All systems operational · Ormskirk, North West England

Beware of That IT Support Call

Scammers are flooding inboxes with spam then calling to offer IT support, tricking employees into granting remote access. The same attack is also being run via fake Microsoft Teams accounts. Here is how it works and how to stop it.

The Scam That Starts With a Flooded Inbox

A cyber crime technique is circulating that uses a combination of email flooding and fake IT support calls to trick employees into granting remote access to their devices. The attack follows a consistent pattern: first, a staff member’s inbox is flooded with spam emails, making it effectively unusable. Then, shortly after, a call arrives claiming to be from Microsoft Teams support, offering to fix the problem.

The caller asks the employee to install remote desktop software, such as AnyDesk, or to use Windows Quick Assist. Once access is granted, the attacker can move through the network, harvest credentials, and deploy ransomware at a time of their choosing.

The Teams Variation

The same attack has also been carried out via Microsoft Teams messages rather than phone calls. Attackers set up Teams accounts using usernames such as “help desk” and domains designed to look like internal Microsoft support accounts. They message employees directly, requesting device access to resolve a fabricated issue.

Because the message arrives through Teams and the account name looks plausible, employees who have not been briefed on this technique may not question it. The access request feels routine.

Key point: Neither Microsoft, nor any legitimate IT provider, will initiate an unsolicited contact to request remote access to your device. Any unexpected call or Teams message claiming to offer this kind of support should be treated as suspicious.

How to Protect Your Business

Brief your team

Every member of staff should understand that legitimate IT support does not contact them uninvited to request remote access. Any call or message offering to fix a problem they did not report should prompt a call to your actual IT support provider to verify, before any action is taken.

Restrict external Teams contacts

Microsoft Teams can be configured to only allow external chats from trusted domains. This prevents attackers from reaching your staff through fake external Teams accounts. Your IT administrator or managed IT provider can apply this setting.

Control remote access tools

Limit which remote access tools can be installed on business devices, and require IT authorisation before any remote session is established. If staff do not have administrative rights to install software, the attacker’s most common tactic is blocked immediately.

Enable Teams chat logging

Logging Teams conversations helps identify suspicious contact attempts and provides an audit trail if an incident occurs. This is a straightforward setting to enable and costs nothing to maintain.

B
Blowfish Technology

The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.