Respond to a possible account takeover when a VIP demands an immediate MFA reset

Instruction: Explain how you separate identity verification, incident containment, and account recovery. Keep your work within help-desk authority and give the VIP a practical response.

Context:

A fictional executive calls from an unfamiliar number asking you to remove all MFA methods and enroll a new phone. They say a board meeting starts in twenty minutes. The support queue also contains reports of repeated unsolicited MFA prompts and a notification that the executive’s mailbox forwards to an unfamiliar external address. These are unconfirmed indicators. Policy requires an independently verified identity-recovery route; caller ID, urgency, and biographical answers are insufficient. Security owns suspected-compromise investigation and containment, the identity team owns authorized recovery, and help desk collects the minimal ticket evidence and coordinates them. An approved executive-support contact and security duty responder are available through the internal directory. You have no authority to bypass the verification rule.

Updated

Official answer available

Read the opening below, then unlock the full answer and practical guidance.

I would not remove the MFA methods on this call. The unfamiliar number, unsolicited prompts, and forwarding notification make this a possible account-compromise incident, not a routine phone replacement. I would start the verified recovery route and contact the security duty responder while explaining to the executive how we can protect their meeting access. I would say: “I understand the meeting starts in twenty minutes. Because there are unusual account reports, resetting security methods from this call could give someone control of your account...

Related Questions