A Microsoft Teams call is not proof that the caller is IT.
A familiar Teams call can become an attacker's remote session. Verify the person before granting access.
Read articleResearch and practical guidance for caller verification, account recovery, enrollment, and other sensitive identity operations.
A familiar Teams call can become an attacker's remote session. Verify the person before granting access.
Read articleA caller knowing personal details does not prove that the person on the line controls an organization-managed authenticator.
Read articleAuthentication factors help establish account control. Verified ID lets an employee present trusted identity evidence when a workflow needs to verify who they are.
Read articleMandiant says the callers reach personal phones, spoof helpdesk numbers, and use urgent passkey or MFA changes to move employees into attacker-controlled flows.
Read articleA real prompt, a Microsoft Teams message, or Microsoft-hosted infrastructure can still be part of an attacker-directed support interaction.
Read articleAn inbox flood makes the employee want help. Attackers exploit that moment by impersonating IT and offering remote support.
Read articleA request to update a passkey can be the pretext for device-code phishing. A real sign-in page does not verify the IT caller.
Read articleEmployees should not have to inspect a script to decide whether the person asking them to run it is really IT.
Read articleProvider permissions determine who can unlock an account. They do not verify the employee asking for that action on the phone.
Read article