The Scam That Starts With a Flooded Inbox
A cyber crime technique is circulating that uses a combination of email flooding and fake IT support calls to trick employees into granting remote access to their devices. The attack follows a consistent pattern: first, a staff member’s inbox is flooded with spam emails, making it effectively unusable. Then, shortly after, a call arrives claiming to be from Microsoft Teams support, offering to fix the problem.
The caller asks the employee to install remote desktop software, such as AnyDesk, or to use Windows Quick Assist. Once access is granted, the attacker can move through the network, harvest credentials, and deploy ransomware at a time of their choosing.
The Teams Variation
The same attack has also been carried out via Microsoft Teams messages rather than phone calls. Attackers set up Teams accounts using usernames such as “help desk” and domains designed to look like internal Microsoft support accounts. They message employees directly, requesting device access to resolve a fabricated issue.
Because the message arrives through Teams and the account name looks plausible, employees who have not been briefed on this technique may not question it. The access request feels routine.
How to Protect Your Business
Brief your team
Every member of staff should understand that legitimate IT support does not contact them uninvited to request remote access. Any call or message offering to fix a problem they did not report should prompt a call to your actual IT support provider to verify, before any action is taken.
Restrict external Teams contacts
Microsoft Teams can be configured to only allow external chats from trusted domains. This prevents attackers from reaching your staff through fake external Teams accounts. Your IT administrator or managed IT provider can apply this setting.
Control remote access tools
Limit which remote access tools can be installed on business devices, and require IT authorisation before any remote session is established. If staff do not have administrative rights to install software, the attacker’s most common tactic is blocked immediately.
Enable Teams chat logging
Logging Teams conversations helps identify suspicious contact attempts and provides an audit trail if an incident occurs. This is a straightforward setting to enable and costs nothing to maintain.
The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.