Fake IT support calls in Microsoft Teams can end in ransomware
THE BRIEF
Once connected, the intruders used PowerShell and remote-management tools to establish access, steal data and move toward extortion. Sophos observed Chaos ransomware deployed in at least three cases. In one incident, only 17 hours passed between initial access and ransomware deployment. Targets included services, manufacturing, energy, construction and engineering organizations. The campaign is important because it began through a familiar workplace channel rather than a suspicious email attachment. Sophos assessed the activity as financially motivated, although some techniques resembled earlier state-linked operations. The reporting confirms observed attacks; it does not establish how many attempted contacts succeeded or whether every victim experienced encryption. For affected people, the practical response should follow confirmed notices rather than speculation. Organizations should preserve records, identify responsible owners and communicate clearly about the known scope. Individuals should use official contact channels, review relevant accounts or devices and be cautious of follow-up messages that exploit publicity around the incident.
WHY IT MATTERS
A Teams call can feel more trustworthy than an unexpected email, particularly when the caller knows company terminology or creates urgency around an IT problem. Once an employee grants remote control, ordinary security tools may see an approved support application rather than obvious malware. The result can be data theft, downtime and costly recovery within hours. Managers therefore need authentication procedures for internal support, not just phishing awareness, and staff need a safe way to pause and verify a request without being blamed for delaying work.
WHO SHOULD CARE
Employees, help-desk teams, managers and organizations using Microsoft Teams or remote-support tools should care. The attack depends on normal workplace trust and can move from conversation to ransomware faster than many escalation procedures or approval chains are designed to handle.
WHAT TO DO NOW
- Require employees to verify unexpected support contacts through a known internal number or ticketing portal.
- Restrict Quick Assist and other remote-control tools to approved support teams and managed devices.
- Block external Teams chats or calls where the business does not need them.
- Alert on unusual PowerShell, remote-support and administrator activity following Teams contacts.
- Rehearse how staff should disconnect and report a suspicious remote-support session immediately.
VERIFICATION NOTE
Verified against Cybersecurity Dive’s account and Sophos telemetry cited in the report. The observed Teams impersonation, remote-support use and three Chaos ransomware deployments are attributed to Sophos. The exact size of the campaign and total victim count were not public. Sophos assessed the actor as criminal rather than state-sponsored, so attribution remains an analytical judgment.