Desk live·
ForensicPost
Ransomware/Identity/File 26-0413

You Outsourced the Help Desk and Kept the Consequences

In the M&S case the password reset was performed by a third-party service desk. Outsourcing that function transfers the work and the cost, and none of the risk.

Constructed geometry · not a chart of case data
TargetOutsourced IT service desks
ActorScattered Spider
D. Kennedy11 min readConfidence: high2 sources reviewed

The detail M&S confirmed publicly is worth isolating: the caller impersonated an employee, and the service desk that performed the password reset was run by a third party.

That arrangement is entirely normal. IT service desks are among the most commonly outsourced functions in large enterprises, for sound reasons of cost, coverage and scale.

What The Contract Cannot Transfer

An outsourcing agreement transfers the activity, the staffing and a defined service level. What it cannot transfer is the consequence of a reset going to the wrong person, which lands entirely on the client.

It also introduces a specific weakness in the verification itself. An internal help desk agent may recognise a voice, know the team, or sense that a request is odd. A contracted agent working across accounts, measured on handle time, has only the script.

The Script Is The Control, And It Is Written For The Wrong Risk

Identity verification scripts are typically built around information the organisation holds: employee number, manager’s name, date of joining, cost centre. Every one of those is discoverable, and this desk has documented an actor call script in 26-0715 that is constructed precisely to satisfy them.

The controls that resist it are structural rather than conversational: callback to a number held in HR records rather than one the caller supplies, manager attestation out of band, and a hold period before a newly reset account can enrol an authentication factor.

Handle Time Is The Real Adversary

Each of those controls adds minutes to a call, and service desk contracts are priced and measured on how few minutes calls take. The commercial incentive runs directly against the security requirement, and it does so in a document signed by procurement rather than by security.

Any organisation with an outsourced desk can answer one question this week: what exactly does the contract require the agent to verify before resetting a credential, and is anyone measured on doing it?

How we reported this

Compiled from the company’s public statements and reporting, listed below. The description of verification scripts and controls is general practice and is labelled as our analysis, not a description of any named provider. Corrections: corrections@forensicpost.com.

Sources
  1. M&S ransomware hack: what happened and the key security lessonsSpecops
  2. Scattered Spider behind cyberattacks on M&S and Co-opThe Hacker News
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary