove the helpdesk from credential issuance, thus closing the holes through which ransomware has been flowing.
That's the more robust defensive posture in 2026. A clean systemic change that makes the dominant ransomware initial-access vector simply stop working against you.