<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Social engineering → Guard IQ | IT Support &amp; Cybersecurity Services in North West London</title>
	<atom:link href="https://guardiq.co.uk/tag/social-engineering/feed/" rel="self" type="application/rss+xml" />
	<link>https://guardiq.co.uk</link>
	<description>Reliable IT &#38; Cybersecurity for Local Businesses</description>
	<lastBuildDate>Tue, 08 Sep 2026 09:48:03 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://guardiq.co.uk/wp-content/uploads/2025/10/cropped-ext-custom-logo-1760826610189-1-32x32.webp</url>
	<title>Social engineering → Guard IQ | IT Support &amp; Cybersecurity Services in North West London</title>
	<link>https://guardiq.co.uk</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Someone calls claiming to be your IT support. How does your team check?</title>
		<link>https://guardiq.co.uk/teams-helpdesk-scam/</link>
		
		<dc:creator><![CDATA[Shailesh Bhudia]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 09:46:01 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Cyber Essentials]]></category>
		<category><![CDATA[Managed IT Support]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[Microsoft 365]]></category>
		<category><![CDATA[Microsoft Teams]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Remote access]]></category>
		<category><![CDATA[SME cybersecurity]]></category>
		<category><![CDATA[Social engineering]]></category>
		<guid isPermaLink="false">https://guardiq.co.uk/?p=2002</guid>

					<description><![CDATA[<p>Microsoft Threat Intelligence published research on 2 September 2026 describing an attack that starts with a Teams message from someone claiming to be IT support. No malicious attachment. No dodgy link that an email filter can catch. Just a conversation, followed by a request for remote access, which the user grants. It works because it [&#8230;]</p>
<p>The post <a href="https://guardiq.co.uk/teams-helpdesk-scam/">Someone calls claiming to be your IT support. How does your team check?</a> first appeared on <a href="https://guardiq.co.uk">Guard IQ | IT Support & Cybersecurity Services in North West London</a>.</p>]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">Microsoft Threat Intelligence published research on 2 September 2026 describing an attack that starts with a Teams message from someone claiming to be IT support. No malicious attachment. No dodgy link that <a href="https://guardiq.co.uk/email-security-check/">an email filter</a> can catch. Just a conversation, followed by a request for remote access, which the user grants.</p>



<p class="wp-block-paragraph">It works because it looks like a Tuesday morning.</p>



<p class="wp-block-paragraph">If your staff have ever been contacted by an IT provider they did not expect, and did anything other than hang up and call back on a number they already had, this one is worth ten minutes of your time.</p>



<h2 class="wp-block-heading">What actually happens</h2>



<p class="wp-block-paragraph">Microsoft set out the chain in detail. The short version:</p>



<ol class="wp-block-list">
<li><strong>First contact through Teams.</strong> The attacker operates from an external Microsoft 365 tenant and starts a chat or call posing as internal IT or helpdesk. Common pretexts include a security update, a spam filter update, account verification, or a warning that an account is about to be deactivated. Sometimes they phone as well, so the instructions never appear in the chat log.</li>



<li><strong>The user grants remote control.</strong> They are talked through approving a &#8220;request control&#8221; prompt during a Teams screen share, or opening Quick Assist and reading back the connection code. From the user&#8217;s side this feels exactly like being helped.</li>



<li><strong>Software gets installed silently.</strong> Inside that session the attacker runs PowerShell to pull down an installer package from cloud storage and installs it with the interface suppressed. The user sees nothing. The files are named things like &#8220;devfix&#8221; and &#8220;Hotfix&#8221; to fit the helpdesk story.</li>



<li><strong>The attacker sets up camp.</strong> The package stages a legitimate, signed JavaScript runtime downloaded from the official source, then uses it to run an encrypted implant. Because every component is legitimate and signed, tooling that only looks for unsigned executables has nothing to flag. Persistence is set up under an update-themed name so it restarts every time the user logs in.</li>



<li><strong>They look around, then move.</strong> Screenshots of the desktop are captured periodically. The attacker enumerates domain accounts and servers, then pivots across the network toward domain controllers and certificate authorities.</li>
</ol>



<p class="wp-block-paragraph">Microsoft is direct about what that pattern usually precedes: data theft, extortion, ransomware.</p>



<p class="wp-block-paragraph">The part worth sitting with is that nothing here was hacked. Teams shows external contact warnings, an accept or block prompt, and phishing indicators. The whole attack depends on persuading one person to click past them.</p>



<h2 class="wp-block-heading">Why this is a small business problem, not just a large one</h2>



<p class="wp-block-paragraph">It is easy to read &#8220;domain controllers&#8221; and &#8220;certificate authorities&#8221; and file this under enterprise. Two reasons not to.</p>



<p class="wp-block-paragraph"><strong>First, the entry point is the same everywhere.</strong> A 12-person care agency and a 12,000-person bank both run Teams, both have someone who answers messages, and both have staff who have been trained for years that the helpful thing to do is cooperate with IT.</p>



<p class="wp-block-paragraph"><strong>Second, smaller organisations are easier to impersonate.</strong> In a large company, an unexpected message from &#8220;IT&#8221; is odd because nobody knows the IT team anyway, so the culture is to check. In a 10-person firm that <a href="https://guardiq.co.uk/managed-it-support-london/">outsources IT</a>, staff are used to a named external person contacting them from outside the organisation. That is the normal state. The attacker is not fighting your culture. They are using it.</p>



<p class="wp-block-paragraph">If you outsource IT, external contact from IT is not a red flag for your staff. It is Tuesday. That is the gap.</p>



<h2 class="wp-block-heading">Four controls that actually close this</h2>



<p class="wp-block-paragraph">Microsoft&#8217;s guidance runs long. Four things carry most of the weight for a small regulated firm.</p>



<p class="wp-block-paragraph"><strong>1. A verification rule your staff can follow under pressure.</strong></p>



<p class="wp-block-paragraph">Not awareness training in general. One rule, written down, that survives someone sounding urgent and authoritative:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">Nobody from IT will ever contact you out of the blue and ask for remote access. If it happens, end the conversation and call the support number yourself. You will never be in trouble for checking.</p>
</blockquote>



<p class="wp-block-paragraph">That last sentence matters more than the rest of it. Most people who fall for this had a doubt and pushed past it, because raising it felt rude. Give them explicit permission and the rule works. Without it, it does not.</p>



<p class="wp-block-paragraph">If you want to see how your own team would do, our <a href="https://guardiq.co.uk/spot-the-phish-quiz/">Spot the Phish quiz</a> takes two minutes and is a useful thing to put in front of staff at a team meeting.</p>



<p class="wp-block-paragraph"><strong>2. Restrict who can reach your staff in Teams.</strong></p>



<p class="wp-block-paragraph">Teams external access can be limited to trusted domains. Most small firms leave it open to the entire world by default and have no idea. If your staff only ever collaborate with a handful of outside organisations, the setting should reflect that. It is a configuration change, not a purchase.</p>



<p class="wp-block-paragraph"><strong>3. Phishing-resistant MFA and Conditional Access.</strong></p>



<p class="wp-block-paragraph">MFA on its own does not stop someone who has been handed live control of a logged-in machine. Conditional Access, requiring a managed and compliant device, limits what that session is worth. This one also has a compliance edge: under Cyber Essentials Requirements for IT Infrastructure v3.3, effective 27 April 2026, MFA is mandatory on every cloud service where it is available, including where it costs extra. Not enabling it is an automatic fail. If you are certifying or renewing this year, our <a href="https://guardiq.co.uk/cyber-essentials-readiness-checker/">Cyber Essentials readiness checker</a> will tell you where you currently stand.</p>



<p class="wp-block-paragraph"><strong>4. Control which remote support tools can run at all.</strong></p>



<p class="wp-block-paragraph">Quick Assist and general-purpose remote support tools are the delivery mechanism here. If your IT provider uses one specific tool, the others should not be usable on your machines. Restricting remote assistance software removes the attacker&#8217;s easiest route, and it takes an afternoon.</p>



<h2 class="wp-block-heading">The awkward question for anyone who outsources IT</h2>



<p class="wp-block-paragraph">This attack impersonates your IT provider. So ask us, or whoever supports you:</p>



<ul class="wp-block-list">
<li>Which channels will you ever contact my staff on, and what will you never ask them to do?</li>



<li>What number should my team call to verify that a request came from you?</li>



<li>Which remote support tool do you use, and are the others blocked on our devices?</li>



<li>Is Teams external access restricted on our tenant, or open to anyone?</li>



<li>If someone did grant a stranger remote access on Monday morning, what would tell you, and how fast?</li>
</ul>



<p class="wp-block-paragraph">A provider who cannot answer the last one has a monitoring gap, and it is the question that decides whether this is an incident or a disaster.</p>



<p class="wp-block-paragraph">For our part, Guard IQ contacts clients through three channels only: our support email, our office number on 020 8537 8167, and our published WhatsApp number. Anything else claiming to be us is not us. If in doubt, hang up and call the office. We would rather take a hundred unnecessary calls than one that came too late.</p>



<h2 class="wp-block-heading">If you want a second opinion</h2>



<p class="wp-block-paragraph">We work with <a href="https://guardiq.co.uk/healthcare/">care and healthcare providers</a>, <a href="https://guardiq.co.uk/solicitors/">law firms</a>, <a href="https://guardiq.co.uk/accountants/">accountancy practices</a> and other regulated businesses across <a href="https://guardiq.co.uk/it-support-north-west-london/">North West London</a> and the Home Counties, where a breach is not just downtime but a reportable incident with a regulator attached.</p>



<p class="wp-block-paragraph">If you are not sure whether your Teams external access is locked down, whether Conditional Access is doing anything, or what your staff would actually do if a convincing stranger asked for remote control, <a href="https://guardiq.co.uk/#contact">book a free consultation</a> or call 020 8537 8167.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><em>Source: Microsoft Security Blog, &#8220;Impersonating IT support: how threat actors turn a remote session into enterprise-wide access&#8221;, 2 September 2026.</em></p><p>The post <a href="https://guardiq.co.uk/teams-helpdesk-scam/">Someone calls claiming to be your IT support. How does your team check?</a> first appeared on <a href="https://guardiq.co.uk">Guard IQ | IT Support & Cybersecurity Services in North West London</a>.</p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
