Ransomware Groups Impersonate IT Support on Teams

Help Net Security · Medium sophistication
Last updated August 11, 2026

Dragos reports that ransomware operators are increasingly disrupting industrial production by targeting the business IT systems that support operations, even without touching industrial control systems. The report highlights real-world social engineering where attackers impersonate internal IT on Microsoft Teams to persuade employees to screen-share and install remote access tools, and also notes a separate FBI warning about fake on-site “IT technicians” plugging in USB drives.

Key findings

  • Dragos identified 1,140 ransomware incidents involving industrial organizations in Q2 2026; manufacturing represented 65% (747 incidents).
  • Industrial disruption can occur by taking down enterprise IT systems that support OT (e.g., ERP, identity, virtualization, remote access), even without direct ICS access.
  • Example impact: Mackay Sugar reported an attack that stopped milling and cane haulage at two of three mills; the Gentlemen ransomware group later listed them on its leak site.
  • Social engineering shifted toward interactive impersonation in collaboration tools: attackers posed as internal IT support on Microsoft Teams and used screen sharing to convince employees to install remote access tools (AnyDesk, Quick Assist).
  • Some attackers used lookalike credential-harvesting domains to capture passwords and MFA codes.
  • FBI warning: Silent Ransom Group (Luna Moth) allegedly began sending people into offices posing as IT technicians and connecting USB drives to machines.

Who’s being targeted

  • Commonly targeted roles: All employees, Operations, Engineering, Plant/Production teams, IT helpdesk, Reception/Facilities.
  • Affected industries: Manufacturing, Construction, Equipment manufacturing, Food and beverage, Engineering firms, System integrators, Transportation and logistics.
  • Attack channels: teams, physical.
  • Impersonated: Internal IT support, IT technician.

Awareness takeaways

  • Treat unsolicited Teams “IT support” chats as high-risk and verify via a known helpdesk channel before screen-sharing or installing anything.
  • Do not install remote access/monitoring tools at another person’s request unless it’s part of an approved IT process.
  • Be cautious of lookalike login pages and never enter passwords or MFA codes into sites you didn’t reach through trusted paths.
  • Require visitor verification and prohibit unknown USB devices, social engineering can be in-person, not just online.

Red flags to watch for

  • Unsolicited Teams message claiming to be IT support
  • Pressure to screen-share or install remote access software
  • Instructions to install tools not previously approved/expected by the employee
  • Unscheduled on-site “IT” visit
  • Requests physical access to devices without a work order or verification
  • Use of removable media (USB) on corporate machines
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: a Teams chat pops up, “Hi, this is IT Support. Start a screen-share so we can install our monitoring tool.” Ransomware groups are doing exactly this, posing as internal IT on Teams, then walking people through screen-share to install AnyDesk or Quick Assist and even sending them to fake login pages to steal passwords and MFA codes. Here’s the scary part: they don’t even have to touch industrial controls. Dragos saw over a thousand industrial ransomware incidents in one quarter, just knocking out business IT systems like ERP and identity was enough to stop factories, like a sugar mill that had to halt cane haulage. So if “IT” pings you on Teams out of the blue, don’t screen-share, don’t install anything. Stop, and contact the helpdesk through our official channel to confirm first.

Similar attacks

Fake IT Support Hits Teams to Drop Ransomware

Fake IT Support Hits Teams to Drop Ransomware

Researchers reported a months-long campaign where attackers used Microsoft Teams chats/calls while pretending to be IT/help desk support. Victims were talked into starting remote-control sessions (Quick Assist or RemSupp), after which the attackers used PowerShell to maintain access and, in some…

July 30, 2026
Fake Teams “IT Support” Calls Hijack PCs via Quick Assist

Fake Teams “IT Support” Calls Hijack PCs via Quick Assist

Attackers are calling employees on Microsoft Teams while pretending to be internal IT support, then persuading them to approve a Microsoft Quick Assist remote-control session. Once the employee approves, the attacker can take control of the computer and use PowerShell to install a Go-based backdoor…

July 28, 2026
AiTM Phishing Now #1 Break-In Method for Law Firms

AiTM Phishing Now #1 Break-In Method for Law Firms

A legal-sector threat intel report says adversary-in-the-middle (AiTM) phishing is now the most common way attackers gain initial access to law firms, because it can bypass MFA by stealing valid session cookies. The report highlights deadline-driven lures (fake document/court portal errors) and…

July 31, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Teams Phishing Rises After Tycoon2FA Takedown

Teams Phishing Rises After Tycoon2FA Takedown

Microsoft reported that phishing tied to the Tycoon2FA phishing-as-a-service platform dropped sharply after a disruption, pushing attackers to change tactics rather than stop. The report highlights real campaigns that shifted toward Microsoft Teams-based social engineering, highly automated BEC…

July 24, 2026