A Microsoft Teams IT support scam can look remarkably normal.
A message appears in Teams. Someone claiming to be from IT says your account needs verification, your spam filter needs an update, or there is a problem with your computer. They offer to help. Then they ask you to share your screen, approve remote control, or open a legitimate remote-support application.
The dangerous part is that almost everything you see may be real.
Microsoft Teams is real.
The remote-support software is real.
PowerShell is real.
The person offering to help is not.
On September 2, 2026, Microsoft Threat Intelligence reported an active campaign in which attackers impersonate IT and help-desk personnel through Microsoft Teams. Their objective is to convince employees to voluntarily give them remote control of a business computer. Once that happens, Microsoft says attackers can install malware, perform network reconnaissance, capture screenshots, and move toward other systems inside the organization.
For small businesses, there is an important lesson:
Your employees need to know how to verify IT support before they give anyone control of a computer.
How Are Hackers Impersonating IT Support in Microsoft Teams?
The attack begins with social engineering rather than a technical exploit.
According to Microsoft, the attacker contacts an employee through Microsoft Teams while operating from an external organization or tenant.
The attacker may pretend to be:
- Internal IT support
- A help-desk technician
- Microsoft support
- A security administrator
- Someone fixing a spam filter
- Someone performing an account verification
- Someone preventing an account from being disabled
The request is designed to sound routine.
Microsoft observed examples involving supposed Microsoft security updates, spam-filter updates, account verification, and account-deactivation warnings.
That is what makes this attack effective.
Employees already expect IT teams to occasionally contact them about computer problems.
Is This a Microsoft Teams Vulnerability?
No.
That distinction matters.
Microsoft says this campaign does not depend on exploiting a vulnerability in Microsoft Teams.
Instead, attackers abuse legitimate collaboration features and persuade employees to ignore or bypass warnings that identify an external contact.
Teams may show that the person comes from outside your organization.
The employee may also receive an Accept or Block prompt.
However, social engineering is designed to convince the employee that those warnings are harmless.
The attacker does not necessarily break through the security control.
They convince the employee to step around it.
What Happens After the Employee Responds?
The attacker moves from conversation to remote access.
Microsoft observed attackers asking victims to approve a Request Control prompt during Teams screen sharing.
In other cases, the attacker tells the employee to open Microsoft Quick Assist and provide the connection information needed to start a remote session.
Quick Assist itself is a legitimate Microsoft remote-support tool.
Businesses and IT professionals use tools like it every day.
The problem is not the tool.
The problem is who receives access.
Once remote control is granted, the employee has effectively handed an outside person access to the computer.
What Can the Attacker Do With Remote Access?
This is where the situation can escalate quickly.
Microsoft observed attackers using PowerShell during the remote session to download a malicious MSI installer.
That package could then install additional components that provide persistent command execution.
Microsoft also observed attackers performing extensive computer and Active Directory reconnaissance. They searched for systems, identified servers, captured screenshots, and attempted to move deeper into the organization’s network using legitimate Windows administrative tools.
Microsoft warns that this type of activity can precede:
- Data theft
- Credential theft
- Extortion
- Ransomware
- Security-control tampering
- Access to high-value servers
- Broader network compromise
One fake support conversation can therefore become much more than a problem on one employee’s computer.
Why Fake IT Support Is So Convincing
Many phishing attacks contain an obvious disconnect.
A bank you do not use sends you an email.
A package you did not order supposedly cannot be delivered.
A stranger asks you to open an unusual attachment.
Fake IT support is different.
Employees expect IT technicians to:
- Ask questions about their computer
- Request screen sharing
- Troubleshoot problems
- Install software
- Use remote-support tools
- Ask employees to restart applications
- Change settings
Attackers are borrowing a workflow people already trust.
Microsoft has previously investigated similar incidents. In a March 2026 case study, its incident-response team described attackers making persistent Microsoft Teams voice calls while pretending to be IT support. After earlier attempts failed, one employee eventually granted remote access through Quick Assist, leading to compromise of the device.
The technique is not new.
What matters is that attackers continue refining it.
The Most Important Question Employees Should Ask
Businesses can make these attacks harder with one simple habit:
Before giving remote access, verify the technician through a contact method you already trust.
Suppose someone named “John from IT” contacts an employee through Teams.
Do not verify John by asking John whether he is legitimate.
Instead, contact your normal IT provider through the phone number, support portal, email address, or other method your company already uses.
For businesses using a Managed Service Provider, employees should know exactly how that provider normally initiates support.
That procedure should be established before an incident occurs.
Create an IT Support Verification Rule
Small businesses do not need a complicated policy.
A practical rule could be:
Unexpected IT request → Stop → Verify → Grant access only after confirmation
Employees should know:
- Who provides your company’s IT support?
- What email domain do they use?
- What phone number or support portal should employees trust?
- Does the provider ever initiate unsolicited remote sessions?
- How can employees verify a technician’s identity?
- Who should employees call when something feels unusual?
Microsoft recommends organizations establish internal help-desk authentication procedures and verify unsolicited support contacts through known channels before granting remote access.
Watch for These Microsoft Teams IT Support Scam Warning Signs
An employee should become cautious when an unexpected Teams contact:
- Claims an account will be disabled immediately
- Says a security update must happen right now
- Requests remote control without a previous support ticket
- Comes from an external Teams account
- Asks the employee to ignore an external-user warning
- Requests a Quick Assist code
- Pressures the employee not to contact anyone else
- Starts running PowerShell or Command Prompt unexpectedly
- Requests administrator privileges
- Says normal verification procedures will take too long
None of these signs alone proves the person is malicious.
However, they are reasons to verify the request independently.
What Should You Do If You Already Granted Access?
If you believe you may have given remote access to a fake technician, contact your real IT provider or cybersecurity professional immediately.
Do not assume that ending the Teams conversation solves the problem.
If an attacker gained remote access, they may already have:
- Installed malware
- Created persistence
- Captured credentials
- Viewed sensitive information
- Taken screenshots
- Identified network resources
- Established another method of access
Microsoft recommends investigating affected devices and looking for associated activity across endpoints, identities, collaboration platforms, and remote-management tools.
For an employee, the appropriate response is simpler:
Stop working on the device and call IT.
Do not delete files or attempt to clean up evidence unless instructed to do so.
Small Businesses Have an Advantage: Everyone Can Know the Rule
Large organizations may have thousands of employees, several help desks, multiple offices, and numerous outside vendors.
A small business often has a simpler environment.
That can be an advantage.
If ten employees know:
“Our IT provider is SofTouch Systems, and this is how we verify them,”
an attacker pretending to be random “Microsoft IT Support” has a much harder job.
Small businesses should turn their size into a security strength.
Make support procedures predictable, verification easy, and make reporting suspicious activity normal.
Technical Protection Still Matters
Employee education should not carry the entire burden.
Microsoft recommends organizations also restrict Teams external access where appropriate and use layered identity, endpoint, and collaboration security controls.
For a small business, practical protections can include:
- Managed endpoint protection
- 24/7 system monitoring
- Microsoft 365 security configuration
- Strong passwords
- Multi-factor authentication
- Limited administrator privileges
- Patch management
- Secure backups
- Employee cybersecurity training
- Controlled remote-support procedures
No individual layer makes a company immune.
Together, they make the attack more difficult and improve the chances of detecting trouble early.
The Real Security Problem Is Trust
This Microsoft Teams campaign teaches a larger cybersecurity lesson.
Attackers increasingly use legitimate tools because legitimate tools look safe.
Microsoft Teams.
Quick Assist.
PowerShell.
Remote-management software.
Cloud storage.
None of these technologies is inherently suspicious.
Therefore, employees cannot judge security only by asking:
“Does this program look legitimate?”
They also need to ask:
“Is this person supposed to have access?”
That is a much better security question.
FAQ
Yes. Microsoft Teams supports communication with external organizations when external access is enabled. Attackers can abuse this capability to contact employees while pretending to represent IT or another trusted organization.
No. Microsoft says the campaign abuses legitimate Teams collaboration features and social engineering rather than exploiting a Teams vulnerability.
Quick Assist is a legitimate remote-support tool. The danger occurs when an employee gives remote access to someone whose identity has not been verified.
Verify unexpected support requests through a known company contact method. Call your normal IT provider, use the established help-desk number, or check the existing support ticket before granting access.
Legitimate IT providers commonly use remote-support technology. The important distinction is whether the support session is expected and whether the technician’s identity has been verified.
Contact your real IT or cybersecurity provider immediately. The computer should be investigated for malware, persistent access, credential exposure, and other suspicious activity.
Know Who Is Behind the Screen Before You Hand Over Control
Modern cyberattacks do not always begin with a malicious attachment.
Sometimes the attacker simply asks for permission.
That makes clear IT support procedures part of cybersecurity.
Employees should know who provides support, how technicians normally contact them, and how to verify an unexpected request before granting remote access.
A thirty-second verification call can be much easier than recovering from a compromised business network.
Make IT Support Easy to Verify
SofTouch Systems provides practical, managed IT support for small Texas businesses. That means your employees can know who supports their technology and where to turn when an unexpected security message, Teams call, or remote-support request appears.
If you are unsure whether your current remote-support procedures, Microsoft 365 settings, or employee security practices are strong enough, start with a free 15-minute IT security check.
We can help you identify practical gaps before an attacker pretending to be “IT Support” finds them first.
Schedule your free IT security check with SofTouch Systems.
Discover more from SofTouch Systems
Subscribe to get the latest posts sent to your email.
