Let mefix that for you.
Your inbox suddenly fills with hundreds of messages. Then someone from “IT” calls and says they already know what is wrong.
The software in this simulation is legitimate. The person asking you to use it is not.
Your inbox suddenly fills with hundreds of messages. Then someone from “IT” calls and says they already know what is wrong.
The software in this simulation is legitimate. The person asking you to use it is not.
You work in operations at Harborline Systems. It is 9:42 on a Wednesday morning.
Your inbox has become almost unusable. Order confirmations, mailing-list subscriptions and account-registration emails are arriving faster than you can delete them.
While you are trying to understand what happened, an incoming Teams call appears from Harborline Service Desk.
You have not opened a support ticket.
Nothing in the remote-support window needed to be fake. The attacker only needed you to believe the person on the other end belonged there.
A sudden flood of email makes the victim believe something is already wrong and makes normal work difficult.
The fake technician calls while the problem is happening. Their knowledge of the flood feels like proof that they are legitimate.
Quick Assist is a real Microsoft tool. A genuine application window says nothing about who is operating the other side of the session.
The employee enters the code, shares the screen, grants control and approves any later prompts. Each step appears small on its own.
The attacker may use the victim to approve elevation prompts, expose sensitive information or allow additional persistence—all inside an apparently normal support call.
End the contact and reach your service desk through a channel you find yourself. A ticket number, familiar company name, real software and knowledge of your problem can all be part of the story.
Do not open a remote session because an unsolicited caller tells you to. The code connects you to the person who generated it.
Use your internal helpdesk portal, a known phone number or a new conversation started from the company directory. Do not rely on details supplied during the suspicious contact.
Close the remote-support session or disconnect the device from the network, then contact security. Do not continue because you have already allowed the first step.
Security may need to review the device, revoke sessions and identify other employees receiving the same call.