You Have Cyber Insurance. That Doesn’t Mean You’re Covered.

Imagine receiving a phone call from someone claiming to be from your IT team. They know your name, your job role and even mention a problem with your account. They ask you to approve a multi-factor authentication (MFA) request or install remote support software so they can “fix” the issue.

It sounds convincing. That’s exactly why it works.

Threat actors are increasingly impersonating IT support teams to gain access to organisations. Whether through phone calls, emails or even face-to-face interactions, these attacks are designed to exploit trust rather than technology. As organisations strengthen their cyber defences, attackers are shifting their focus to people.

 

Why help desk impersonation is so effective

Employees are used to interacting with their IT department. When someone claims to be calling from the help desk, most people naturally want to cooperate. Attackers take advantage of this trust. They often gather information from company websites, LinkedIn profiles or previous data breaches to make their approach appear genuine. Knowing an employee’s name, department or manager can make the conversation feel legitimate.

The attacker then creates a sense of urgency. They might claim your account has been compromised, your laptop is infected or suspicious activity has been detected. Their goal is to pressure you into acting before you have time to question the request.

According to the 2025 Verizon Data Breach Investigations Report, compromised credentials were involved in 22% of security breaches, demonstrating how attackers continue to rely on stealing legitimate access rather than exploiting technical vulnerabilities. The report also found that the human element remains involved in the majority of breaches, reinforcing the importance of security awareness alongside technical controls.

 

This isn’t just happening online

Help desk impersonation is no longer a theoretical threat. Following several high-profile cyber attacks against UK retailers in 2025, including Marks & Spencer and Co-op, the National Cyber Security Centre (NCSC) warned organisations that attackers were increasingly using social engineering techniques to impersonate employees and IT support staff. Rather than breaking through sophisticated security controls, criminals simply convinced people to reset passwords, provide authentication codes or grant remote access.

You can read the NCSC’s guidance on phishing and scams here. These attacks demonstrate an important lesson. Sometimes the easiest way into an organisation isn’t by exploiting software, it’s by exploiting trust.

 

It’s not just phone calls anymore

While telephone scams remain common, attackers are constantly adapting their methods. Some now send Microsoft Teams messages pretending to be internal IT support. Others use convincing phishing emails that direct employees to fake login pages or ask them to install remote assistance software. Microsoft has warned of campaigns where attackers contact employees through Microsoft Teams before persuading them to launch Quick Assist, Microsoft’s legitimate remote support tool. Once access is granted, attackers can begin moving through the organisation using genuine administrative software, making their activity much harder to detect.

Attackers have even been known to impersonate contractors or IT engineers in person, arriving at offices wearing branded clothing or carrying equipment to appear authentic. Regardless of the method, the objective is always the same: persuade someone to bypass normal security procedures.

 

How can organisations reduce the risk?

Technology plays an important role, but it cannot prevent every social engineering attack. Employees should understand that legitimate IT teams will never ask them to share passwords, disclose MFA codes or approve unexpected authentication requests. It’s equally important to verify any unexpected contact. If someone claims to be from IT, end the conversation and contact your internal help desk using your organisation’s official support channels rather than the details provided by the caller or message.

Clear support processes also make a significant difference. Employees should know exactly how IT requests are raised, which remote support tools are approved and how technicians identify themselves before any work begins. Regular security awareness training helps reinforce these behaviours. The more familiar employees become with modern social engineering tactics, the more likely they are to recognise suspicious activity before it leads to a compromise.

 

Think before you trust

Cyber criminals are becoming increasingly sophisticated. They don’t always need malware or software vulnerabilities to breach an organisation. Sometimes, all they need is one convincing conversation.

Microsoft’s latest Cyber Signals report highlights the scale of the challenge, revealing that between April 2024 and April 2025 the company blocked around 1.6 million bot sign-up attempts every hour and prevented $4 billion worth of fraud attempts across its platforms. While technology continues to evolve, one simple habit remains one of the strongest defences against social engineering: pause and verify.

If someone unexpectedly contacts you claiming to be from IT, don’t feel pressured to act immediately. Take a moment to confirm their identity using an official communication channel. That one decision could prevent a cyber attack before it even begins.

Share the Post: