ATO and Social Engineering: The Rising Threat to Tech Companies

Quick question: when your help desk gets a call from someone claiming to be an employee who's locked out of their account, how confident are you that the voice on the line is who they say they are?

For a growing number of technology companies, that single phone call has become the front door to a full-blown breach. Attackers have figured out something important. Why spend weeks trying to crack a firewall when you can simply call someone and ask them to open it for you?

This is the world of account takeover (ATO) and social engineering, and it is aimed squarely at the phone. Let's unpack what's happening, why tech companies are such attractive targets, and what you can actually do about it.

What Is Account Takeover, and Why the Phone?

Account takeover is exactly what it sounds like. An attacker gains control of a legitimate user's account, then uses that trusted access to steal data, move money, or burrow deeper into your systems.

Social engineering is the "how." Instead of exploiting software, attackers exploit people. They manipulate a human being into handing over credentials, resetting a password, or approving a login. And increasingly, they do it over a phone call, a tactic known as vishing (voice phishing).

The numbers tell the story. Account takeover attacks surged 250% year over year in 2024, with 99% of organizations targeted and 62% of those experiencing a successful breach (Vectra AI; The SSL Store). Voice-based attacks are climbing especially fast: CrowdStrike reported that vishing activity jumped 442% between the first and second halves of 2024 (The SSL Store).

Here's the part that should get your attention. Social engineering was the starting point for 36% of incident response cases between May 2024 and May 2025, and 66% of those attacks targeted privileged accounts (Palo Alto Networks Unit 42). Attackers aren't going after just any account. They want the keys to the kingdom.

Why Tech Companies Are in the Crosshairs

Technology companies make especially rich targets for a few reasons:

  • Privileged access is everywhere. Engineers, admins, and IT staff hold the credentials that unlock cloud environments, source code, and customer data.
  • Identity is the perimeter. Modern tech stacks run on identity providers, single sign-on, and multi-factor authentication (MFA). Trick the right person into resetting an MFA token, and the attacker inherits their access.
  • Help desks are built to be helpful. Support teams are trained to solve problems quickly and reduce friction. Attackers weaponize that instinct.
  • Employee information is public. A quick search on professional networking sites gives attackers names, roles, and reporting lines. It's everything they need to sound convincing.

When One Phone Call Costs $100 Million

If you want a case study in how devastating this can be, look no further than the 2023 attack on MGM Resorts.

The attack group, known as Scattered Spider, didn't break in with malware or a zero-day exploit. They researched an MGM employee on LinkedIn, then simply called the company's IT help desk posing as that employee and requested a credential reset. The help desk complied. From there, the attackers escalated privileges inside MGM's identity and cloud environments and deployed ransomware (Netwrix; Wikipedia).

The result? An estimated $100 million loss, roughly 10 days of operational chaos, slot machines going dark, and digital room keys failing (Netwrix). A related attack on Caesars Entertainment, which began with social engineering against an IT vendor, reportedly ended in a $15 million ransom payment (Reuters).

The uncomfortable takeaway: enormous investments in data-network security were bypassed by a single, well-researched phone call.

The Slow Con: How ATO Actually Unfolds

Not every attack is a smash-and-grab. Many are patient, methodical, and built entirely on phone calls.

We've seen this pattern up close. A global financial institution was habitually targeted for account takeover attacks through calls into its contact centers. Malicious callers used spoofing to mask the source of their calls, then made multiple social engineering calls about a single account, gleaning one piece of personal information at a time. Once they had assembled enough detail, they'd place a final call to take over the customer's account and commit fraud (SecureLogix Customer Story #1012).

Notice the pattern. No malware. No hacking in the Hollywood sense. Just phone call after phone call, each one harvesting a small piece of the puzzle until the picture was complete.

The same playbook works against a tech company's internal help desk, its customer support line, or its outsourced IT vendor. Anywhere a human answers a phone and makes a trust decision, ATO can take root.

Why Traditional Defenses Fall Short

Most organizations have poured resources into securing email and data networks while leaving the voice channel wide open. That gap is exactly what attackers exploit.

Consider how these attacks defeat common controls:

  • Caller ID can't be trusted. Attackers spoof numbers to appear as a known employee or internal extension.
  • Knowledge-based authentication is leaky. Asking security questions doesn't help when attackers have already social-engineered the answers, or bought them from a breach.
  • MFA can be reset away. If an attacker can talk a help desk into resetting a token, the second factor becomes the attacker's factor.

Huge investments have been made to secure data networks and email, while enterprise voice systems remain largely unprotected. In a world where fraudsters target phone systems with the same intensity they once reserved for data networks, that old-world approach is no longer up to the task.

Closing the Voice Gap

The good news, and there is good news, is that this problem is solvable. You don't have to accept that any convincing caller can talk their way past your defenses.

The key is to verify and authenticate calls before a human ever makes a trust decision. That means treating the voice channel with the same rigor you apply to your data network.

SecureLogix helps technology companies close the voice gap on two fronts:

Authenticate every inbound call automatically. The Orchestra One™ Call Authentication Service verifies and scores every inbound call using thousands of call and network details, plus real-time carrier metadata including STIR/SHAKEN. Suspicious and spoofed calls are flagged before your agents or help desk staff pick up, so trust decisions aren't left to gut instinct. It also removes the need for frustrating knowledge-based security questions and delivers authentication at roughly 50% less cost than competing solutions on average, reducing contact center costs by around 20%.

Filter attacks out of your voice network. The Call Defense™ Call Security System sits at the edge of your voice network and sorts good traffic from bad in real time. In the financial institution case above, SecureLogix identified the unusual pattern of spoofed calls, redirected them to fraud detection agents through new policies, and helped the bank stop about $400,000 in fraudulent transfers in just the first three months (SecureLogix Customer Story #1012).

Behind both is a team with more than 400 years of collective experience that protects over 3 billion calls a year, backed by SecureLogix's more than 25 years in voice security and joint research with the U.S. Department of Homeland Security and Department of Defense.

The Bottom Line

Account takeover and social engineering are no longer fringe threats. They are the preferred way into modern technology companies, and the phone is the weapon of choice. The MGM attack proved that a single call can undo hundreds of millions in security investment.

But it also points to the fix. If a phone call can bring a company down, then securing and authenticating your calls is one of the highest-leverage moves you can make.

Your voice network is under attack. The question is whether you'll answer that call prepared.

Ready to close the voice gap? Speak with a Call Security & Trust Expert.