Voice phishing is no longer limited to a convincing phone call and a fake sign-in page. A newly examined criminal platform called Work Panel brings target research, caller management, phishing-site creation, and stolen-credential handling into one web-based operation.

The result is a faster route from a helpdesk impersonation call to an enterprise account takeover.

The platform is being used in vishing campaigns aimed at customers of multiple identity providers.

It lets operators gather employee details, clone recognizable login brands, launch isolated phishing pages, and guide victims through authentication prompts while a caller keeps them on the phone.

This mirrors the pressure tactics reported in Microsoft Teams impersonation campaigns, where trust in internal support channels becomes the entry point.

Okta said in a report shared with Cyber Security News (CSN) that Work Panel is an active operator console linked to an intrusion cluster it tracks as O-UNC-045, also known as CORDIALSPIDER.

Researchers described it as a full application for running a vishing-driven account takeover business rather than a basic phishing kit.

Work Panel login page (Source – Okta)

The impact is not tied to one malicious domain or one individual caller. Work Panel is designed for several operators and distinct staff roles, allowing campaigns to be launched quickly and rebuilt after disruption.

That model gives criminals a repeatable service that can target organizations at scale while keeping the people making calls separate from the people collecting stolen access.

Cybercrime Platform Turns Helpdesk Calls Into Enterprise Account Takeovers

Work Panel divides its workforce into caller, manager, and administrator roles. Callers find employees, retrieve assigned internet-phone credentials, send limited pretext emails, and speak with targets.

Managers watch live victim sessions and collect submitted passwords or authentication codes, while administrators control the broader infrastructure, staffing, settings, and shutdown options.

Before a call, the platform can query commercial business-contact data to return employee names, corporate email addresses, direct phone numbers, job titles, and LinkedIn profiles.

The Work Panel user registration page (Source - Okta)
The Work Panel user registration page (Source – Okta)

That preparation makes an impersonated helpdesk call feel personal because the caller may already know the target’s role and reporting structure.

Similar social-engineering pressure appears in email bombing support scams, where confusion makes an unexpected support contact seem credible.

The caller does not receive the credentials captured during the attack. Instead, a manager monitors a live queue showing which phishing page a victim is viewing and pushes the next step in real time, including prompts for push approvals, number matching, authenticator codes, or support-ticket completion.

This separation protects the criminal operator’s most valuable data while making callers easier to recruit and replace. Work Panel also automates work that previously required technical skill.

An administrator can register a domain, configure DNS, create a separate phishing site, select an Okta, Microsoft 365, or Salesforce sign-in template, and clone visual branding from a target organization.

The platform can then send branded phishing emails that direct employees to the newly created site.

Each phishing panel operates independently with its own subdomain, configuration, process, and web-server block.

The platform also includes secret rotation, activity logging, live caller monitoring, and a self-destruct function that can remove phishing sites and supporting DNS records in one action.

These features make it harder for defenders to rely on a single domain takedown as a lasting solution.

Defending Against Faster Vishing

Organizations should treat unsolicited support calls as a verification problem, not simply a user-awareness issue.

Employees need a clearly communicated, trusted method to confirm the identity of helpdesk staff before sharing information, approving a login request, or following instructions received by phone, email, or collaboration software.

This is particularly important amid device code phishing technique campaigns that abuse legitimate-looking authentication flows.

The admin workspace (Source - Okta)
The admin workspace (Source – Okta)

Okta recommends phishing-resistant authenticators, including passkeys and smart cards, rather than methods that can be approved or read aloud during a call.

Security teams should also restrict access to sensitive applications to managed devices protected by endpoint security tools, notify users about every authenticator lifecycle event, and limit changes to authenticators based on device and network context.

Location-based access restrictions can further reduce exposure by denying sign-in attempts from countries, networks, or IP ranges where an organization does not operate.

Since Work Panel can rapidly clone brands and rebuild its infrastructure, defenders should pair those controls with prompt investigation of unusual authentication activity, especially when a user reports an unexpected support interaction or repeated login prompts.

The broader credential theft attack trends show why identity controls must assume attackers can adapt quickly.