Skip to content

The Service Desk Is the Front Door

Identity, impersonation and zero trust for AI agents in UK IT support

Kroneus Zero Trust Security19 min read

In 2025 the attacks on Marks and Spencer and the Co-op showed what follows when an attacker persuades an organisation that they are someone else. The likely next step for many service desks is an AI agent that can act as well as answer. This report argues that the identity checks the NCSC recommended for human help desks should apply at least as strictly to AI agents, and that the agent itself should be treated as an untrusted party.

TL;DR — key takeaways

  • Identity is the target, and the service desk is a route to it. The NCSC gives impersonating a user on helpdesk calls to reset credentials as an example of attackers targeting identity.
  • Knowledge-based checks no longer prove identity. Co-op's attackers answered the security questions. The NCSC says the "secret answer" information available to verify an identity is diminishing.
  • An AI agent can be persuaded too. NIST SP 800-207 warns that an attacker may "induce or coerce" a software agent, and the NCSC says prompt injection may never be totally mitigated.
  • Safeguards must sit outside the model. The NCSC advises deterministic, non-LLM safeguards that constrain what an AI system can do.
  • Help-desk providers face new regulation. The Cyber Security and Resilience Bill, now in the House of Lords, would bring medium and large managed service providers, including helpdesk providers, into scope.
No password reset or access change should rest on whether the caller, or an AI agent acting for the caller, is believed.

One persuaded reset hands over an identity: an impersonator persuades the service desk, the password or MFA reset hands over the identity, and email, VPN, cloud admin and files all trust it.

What happened in 2025

Much of the public discussion of these incidents rests on press accounts that the companies have not confirmed. This section separates what the organisations said on the record from what was reported in the press.

Timeline of the M&S and Co-op incidents from 17 April 2025 to 20 May 2026, marking which events are on the record and which are press reports.

DateEventBasis
17 Apr 2025M&S: initial entry, through what the chairman later called "sophisticated impersonation".On record
19 Apr 2025M&S became aware in the late afternoon of Easter Saturday that the attackers were in its systems.On record
22 Apr 2025M&S told the market it was managing a cyber incident and had reported it to the NCSC.On record
25 Apr 2025M&S paused orders through its UK and Ireland websites and apps. The Co-op initial attack took place.On record
4 May 2025The NCSC published recommendations for organisations following the retail incidents.On record
13 May 2025M&S confirmed some personal customer data had been taken, not including usable payment or card details, or account passwords.On record
21 May 2025M&S estimated an impact of around £300m on 2025/26 group operating profit, before mitigation.On record
10 Jun 2025Online orders resumed for selected fashion ranges in Great Britain.Press
8 Jul 2025M&S and Co-op executives gave evidence to the Business and Trade Sub-Committee.On record
10 Jul 2025The National Crime Agency arrested four people in connection with the M&S, Co-op and Harrods attacks.On record
11 Aug 2025M&S restored Click & Collect, about 15 weeks after the attack.Press
20 May 2026M&S reported £131.3m of incident-related costs and £100.0m of insurance proceeds for 2025/26.On record

On the record

M&S's chairman, Archie Norman, told MPs on 8 July 2025 that the initial entry on 17 April "occurred through what people now call social engineering", and that "it was sophisticated impersonation". He said the attackers "appeared as an individual, with their details", and that "Part of the point of entry in our case also involved a third party." He did not name the third party, and he did not refer to a help desk.

Co-op gave the clearest first-hand account of a reset attack. Its Chief Digital Information Officer, Rob Elsey, told the same committee: "They were able to impersonate a colleague and successfully answer a number of security questions to get their account reset. That activity happened about an hour before they started to use the account maliciously."

Reported and disputed

Press reports widely said that the M&S attackers deceived the IT help desk. Professor Ciaran Martin, former chief executive of the NCSC, told MPs he was relying on those reports. Tata Consultancy Services told the committee that it was M&S's service desk provider until July 2025, and that its scans found "no indicators of compromise within the TCS network". TCS has also said the M&S service desk contract was re-tendered from January 2025, and that the two matters are "clearly unrelated". The public record does not establish who was deceived, or how.

Attribution is also unsettled. In May 2025 the NCSC referred to "speculation in the press" about a group known as Scattered Spider and said it was "not yet in a position to say if these attacks are linked". Norman said M&S believed DragonForce, "a ransomware operation", was involved alongside a separate instigator. We found no primary source reporting charges over the retail attacks as at 6 October 2026.

Cost

In May 2025 M&S estimated "an impact on Group operating profit of around £300m for 2025/26", before mitigation. Norman described it as "a gross estimate of loss of profit": a forecast, not a loss of sales or a final cost. In its 2025/26 results M&S reported £131.3m of incident-related costs, of which £109.3m related to immediate systems response and recovery, and £100.0m of insurance proceeds. For Co-op, the NCSC Annual Review records that the data of all 6.5 million members was stolen.

Why the service desk is the target

A service desk exists to restore access quickly. That is also what an attacker wants from it. A password reset or a new multi-factor authentication (MFA) enrolment, granted to the wrong person, hands over an identity that every later control will then trust.

The NCSC's Annual Review 2025 states: "Attackers of all capabilities are pivoting away from targeting individual devices in favour of targeting user identity. For example, impersonating a user on helpdesk calls to reset an identity's access credentials". It adds that "the amount of 'secret answer' information that can be used to securely verify an identity (such as previous addresses, schools, and personal reference numbers) is diminishing." The Co-op account shows the effect: the attackers answered the questions.

The weakness lies in the check. Answers that can be found in breached data do not prove who is on the line.

The pattern is not limited to retail. Palo Alto Networks' Unit 42 reported that, across more than 700 incident response cases between May 2024 and May 2025, "36% of all incidents in the IR caseload began with a social engineering tactic". It lists "help desk protocols and fast-track approvals" among the processes attackers routinely exploit. Unit 42 does not publish a separate figure for help-desk attacks, and this report does not estimate one.

Fast-track approvals matter. Any process that lets urgency or seniority shorten a check gives an impersonator something to push on. A caller who is senior, locked out and under pressure is the case the process must handle most carefully.

On 4 May 2025 the NCSC recommended that organisations "review helpdesk password reset processes, including how the helpdesk authenticates staff members credentials before resetting passwords, especially those with escalated privileges", alongside comprehensive 2-step verification, attention to Domain Admin, Enterprise Admin and Cloud Admin accounts, and detection of logins from atypical sources.

What "verify before reset" means in practice

  • Verify identity through a channel the requester does not control, such as a call back to a number held in the HR record, or confirmation from the user's line manager. Caller ID, an email from the account in question and answers to personal questions are not proof.
  • Treat a request to reset MFA or register a new device as at least as sensitive as a password reset.
  • Apply stronger checks to privileged accounts, in line with the NCSC's advice on accounts with escalated privileges.
  • Do not let urgency or seniority bypass the check. Escalate instead.
  • Limit who can initiate resets, and monitor for unusual request patterns.
  • Record who verified the requester, by what method, and what was changed.

The next service desk is agentic

An AI agent placed in a service desk does more than draft replies. It reads a ticket or a chat, works out what is wrong, and may call tools that reset credentials, change group membership or run scripts on endpoints. In May 2026 the NCSC summarised joint international guidance, "Careful adoption of agentic AI services", which applies to exactly this kind of deployment.

The risk was described before today's language models existed. NIST SP 800-207, published in August 2020, warns that "an attacker will be able to induce or coerce an NPE to perform some task that the attacker is not privileged to perform", and that "The software agent may have a lower bar for authentication (e.g., API key versus MFA) to perform administrative or security-related tasks compared with a human user."

The NCSC's December 2025 blog on prompt injection explains why this applies to large language models. Current LLMs "simply do not enforce a security boundary between instructions and data inside a prompt", and "it's very possible that prompt injection attacks may never be totally mitigated in the way that SQL injection attacks can be." This is "particularly critical when the system calls tools or uses APIs based on the LLMs output".

The same manipulated ticket reaches an AI agent twice: without controls outside the model the MFA reset runs; with a deterministic policy gate it is escalated to a named person.

A ticket is text written by the requester. The impersonator would no longer need to persuade a person. Persuading the model could be enough.

The NCSC's agentic AI guidance says organisations should "never grant an agent unrestricted access to sensitive data or critical systems", should "apply least privilege – give agents only the minimum access they need, for the shortest time required", and should "avoid long-lived credentials". It is plain about readiness: "If you cannot understand, monitor or contain an agent's actions, it is not ready for deployment". The NCSC does not advise against adoption. It encourages organisations to start small, with low-risk tasks.

The UK government's voluntary Code of Practice for the Cyber Security of AI (DSIT, January 2025) asks organisations to "Enable human responsibility for AI systems", to grant permissions on other systems "only provided as required for functionality", and to log system and user actions. The NCSC and CISA Guidelines for secure AI system development ask that where AI components trigger actions, developers "apply appropriate restrictions to the possible actions".

Zero trust for the AI itself

The NCSC defines zero trust as "an architectural approach where inherent trust in the network is removed, the network is assumed hostile, and each request is verified based on an access policy." Its design principles state that "An identity can represent a user (a human), service (software process) or device." An AI agent is a software process. It should have its own identity, and its requests should be verified like any other. NIST puts it briefly: "No asset is inherently trusted."

We apply this to the agent itself. The agent should be treated as an untrusted party even when it works for the organisation. Its output is a proposal. The decision to act, the authority to act and the proof that the action happened should each sit outside the model, in components that follow fixed rules and cannot be argued with. Before any of this, an organisation needs to know which agents it runs and what each can reach — the NCSC's first principle: "Know your architecture, including users, devices, services and data".

The seven-step control model: the AI proposes inside the model; outside it, policy decides, a person approves, a gateway re-verifies, the endpoint verifies, the change is read back, and every step is recorded.

StepControlAddressesAnchored in
1. The AI proposesThe agent drafts a diagnosis and a proposed change. It holds no standing credentials for the systems it would change.A manipulated agent acting directlyNCSC: know your user, service and device identities. NIST tenet 3. NCSC agentic AI guidance
2. Policy decidesA deterministic policy engine checks who is asking, for which account, which action, and what verification has been done. It can refuse or escalate. The model cannot override it.Prompt injection turning into actionNCSC: use policies to authorise requests. NIST tenet 4. NCSC prompt injection guidance
3. A named person approvesChanges that affect access are approved by an identified person who sees the evidence. Privileged accounts need two people.Deception of a single decision-maker, human or machineDSIT Code principle 4 and provision 4.1. NCSC agentic AI guidance
4. A gateway re-verifiesA separate execution gateway checks the approval, the policy decision and the request again before anything runs.Tampering between approval and executionNCSC: authenticate and authorise everywhere. NIST tenet 6
5. The endpoint verifiesThe target accepts only commands signed by the gateway, limited to one action on one target, valid for a short time.Forged or replayed commandsNCSC: don't trust any network, including your own. NIST tenet 2
6. The change is read backAfter the change, the actual state is read back and compared with what was approved.Silent failure, or a different changeNCSC: assess user behaviour, devices and services health. NIST tenet 5
7. Every step is recordedRequest, verification, proposal, decision, approval, execution and result go to an append-only, hash-chained log.Disputed accounts after an incidentNCSC: focus monitoring on users, devices and services. DSIT Code provision 12.1

Help-desk controls within the model

  • Verify identity before any reset. Verification happens through an independent channel. The agent may gather information, but it cannot mark a user as verified.
  • Legitimacy checks escalate; they do not decide. A model or rule that assesses whether a request looks genuine can send it to a person. It cannot approve it.
  • Resets for another person need authority. The request must come from someone with a recorded right to ask, such as the user's line manager or a named delegate.
  • Temporary credentials never go by chat or email. They are delivered through a channel already bound to the verified user.
  • Two people for privileged access. Any change to access for a privileged account needs two approvers.

This model does not remove the need for judgement. It limits what a successful deception can achieve and makes the attempt visible afterwards. It also adds friction, so each organisation will need to decide which low-risk actions can run without a human approver. The NCSC's advice to begin with low-risk tasks is a sensible starting point.

Regulation and accountability

The Cyber Security and Resilience (Network and Information Systems) Bill is not yet law. It was introduced in the House of Commons on 12 November 2025, reintroduced on 14 May 2026, and completed its Commons stages on 16 June 2026. Lords report stage is scheduled for 26 October 2026.

Under the Bill, medium and large managed service providers would be regulated for the first time. The government's factsheet says a managed service can include "IT outsourcing (for example, IT remote support or helpdesks, and management of applications, such as emails and IT infrastructure management)", and that MSPs' "widespread and trusted access to their clients' networks" gives a "one to many" impact. As announced in November 2025, organisations in scope would report more harmful incidents within 24 hours, with a full report within 72 hours. The final duties will depend on the Act as passed and on secondary legislation.

Evidence to hold after an incident

A 24-hour reporting window, if enacted as announced, leaves little time to rebuild records. MSPs and in-house teams should be able to answer these from records rather than recollection:

  • For each reset or access change: who asked, through which channel, and how their identity was verified.
  • Who approved the change, and under which policy rule.
  • What exactly was changed, on which system, and whether the result was checked.
  • Which actions an AI agent proposed or carried out, and what input it was given.
  • Whether any of these records could have been altered after the event.

Recommendations

For organisations

  1. Review help-desk password and MFA reset processes now, starting with privileged accounts, as the NCSC recommended in May 2025.
  2. Stop treating answers to personal questions as proof of identity.
  3. Deploy MFA comprehensively, and treat an MFA reset as a high-risk change in its own right.
  4. Monitor for unusual reset patterns and for risky logins that follow a reset.
  5. Map every route by which an identity can be reset, including routes run by suppliers, and name an owner for each.

For managed service providers

  1. Plan on the basis that you will be regulated. The Bill's description of managed services includes IT remote support and helpdesks.
  2. Agree with each client, in writing, how identity is verified before a reset and who may ask for a reset on another person's behalf.
  3. Keep per-client records that would support an initial report within 24 hours.
  4. Separate each client's credentials and tools, so that the compromise of one does not reach the others.

For anyone deploying AI agents in IT operations

  1. Give every agent its own identity and the least privilege it needs, with no long-lived privileged credentials.
  2. Place deterministic controls between the model and any action. Do not rely on the model to detect that it is being manipulated.
  3. Require a named human approver for changes to access, and two approvers for privileged accounts.
  4. Log every input, proposal and action in a form that shows whether records have been altered.
  5. Decide who can stop the agent, and test that they can.
  6. Start with low-risk tasks. Extend the agent's scope only when you can understand, monitor and contain what it does.

How KRONEUS approaches this

KRONEUS builds FORGE, an AI service desk designed on the principles in this report: the AI proposes, policy decides, a named person approves, and every change is verified and recorded. Nothing changes without a person's approval, passwords are never sent by chat or email, and every action is written to a tamper-evident audit trail. FORGE is in early access with pilot customers; you can book a demo.

FORGE has not been endorsed or reviewed by the NCSC or by any government body. This report reflects KRONEUS's own analysis of public sources and makes no claims about the performance of any product.

FAQs about service desk security and AI agents

How did the attackers get into M&S and the Co-op?

On the record, M&S's chairman told MPs the initial entry on 17 April 2025 was "sophisticated impersonation", and Co-op said attackers impersonated a colleague and answered security questions to get an account reset. Press reports said the M&S help desk was deceived, but the public record does not establish who was deceived, or how.

Why are security questions no longer enough to verify identity?

Answers such as previous addresses, schools and reference numbers can be found in breached data. The NCSC says the "secret answer" information available to verify an identity is diminishing, and Co-op's attackers answered the questions.

What does "verify before reset" mean?

Confirm the requester's identity through a channel they do not control, such as a call back to a number in the HR record or confirmation from their line manager, before any password or MFA reset. Caller ID, an email from the account in question and personal questions are not proof.

Can an AI agent be manipulated into resetting a password?

Yes. NIST warned in 2020 that an attacker may "induce or coerce" a software agent, and the NCSC says prompt injection may never be totally mitigated. If an agent reads requester-written text and also holds reset permissions, the right text could steer the reset. That is why the decision has to sit outside the model.

What is zero trust for AI agents?

Treating the agent as an untrusted party with its own identity. Its output is a proposal; a deterministic policy, a named human approver, independent verification and a tamper-evident record decide and prove what actually happens.

Does the Cyber Security and Resilience Bill apply to IT helpdesk providers?

If enacted as introduced, it would bring medium and large managed service providers into scope, and the government's factsheet names "IT remote support or helpdesks". The Bill is not yet law; Lords report stage is scheduled for 26 October 2026.

Should we use AI agents on the service desk at all?

The NCSC does not advise against adoption. It encourages starting small with low-risk tasks, and says an agent is not ready for deployment if you cannot understand, monitor or contain its actions.

About this research

The Service Desk Is the Front Door: identity, impersonation and zero trust for AI agents. Kroneus Zero Trust Security, London. Report KZT-2026-002, 7 October 2026. Independent analysis; facts are drawn from the public sources below, as at 6 October 2026. Reference to any organisation, guidance or standard does not imply endorsement of KRONEUS or its products by that organisation.

Related research. When AI Gets a Badge — the enterprise blast radius of AI agents, and When the Agent Holds the Keys.

Sources

  1. House of Commons Business and Trade Sub-Committee. Oral evidence: UK economic security, HC 835, Panel I (Marks and Spencer). 8 Jul 2025. committees.parliament.uk
  2. House of Commons Business and Trade Sub-Committee. Oral evidence: UK economic security, HC 835, Panel II (Co-op). 8 Jul 2025. committees.parliament.uk
  3. NCSC. Annual Review 2025. Oct 2025. ncsc.gov.uk
  4. NCSC. Thinking carefully before adopting agentic AI. 15 May 2026. ncsc.gov.uk
  5. NIST. SP 800-207, Zero Trust Architecture. Aug 2020. csrc.nist.gov
  6. NCSC. Prompt injection is not SQL injection (it may be worse). 8 Dec 2025. ncsc.gov.uk
  7. UK Parliament. Cyber Security and Resilience (Network and Information Systems) Bill: bill stages. bills.parliament.uk
  8. DSIT. Cyber Security and Resilience Bill factsheet: relevant managed service providers. Updated 30 Jun 2026. gov.uk
  9. Marks and Spencer Group plc. Cyber Incident Update (RNS 7170F). 22 Apr 2025. data.fca.org.uk
  10. Marks and Spencer Group plc. Cyber Incident – Further Update (RNS 2813G). 25 Apr 2025. ticker.app
  11. NCSC. Incidents impacting retailers – recommendations from the NCSC. 4 May 2025. ncsc.gov.uk
  12. Marks and Spencer Group plc. Cyber Incident – Further Update (RNS 4286I). 13 May 2025. data.fca.org.uk
  13. Marks and Spencer Group plc. Full Year Results for the 52 Weeks Ended 29 March 2025 (RNS 4982J). 21 May 2025. data.fca.org.uk
  14. The Register. Online orders working again at M&S, 46 days later. 10 Jun 2025. theregister.com
  15. National Crime Agency. Retail cyber attacks: NCA arrest four for attacks on M&S, Co-op and Harrods. 10 Jul 2025. nationalcrimeagency.gov.uk
  16. The Register. M&S restores Click & Collect months after cyber attack. 11 Aug 2025. theregister.com
  17. Marks and Spencer Group plc. Preliminary Results for the 52 Weeks Ended 28 March 2026. 20 May 2026. londonstockexchange.com
  18. House of Commons Business and Trade Sub-Committee. Oral evidence: UK economic security, HC 835, Panel III. 8 Jul 2025. committees.parliament.uk
  19. Tata Consultancy Services. Letter to the Business and Trade Sub-Committee. 29 Sep 2025. committees.parliament.uk
  20. Tata Consultancy Services. Clarification on the article published by The Telegraph. 26 Oct 2025. nseindia.com
  21. Palo Alto Networks Unit 42. 2025 Global Incident Response Report: Social Engineering Edition. 30 Jul 2025. unit42.paloaltonetworks.com
  22. House of Commons Business and Trade Sub-Committee. Oral evidence: UK economic security, HC 835, Panel IV. 8 Jul 2025. committees.parliament.uk
  23. DSIT. Code of Practice for the Cyber Security of AI. 31 Jan 2025. gov.uk
  24. NCSC, CISA and partners. Guidelines for secure AI system development. 27 Nov 2023. ncsc.gov.uk
  25. NCSC. Zero trust architecture design principles (v1.1). Reviewed 16 Jan 2026. ncsc.gov.uk
  26. DSIT. Tough new laws to strengthen the UK's defences against cyber attacks on NHS, transport and energy. 12 Nov 2025. gov.uk

KRONEUS builds SELA, Zero Trust runtime control and governance for autonomous AI agents, and FORGE, an AI service desk where every change needs a person’s approval. We also deliver web and API penetration testing. Read more on agentic AI security.

Add KRONEUS as a preferred source on Google

Marks us as preferred in your own Google results — Top Stories, AI Mode and AI Overviews. It changes what you see, not what anyone else does.