Halil, the change tonight is that help-desk identity recovery becomes a privileged transaction, not a customer-service workflow. FACT: the UNC6671 reporting says callers impersonated IT help desks, phoned employees on personal devices, sent them to fake MFA/passkey enrollment pages, stole live MFA codes, and then accessed cloud services including Microsoft 365 and Okta. FACT: the hedge-fund vishing reporting says AI-cloned voices were used against firms including Two Sigma, Citadel, and Millennium Management, with Two Sigma saying it stopped the attempt. So the control is: no password reset, MFA reset, passkey enrollment, device enrollment, or remote-access grant can be approved from voice identity alone — cloned or not.
Operationally: require a help-desk “step-up triangle” for resets: verified ticket from the corporate portal, manager or pre-registered peer approval inside the IdP/workflow system, and a phishing-resistant re-authentication path where possible. If the user cannot satisfy that, recovery goes to a quarantined state: temporary account access only, no admin roles, no mailbox export, no OAuth consent, no device enrollment, no VPN, and no financial-system access until an out-of-band verification is completed. For executives, traders, finance, and IT admins, I’d add a mandatory cooling-off period or second operator approval for MFA factor replacement.
On session-token controls: password rotation is insufficient. After any suspected vishing, AiTM, WhatsApp Web session hijack, or remote-access social engineering event, revoke active web sessions, OAuth/OIDC refresh tokens, SAML sessions where the service provider supports it, remembered devices, device-code grants, third-party OAuth grants, and remote-management tool sessions. For Microsoft 365 and Okta specifically, hunt for new MFA factors, new passkeys, suspicious device registrations, OAuth app consent, mailbox forwarding, impossible travel, and help-desk initiated resets tied to the same user.
For the India WhatsApp and Levi items, I won’t infer mechanics beyond the session-hijack and social-engineering descriptions on the table. But the identity lesson is the same: treat browser sessions and remote-control grants as credentials. Recovery must include “log out all linked devices,” revoke web tokens, kill remote-support sessions, and re-verify enrolled devices. If your MFA recovery flow can be completed by a convincing phone call, you do not have MFA recovery — you have a voice-authenticated bypass.