
Social engineering just industrialized. A platform marketed on underground forums as “ATHR” ($4,000 plus 10% commission) automates telephone-oriented attack delivery end to end: spoofed brand emails prompt victims to call a “support” number, where AI voice agents impersonating Google and Microsoft support staff dynamically work callers through scripts to harvest credentials and six-digit MFA codes. Combine that with Scattered Spider-style help-desk impersonation which is still driving account takeovers across financial services in 2026 and the identity layer is now under attack from both directions: attackers calling your users, and attackers calling your help desk. Detection here is inherently investigative. A “successful login with MFA” alert tells you nothing; the signal is in the surrounding questions: was there a password reset via the service desk, a new device enrollment, an impossible-travel pattern, a mailbox rule created minutes later? Make those questions routine before the phone rings.
