Skip to main content
The Signicat Blog
An icon of a mobile phone verifying an identity using NFC. The text reads: "Stop fighting deepfakes with helpdesks: Verify identities instantly via NFC."
Portrait of Rob Brown
Rob Brown

Strategic Alliances & Partnerships Leader

Why IT helpdesks cannot stop deepfakes: use passport chips to secure account recovery

We spend millions of pounds hardening our perimeter. We roll out passkeys, multi-factor authentication (MFA), and single sign-on. Yet attackers do not bother breaking our primary security systems. They simply call the IT helpdesk and ask them to reset them. 

Social engineering is now the primary route for major enterprise security breaches. The hacking group Scattered Spider bypassed hardened authentication controls at some of the UK's biggest brands. They did not exploit intricate software vulnerabilities. Instead, they pretended to be locked-out employees, phoned the helpdesk, spun a convincing story, and tricked support agents into resetting credentials and registering malicious devices.

When these helpdesk social engineering hacks succeed, the real-world consequences are catastrophic:

  • TfL (Transport for London): Following a major cyber-attack, TfL had to shut down remote password resets. Because they lacked a secure, remote way to verify their workforce, they had to order thirty thousand staff to physically travel to IT hubs just to prove who they were and get back online.
  • M&S and Co-op: Attacks on vital logistics and IT supply chain networks led directly to supply failures, leaving retail shelves empty.
  • JLR (Jaguar Land Rover): Supply chain disruptions and IT lockouts halted car manufacturing lines completely, leaving factories inactive for two months.

Traditional account recovery does not verify the actual human. It only verifies easily spoofed facts. Today, generative AI and deepfakes make it simple to clone voices and fake identity documents. We are asking support agents to do an impossible job: tell the difference between a real colleague and a deepfake.

What is helpdesk social engineering, and why are helpdesks targeted?

Account recovery is the riskiest phase of the identity lifecycle. When an employee loses their phone or locks themselves out of their authenticator, standard cryptographic security controls are suspended.

This leaves the IT support agent as your final line of defence. The agent must make a high-stakes identity decision during a brief phone call. They rely on static information, like an employee ID, address, or manager's name - that fraudsters can buy on the dark web or gather from LinkedIn.

FeatureTraditional helpdesk recoveryCryptographic NFC recovery
Verification methodManual checks (human judgement)Automated cryptographic proof
Trust anchorStatic personal informationGovernment-signed passport chip
Average resolution time1.5 hours to 1 dayUnder 3 minutes
Resistance to deepfakesExtremely low (high error risk)Absolute (deepfakes lack chips)

Manually verifying a locked-out employee takes hours, sometimes even a full day. Meanwhile,       productivity plummets. Support admins lie awake at night dreading the reset call they get wrong.

How does passport NFC chip account recovery work?

The solution does not lie in more training or stricter scripts for support staff. It lies in cryptographic proof.

Most modern passports and national identity cards contain a secure Near Field Communication (NFC) chip. This chip holds government-signed, tamper-proof data, including a high-resolution photograph of the owner. Deepfakes do not have chips in their fake IDs. An attacker can clone a voice or fake a face on a video call, but they cannot manufacture a government-signed cryptographic chip.

By using the NFC reader in any smartphone, you can verify an identity document in seconds.

How Signicat delivers phishing-resistant account recovery

To secure the entire recovery lifecycle, Signicat combines ReadID (for cryptographic NFC chip verification) and iProov (for biometrics and liveness matching).

Instead of phoning support, a locked-out employee recovers their own account in a few simple steps:

  1. Scan the document: The user taps their passport or national ID card against their phone. ReadID checks the secure NFC chip and verifies the cryptographic signature to prove the document is authentic.
  2. Verify liveness: The user completes a brief face scan. iProov matches their live face to the high-resolution photo stored inside the passport chip.
  3. Automate the match: Once matched, the system updates their Microsoft Entra ID record. The user can safely reset their password or register a new authenticator.

This process takes minutes. It removes human bias and error completely. Your IT support staff no longer have to play spot-the-deepfake. It gives your helpdesk "permission for suspicion" because the automated system does the heavy lifting.

Meeting NIS2 and DORA helpdesk identity proofing mandates

Many organisations worry about privacy and data protection. Signicat’s solution stores no personal data. It only matches a secure cryptographic hash in your active directory. This privacy-first design means you do not need to run an intricate data protection impact assessment (DPIA).

This approach also satisfies strict European regulations like NIS2 and DORA. For instance, the European Union Agency for Cybersecurity (ENISA) NIS2 technical guidance (Section 11.6) states that organisations must establish clear procedures to verify a user's identity before giving them new, replacement, or temporary authentication credentials.

Stop asking your helpdesk to fight an unfair war against deepfakes. Let the chip in your pocket do the work.

Stop playing spot-the-deepfake: secure your helpdesk today

Your IT helpdesk cannot win a war against generative AI and voice cloning. Stricter scripts will not save them, and more training will not help them spot a cloned voice.

The choice is simple. You can keep risking a catastrophic shutdown like TfL, Co-op, or JLR, or you can use the cryptographic chip already sitting in your employees' pockets.

With Signicat, you get:

  • Absolute security: Cryptographic, government-grade proof that stops deepfakes dead.
  • Immediate savings: Account recovery times drop from hours to under three minutes.
  • Zero data headaches: No personal data is stored, meaning no new data protection assessments are required.
  • Instant compliance: Fully meet NIS2 and DORA identity-proofing rules overnight.

Frequently asked questions

  • Hackers use social engineering, generative AI voice cloning, and fake identity documents to trick IT helpdesk agents. By pretending to be a locked-out employee, they convince support agents to reset passwords, bypass multi-factor authentication (MFA), and register malicious devices.

  • No. While generative AI can clone voices and faces to trick human support agents, it cannot fake the cryptographic signatures stored inside government-issued passport chips. If the cryptographic signature matches, the identity document is genuine.

  • Under NIS2 and DORA guidelines, organisations must verify a user’s identity before issuing temporary or replacement credentials. Signicat combines NFC chip verification and iProov liveness detection to deliver fully automated, phishing-resistant, and audit-ready helpdesk identity proofing.