Most Important Detection – Vishing/Rogue MFA Takeover/Helpdesk-Support Impersonation 2026: New MFA/Device Registration from Hosting-ASN IP Post Password Reset

Detects the registration of a new MFA device or authenticator by a user shortly after a password reset event, where the registration originates from an IP address classified as a hosting provider, datacenter, or VPN. This pattern is indicative of a help-desk or vishing-based account takeover attack where an adversary registers their own MFA device to gain persistent access.