Critical 2026 Detection — Sequential Account-Recovery Chain: Password Reset → MF
Detects a suspicious sequence of identity-related operations performed by a single user within a 2-hour window. The chain consists of a password reset, MFA method modification, new device registration, and a subsequent privilege escalation event (such as role assignment or application consent). This pattern is consistent with helpdesk-vishing campaigns often used by threat actors like Scattered Spider to perform full account takeovers.
Sigma

