An attacker uses a stolen help-desk token to reset the utilities-billing administrator. What attack type is this?
Select an answer to reveal the explanation.
Short Explanation
Nobody dropped a USB or launched a new encryptor—they walked up to the help desk with a stolen badge and reset the billing admin. That is account takeover via identity, not a malware family. The vector is social-plus-help-desk access.
Full Explanation
Resetting a privileged civic account with a stolen help-desk token is account takeover through identity and social-adjacent access. The defining action is control of a legitimate administrator identity, not deployment of ransomware, volumetric flooding, or removable media. Analysts should classify the attack from the abused reset path.