Recovery flows include reset links, backup codes, recovery email or phone verification, help-desk identity checks, and administrator resets. Attackers exploit the weakest leg: SIM-swap against SMS recovery, guessing security questions, or manipulating support staff into resetting another person’s account.
Key points
Matched recovery strengthPhishing-resistant sign-in paired with a weak reset path means the reset path becomes the attack surface.
Flow instrumentationAlert on recovery attempts, require verification evidence for privileged accounts, and audit help-desk resets separately from self-service.
Important limitationRecovery trades security for availability by design. Every fallback that keeps users from being locked out is also a door that can be abused — treat it as a security control, not a convenience feature.