📝 Show notes
CyberAware Daily — 2026-09-08
- Fake IT support calls are now targeting executives to steal Microsoft 365 logins and extort money.
- Real IT teams never ask for passwords or verification codes over the phone.
- If you get a suspicious call, hang up and call your IT department on a known, trusted number.
- Turn on multi-factor authentication to stop stolen passwords being used.
- If you've been scammed, report it to Action Fraud and your IT team immediately—don't pay the criminals.
More at https://cyberawareuk.co.uk
📄 Full transcript
Morning, Alex. Today we're doing a proper deep dive into one scam type and honestly it's one
that's been making the rounds in offices up and down the country. Oh brilliant. So what are we
digging into today? Fake IT support calls. But not the usual so your computer has a virus nonsense.
This is targeted at top executives and it's about stealing their Microsoft 365 logins and
then holding their data to ransom. Right. So it's not just the office junior getting a scary pop-up.
They're going after the big fish. Exactly. The news is that criminals are phoning executives
pretending to be from their own IT team or a trusted tech supplier. They'll say there's a
problem with their email account and they need their password or a verification code right now
to fix it. And busy execs just hand it over don't they? They do especially when the caller already
knows their name, their department, maybe even their boss's name. It sounds convincing. So what
happens once they've got that login? They're in. They can read every email, download every attachment
and then they threaten to leak it all unless they get paid. It's extortion, pure and simple.
That's terrifying. So how does the average person spot this?
First rule, your real IT team will never ask for your password or a one-time code over the phone.
Never. If someone calls and asks for that, hang up.
Even if they sound legit.
Especially if they sound legit. Hang up, then call your IT department using a number you know is real,
like from your staff handbook or the company website. Don't use a number the caller gives you.
And what about the data part? If they've already got access, what then?
That's where the second line of defense comes in. Turn on multi-factor authentication if you haven't
already. Even if they steal your password, they can't get in without that second code.
And what if you've already been caught out?
Don't panic. Don't pay. Report it straight to your IT team and to action fraud.
The sooner they know, the sooner they can lock things down and potentially stop the leak.
So the takeaway today is?
Treat any unsolicited call asking for login details as a scam.
Hang up, call back on a trusted number, and if in doubt, don't give anything out.
Your data is worth more than a moment of politeness.
Thanks, bully. That's a solid reminder for all of us, not just the XX.
And that's your Cyber Aware UK Deep Dive for Tuesday.
Stay sharp, stay suspicious, and always verify before you hand over anything.