Fake IT Calls: How Executives Are Being Scammed Out of Microsoft 365 Logins
Cybercriminals are sharpening their tactics, and this time they're aiming at the top. Recent reports show a wave of fake IT support calls targeting executives, with the goal of stealing Microsoft 365 credentials and then using that access to extort money.
The scam works like this: you receive a phone call from someone claiming to be from your IT department or a trusted technology vendor. They might say there's an unusual login attempt on your email, a security breach, or a routine maintenance issue. The caller often already knows your name, your job title, and even your manager's name—information easily found on LinkedIn or company websites.
To “fix” the problem, they'll ask for your password or a one-time verification code. Once you provide it, they're in. They can read your emails, download sensitive attachments, and then threaten to leak everything unless you pay a ransom.
It's a form of social engineering that preys on urgency and authority. Executives are busy and may not have time to second-guess a caller who seems legitimate. But here's the hard truth: your real IT team will never ask for your password or a one-time code over the phone.
How to protect yourself:
- Hang up. Politely end any call where someone asks for your login details.
- Call back on a trusted number. Look up your IT department's official extension or email, not one the caller gives you.
- Turn on multi-factor authentication. Even if your password is stolen, a second factor like an app code or biometric scan keeps the criminal out.
- Report it. If you suspect a scam, contact your IT team and Action Fraud immediately. Don't pay, and don't be embarrassed—these scams are designed to fool even the most cautious people.
Remember, it's always better to be rude and hang up than to lose your company's data. Stay alert, stay safe.
