{"id":5197,"date":"2024-12-28T12:06:43","date_gmt":"2024-12-28T12:06:43","guid":{"rendered":"https:\/\/sysdojo.com\/?p=5197"},"modified":"2024-12-28T12:06:45","modified_gmt":"2024-12-28T12:06:45","slug":"beware-that-support-call-it-could-be-a-ransomware-scam","status":"publish","type":"post","link":"https:\/\/sysdojo.com\/corp\/beware-that-support-call-it-could-be-a-ransomware-scam\/","title":{"rendered":"Beware that &#8220;support call&#8221; \u2013 it could be a ransomware scam"},"content":{"rendered":"\n<p>If you get a call claiming to be from Microsoft Teams support, think twice before doing what they ask.<\/p>\n\n\n\n<p>There\u2019s a new trend for scammers to pose as \u201chelp desk\u201d staff, with the aim of tricking employees into letting them take over their devices. This is part of a larger ransomware attack, where you\u2019ll be denied access to your business data unless you make a hefty payment to get it back.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/sysdojo.com\/corp\/wp-content\/uploads\/2024\/12\/USwc2024-12-30-BlogarticleLinkedInnewsletterimage-1024x576.jpg\" alt=\"\" class=\"wp-image-5198\" srcset=\"https:\/\/sysdojo.com\/corp\/wp-content\/uploads\/2024\/12\/USwc2024-12-30-BlogarticleLinkedInnewsletterimage-1024x576.jpg 1024w, https:\/\/sysdojo.com\/corp\/wp-content\/uploads\/2024\/12\/USwc2024-12-30-BlogarticleLinkedInnewsletterimage-300x169.jpg 300w, https:\/\/sysdojo.com\/corp\/wp-content\/uploads\/2024\/12\/USwc2024-12-30-BlogarticleLinkedInnewsletterimage-768x432.jpg 768w, https:\/\/sysdojo.com\/corp\/wp-content\/uploads\/2024\/12\/USwc2024-12-30-BlogarticleLinkedInnewsletterimage-1536x864.jpg 1536w, https:\/\/sysdojo.com\/corp\/wp-content\/uploads\/2024\/12\/USwc2024-12-30-BlogarticleLinkedInnewsletterimage.jpg 1920w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Recently, a notorious cybercrime group has taken this scam to a new level. First, they\u2019ll flood an employee\u2019s inbox with so much spam that it becomes unusable. Then they swoop in with a phone call, pretending to be from IT support, offering to \u201cfix\u201d the problem.<\/p>\n\n\n\n<figure class=\"wp-block-video\"><video height=\"1080\" style=\"aspect-ratio: 1920 \/ 1080;\" width=\"1920\" controls src=\"https:\/\/sysdojo.com\/corp\/wp-content\/uploads\/2024\/12\/USwc2024-12-30-Techupdatevideoreadytouse.mp4\"><\/video><\/figure>\n\n\n\n<p>They may ask your employee to install remote desktop software like AnyDesk or use built-in tools like Windows Quick Assist. Once they have access, they can move around your network, collect sensitive data, and launch ransomware on your devices.<\/p>\n\n\n\n<p>Be warned \u2013 they don\u2019t only reach out over the phone. They\u2019ve also started setting up Teams accounts to make employees think they\u2019re part of IT support.<\/p>\n\n\n\n<p>They do this by choosing usernames like \u201cHelp Desk\u201d and using fake Microsoft tenant domains such as \u201csecurityadminhelper.onmicrosoft .com.\u201d Then they send one-to-one messages to employees, saying they need access to their device.<\/p>\n\n\n\n<p><a href=\"https:\/\/sysdojo.com\/corp\/ransomware-threats-are-surging-heres-how-to-protect-your-business\/\" data-type=\"link\" data-id=\"https:\/\/sysdojo.com\/corp\/ransomware-threats-are-surging-heres-how-to-protect-your-business\/\">Ransomware attacks<\/a> are serious business. Along with locking you out of your data, they can also shut down your operations, disrupt customer service, and potentially leak confidential information.<\/p>\n\n\n\n<p>Recovering from a ransomware attack can be expensive, both in terms of paying the ransom and dealing with the aftermath. It can cause loss of revenue, damage your reputation, and it could even have legal consequences.<\/p>\n\n\n\n<p>Even beyond financial losses, these attacks erode trust among employees and customers. Clients may hesitate to share sensitive information with your company, fearing it could fall into the wrong hands. Employees may also feel unsafe or uncertain about their digital workspace, reducing morale and productivity.<\/p>\n\n\n\n<p>One way to mitigate this risk is to conduct regular phishing simulations and cybersecurity training. Employees need to recognize the signs of a scam, such as unexpected requests for credentials or pushy language demanding immediate action.<\/p>\n\n\n\n<p>The more your team understands these threats, the harder it is for scammers to succeed.<\/p>\n\n\n\n<p>In addition to training, consider implementing advanced security measures like <a href=\"https:\/\/sysdojo.com\/corp\/dont-sleep-on-mfa-a-simple-and-effective-security-booster\/\" data-type=\"link\" data-id=\"https:\/\/sysdojo.com\/corp\/dont-sleep-on-mfa-a-simple-and-effective-security-booster\/\">multi-factor authentication<\/a> (MFA) and endpoint detection tools.<\/p>\n\n\n\n<p>These solutions can significantly reduce the chances of unauthorized access, even if an employee accidentally falls for a scam. Regular audits of your IT systems can also help identify and fix vulnerabilities before they\u2019re exploited.<\/p>\n\n\n\n<p>Make your team aware of this <a href=\"https:\/\/support.microsoft.com\/en-us\/windows\/protect-yourself-from-tech-support-scams-2ebf91bd-f94c-2a8a-e541-f5c800d18435\" data-type=\"link\" data-id=\"https:\/\/support.microsoft.com\/en-us\/windows\/protect-yourself-from-tech-support-scams-2ebf91bd-f94c-2a8a-e541-f5c800d18435\" target=\"_blank\" rel=\"noopener\">scam<\/a> and encourage everyone to be cautious with any unsolicited support calls or Teams chats. And make sure everyone knows to check with your actual IT department first, if someone is asking to install software or gain access.<\/p>\n\n\n\n<p>Also, if you use <a href=\"https:\/\/sysdojo.com\/corp\/copilot-is-bringing-another-productivity-boost-to-teams\/\" data-type=\"link\" data-id=\"https:\/\/sysdojo.com\/corp\/copilot-is-bringing-another-productivity-boost-to-teams\/\">Microsoft Teams<\/a> in your business, make sure it\u2019s set up securely. Only allow external chats from trusted domains, and make sure chat logging is enabled. If you want extra help safeguarding your setup, we can do that. Get in touch.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Would your employees give an unknown caller access to your business devices? But what if they got a Teams chat from someone posing as Microsoft support? Here we tell you all about a new ransomware scam.<\/p>\n","protected":false},"author":3,"featured_media":5198,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[29],"tags":[64,103,55],"class_list":["post-5197","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-microsoft","tag-ransomwarescam","tag-teams"],"_links":{"self":[{"href":"https:\/\/sysdojo.com\/corp\/wp-json\/wp\/v2\/posts\/5197","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sysdojo.com\/corp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sysdojo.com\/corp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sysdojo.com\/corp\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/sysdojo.com\/corp\/wp-json\/wp\/v2\/comments?post=5197"}],"version-history":[{"count":1,"href":"https:\/\/sysdojo.com\/corp\/wp-json\/wp\/v2\/posts\/5197\/revisions"}],"predecessor-version":[{"id":5200,"href":"https:\/\/sysdojo.com\/corp\/wp-json\/wp\/v2\/posts\/5197\/revisions\/5200"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sysdojo.com\/corp\/wp-json\/wp\/v2\/media\/5198"}],"wp:attachment":[{"href":"https:\/\/sysdojo.com\/corp\/wp-json\/wp\/v2\/media?parent=5197"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sysdojo.com\/corp\/wp-json\/wp\/v2\/categories?post=5197"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sysdojo.com\/corp\/wp-json\/wp\/v2\/tags?post=5197"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}