A convincing voice.
A familiar name.
A request that sounds routine.
“Hey Margaret! It’s Kevin. I’m locked out of Microsoft 365. Can you reset my MFA and add my temporary phone?”
The caller sounds like the managing partner. They know Margaret’s name. They may know the firm’s terminology, the current matter, and even the partner’s schedule.
But the voice is fake.
Attackers can now create convincing voice clones from short recordings taken from webinars, podcasts, voicemail greetings, conference videos, or social media. Their objective is not always to steal money directly. Sometimes, they simply want your IT helpdesk to weaken the front door.
Once an attacker receives an MFA reset, enrolls a new device, or changes a mailbox rule, the rest of the compromise can happen quietly.
For law firms, medical practices, and accounting firms, that may expose client files, protected health information, tax records, financial information, or confidential communications.
Your helpdesk needs a new rule:
A familiar voice is not proof of identity.
The “Hey Margaret!” Deepfake Scenario
The call may sound like this:
“Hey Margaret! It’s Kevin. I’m heading into court and I can’t get into email. I need you to reset my MFA right now. Please don’t call me back: I’m walking into a meeting.”
Or:
“This is Dr. Patel. I need you to add an external forwarding rule to my mailbox. I’m working with a consultant and need messages sent to this address immediately.”
The request is urgent. The person sounds authoritative. The employee wants to be helpful.
That is exactly what the attacker is counting on.
A voice-clone scam may target:
- MFA resets
- Password resets
- New device enrollment
- Mailbox forwarding rules
- External email delegates
- VPN access
- Remote desktop access
- Administrator permissions
- Payment or wire instructions
The technical action may take less than five minutes. The consequences may last for months.
A mailbox rule can silently forward messages to an attacker, delete replies, or hide conversations involving clients, patients, tax documents, or settlement funds. An MFA reset can give an attacker control over a Microsoft 365 account. From there, they may launch business email compromise, ransomware, data theft, or further impersonation.
Why Traditional Verification Fails
Many organizations still rely on three basic checks:
- Caller ID shows the executive’s name.
- The caller knows the employee’s name and role.
- The caller answers security questions.
None of those controls is reliable against a prepared attacker.
Caller ID can be spoofed
A phone display is not an identity document. Attackers can manipulate caller ID information or call through services that make the number appear familiar.
Names and organizational details are easy to research
Company websites, LinkedIn profiles, public filings, social media posts, and data breaches can reveal job titles, office locations, reporting relationships, and current projects.
Security questions rely on information that may already be exposed
A birth date, office address, assistant’s name, client name, or last four digits of a phone number may be available online or in breached data.
Voice recognition is no longer enough
People naturally trust familiar voices. That instinct helped organizations move quickly in the past. Today, it creates a new attack surface.
The problem is not that employees are careless. The problem is that the old verification method was built for a world where a voice was difficult to reproduce.
It is not anymore.

The Solution: Build Verification Around Process, Not Intuition
A helpdesk should not have to decide whether someone “sounds right.” Your policy should make the decision for them.
Think of IT support like medical care.
A doctor does not prescribe a high-risk medication because a patient sounds convincing over the phone. The doctor checks the record, confirms identity, follows the procedure, and documents the decision.
Your IT provider should handle sensitive access changes the same way.
How to Stop Deepfake Voice Scams: 7 Practical Controls
1. Make the ticket the starting point
Adopt a ticket-first rule for security-sensitive requests.
No MFA reset, mailbox rule change, password reset, or privileged access change should begin with an unverified phone call.
Require the request to originate through an authenticated channel, such as:
- Your IT service portal
- A verified Microsoft 365 account
- A secure internal messaging platform
- A known device with an existing authentication factor
The ticket should record:
- The requester’s identity
- The requested change
- The business reason
- The affected account
- The approval required
- The technician who completed the action
A phone call can create urgency. It should not create authorization.
2. Call back using a number already on file
For high-risk actions, require out-of-band verification.
That means the helpdesk ends the call and contacts the individual using a trusted number already stored in your HR system, directory, practice management system, or client record.
Do not:
- Call the number shown on caller ID
- Call a number provided by the caller
- Reply to an email address supplied during the call
- Accept “I’m traveling” as a reason to bypass the process
Use a simple script:
“Our policy requires separate-channel verification for this request. I’m going to call you back using the number in our directory.”
A legitimate managing partner, physician, or accounting manager may be inconvenienced for two minutes. That is a reasonable tradeoff for protecting your entire environment.
3. Require approval for privileged actions
MFA resets and mailbox rule changes should be classified as privileged actions, even when the person requesting them is a senior executive.
Require secondary approval for:
- Managing partners and firm owners
- Physicians and medical directors
- CFOs and accounting partners
- Global administrators
- Finance and payroll users
- Shared mailboxes
- EHR and practice-management administrators
The approval may come from a designated security leader, practice administrator, department head, or second helpdesk technician.
This removes the burden from one employee’s judgment and creates accountability through documented review.
4. Deploy phishing-resistant MFA
Traditional MFA is important, but not every MFA method provides the same level of protection.
SMS codes, email codes, and push approvals can be exposed to phishing, SIM swapping, MFA fatigue, or social engineering. An attacker may call an employee and say:
“You’ll receive a code in a moment. Read it to me so I can finish the repair.”
Use FIDO2 security keys or passkeys for high-risk users and systems whenever practical.
According to the FIDO Alliance, passkeys use cryptographic credentials tied to an account and device. They are designed to resist phishing because there is no reusable code for an attacker to collect over the phone.
A cloned voice cannot approve a passkey challenge. A helpdesk technician should not be able to bypass that protection with a casual reset.
Important: phishing-resistant MFA does not eliminate recovery risk. Your MFA enrollment and reset process must be protected just as carefully as the login itself.
5. Treat mailbox rules as security events
A mailbox rule is not merely an email preference.
New forwarding rules, hidden redirects, auto-delete rules, and external delegates can be the first sign of business email compromise.
Configure email security and monitoring to alert on:
- Forwarding to external domains
- New inbox rules that delete or hide messages
- Unusual delegate access
- Rules created shortly after an MFA reset
- Sign-ins from unfamiliar locations or devices
- Multiple authentication failures followed by a successful login
Mailbox rule changes should trigger the same callback and approval process as MFA resets.
For law firm cybersecurity, this is especially important because attackers may search for client communications, settlement instructions, trust accounting information, and litigation deadlines. For medical practices, compromised email can expose patient information. For accounting firms, it may reveal tax records, bank details, or payroll data.
6. Train staff on voice-based social engineering
Generic phishing training is not enough.
Your team should practice realistic scenarios involving:
- A managing partner demanding an urgent reset
- A physician calling between appointments
- An accounting partner asking for an external forwarding rule
- A vendor requesting a new administrator account
- A senior employee insisting that “the usual process is too slow”
Training should teach staff to recognize:
- Urgency
- Authority
- Pressure to skip a ticket
- Resistance to callback verification
- Requests for MFA codes
- Emotional manipulation
- Unusual changes in communication style
Most importantly, employees need permission to slow down.
A good helpdesk employee should never be punished for following the policy: even when the requester is the owner.
7. Monitor, test, and improve the workflow
Policies are only useful when they work under pressure.
Your IT support and cybersecurity program should regularly review:
- MFA reset logs
- New authentication methods
- Mailbox rule changes
- Administrator activity
- Helpdesk tickets involving identity verification
- Failed callback attempts
- Suspicious calls and near misses
Run tabletop exercises. Test whether the helpdesk knows what to do when a caller sounds exactly like the managing partner.
Your monitoring should connect identity events, endpoint security, email security, and helpdesk activity. An MFA reset followed by a new mailbox rule and an unfamiliar login should create immediate concern: not wait for someone to notice missing messages weeks later.
Internal IT vs. a Managed Services Provider
You may be able to build and manage these controls internally.
Potential advantages of internal management
- Your employees understand the organization
- Policies can be customized quickly
- Leadership maintains direct oversight
- Existing staff may already know the systems
Potential disadvantages
- Training and certification costs
- Dependence on one or two employees
- Limited coverage during vacations or turnover
- Difficulty monitoring after hours
- Inconsistent documentation
- Competing priorities during tax season, litigation, or patient-care demands
- Limited experience with identity security, endpoint security, and incident response
For many firms with fewer than 150 employees, an outsourced IT model provides practical economies of scale. A qualified managed services provider can combine helpdesk operations, Microsoft 365 administration, identity governance, email security, endpoint security, monitoring, and compliance documentation.
The goal is not to remove control from your business. It is to make sure critical controls do not depend on whether one employee happens to recognize a voice.
Where A PC of Mind Fits
A PC of Mind provides managed helpdesk and security posture services for law firms, medical practices, accounting firms, and other professional services organizations.
That includes helping clients establish:
- Secure IT helpdesk procedures
- MFA enrollment and reset policies
- Microsoft 365 identity governance
- FIDO2 and passkey implementation
- Endpoint security and device management
- Email security and mailbox monitoring
- Backup and ransomware protection
- Incident response planning
- Documentation supporting HIPAA compliance and FTC Safeguards Rule obligations where applicable
The FTC Safeguards Rule requires covered financial institutions to maintain a written information security program with safeguards such as MFA, access controls, monitoring, employee training, service-provider oversight, and incident response. Coverage depends on the activities your organization performs, so consult qualified counsel regarding your obligations.
Medical practices should also align identity, access, audit, and incident-response controls with their HIPAA security program. Law firms must consider client confidentiality, professional responsibilities, cyber insurance, and contractual security requirements.

Final Word
Your helpdesk is part of your security perimeter.
If an attacker can convince one employee to reset MFA or change a mailbox rule, they may not need to defeat your firewall, endpoint security, or encryption. They may simply walk through the process your business created to be helpful.
The answer is not to distrust every phone call. It is to stop treating a voice, caller ID, name, or security question as sufficient proof of identity.
Use ticket-first rules.
Call back through a trusted number.
Require approvals.
Deploy phishing-resistant MFA.
Monitor sensitive changes.
Train your team to slow down.
If your current IT provider cannot clearly explain how MFA resets and mailbox rule changes are verified, it is time to review the process.
Contact A PC of Mind for a structured review of your helpdesk, identity controls, email security, endpoint security, and overall cybersecurity posture. Your business deserves IT support that protects access( not just restores it.)