Social engineering is always a problem, and I think first-level support should NEVER have the ability to see any information or have the ability to make changes to accounts. This should get escalated to second level support.
But regardless, a single account may get compromised, but at least you can't feed partial data from one social engineering attempt into another company, which is what apparently is happening more and more because of impedance mismatches with what everyone uses.
But regardless, a single account may get compromised, but at least you can't feed partial data from one social engineering attempt into another company, which is what apparently is happening more and more because of impedance mismatches with what everyone uses.