When “IT Support” Calls: Inside The Teams Scam Rewriting The Rules Of Workplace Trust

Key takeaways
- Sophos says the STAC4749 campaign has been active since February 2026, targeting dozens of North American organizations—about half in Canada and nearly half in the U.S.—especially in services, manufacturing, energy, and construction.
- Attackers posed as internal IT over Microsoft Teams, used lookalike domains such as scan-security.top and corp-connect.top, and requested remote access through familiar tools like Microsoft Quick Assist and RemSupp; Sophos says 3 calls led to Chaos ransomware, with one victim fully encrypted in under 17 hours.
- The article ties STAC4749 to a broader ransomware-as-a-service model: Sophos assesses the campaign was financially motivated, and MIT Sloan’s Stuart Madnick explains that malware operators and the affiliates making the calls can be separate groups that split proceeds.
- It connects the scam’s success to social-engineering research from Frank Stajano and Paul Wilson at the University of Cambridge, citing their principles that people tend not to question authority and make worse decisions under time pressure—exactly what a two-minute fake IT call exploits.
- Bruce Schneier’s usable-security argument is used to show why blaming employees is ineffective: workers are conditioned to help IT, so defenses should be designed around real behavior rather than relying on one-time reminders to stay vigilant.
- The recommended controls are concrete: verify unsolicited support calls through known contact info, require a second person before granting remote access, restrict Teams interactions from outside the company, keep a short centrally managed list of approved remote-support tools, monitor endpoints and segment networks, and rehearse these scenarios through training and simulations.
The Two-Minute Call
A Microsoft Teams call comes in. The caller ID reads like an internal help desk ticket. The voice on the line sounds patient, professional, and mildly apologetic for the interruption. There’s a system issue, the caller explains, and it needs a quick fix. Could the employee open Quick Assist for a minute? The call lasts about two minutes. Then it ends, and so does the company’s control over that machine.
Sophos has been tracking this campaign since February 2026. Its internal name for it is STAC4749. The group called dozens of organizations across North America. Roughly half were in Canada and nearly half in the United States, concentrated in services, manufacturing, energy, and construction firms. Three of those calls ended in Chaos ransomware, a ransomware-as-a-service operation that encrypts files and threatens to leak stolen data if the ransom isn’t paid. In one case, the time between the first call and fully encrypted files was under seventeen hours.
The attackers built lookalike web addresses with names like scan-security.top and corp-connect.top. They gave themselves ordinary names: Anthony Brooks, Dylan Harper, Ethan Parker. They asked employees for remote access using tools IT departments already rely on, Microsoft Quick Assist and a cloud tool called RemSupp. The request looked routine. That is exactly what made it work.
Attackers have used Microsoft Teams this way before. Black Basta ransomware affiliates ran a similar playbook in 2024, flooding employee inboxes first and then following up as fake IT support over Teams. STAC4749 refined the formula. Custom web addresses replaced Microsoft's own default ones, and the group switched from Quick Assist to RemSupp partway through its run, a change Sophos believes was made to dodge corporate blocklists. Researchers assess with high confidence that the campaign was financially motivated, whether run directly by the ransomware operators or by an affiliate working with them.Stuart Madnick, who co-founded and co-directs Cybersecurity at MIT Sloan, has tracked this pattern across the ransomware industry for years. “Most companies are aware of the threat and are doing things to improve security, but the bad guys haven't stayed still either,” he said. “You have to think beyond what you did for protection last year.” One reason: the group that built the ransomware doesn't have to be the same group making the calls. Madnick describes ransomware-as-a-service as a productized version of malware, where one group builds the tooling and brand while affiliates handle the break-ins and split the proceeds, the same setup Sophos points to behind STAC4749.
Why It Works
Researchers have a name for the mechanism behind this kind of attack, and it has little to do with software. Frank Stajano at the University of Cambridge spent years studying con artists for a research project built around a BBC television series about hustlers. One of the seven scam principles he and co-author Paul Wilson documented explains this call almost exactly. “Society trains people not to question authority,” they wrote. “Hustlers exploit this ‘suspension of suspiciousness’ to make you do what they want.” Their research also names what they call the Time principle: “When you are under time pressure to make an important choice, you use a different decision strategy.” A two-minute call is built for precisely that kind of pressure.
Bruce Schneier, a fellow at Harvard’s Berkman Klein Center and a lecturer at the Harvard Kennedy School, has spent years making the case for where security teams should focus their energy instead of blaming the employee who picks up the phone. “We must stop trying to fix the user to achieve security,” he wrote in IEEE Security & Privacy. Usable security, he argued, “means creating security that works, given (or despite) what people do.” His point applies directly here. The employee who opened Quick Assist did what employees have been trained to do for decades: help the person who calls from IT. A rehearsed habit outlasts a one-time reminder about vigilance, the same way a fire drill outlasts a memo about fire safety. People remember what they practice, and that is the design problem for security teams to solve, not a character flaw in the employee who answered the phone.
How CISOs Can Shut This Down
Stopping a call like this takes four things working together: a verification habit, a short list of approved tools, monitoring that catches what slips through, and practice that makes the other three automatic.
- Verify the caller. Treat every unsolicited support call as unverified until proven otherwise. Call back through a number the company already has on file, never one the caller provides. Make granting remote access a decision that involves a second person, rather than something one employee decides alone under time pressure. Microsoft’s own Teams settings let administrators restrict or flag messages from outside the company, which cuts off one of the paths STAC4749 used to make first contact.
- Control the tools. Restrict which remote-support tools employees are allowed to install, and keep that list short and centrally managed. Quick Assist and RemSupp only worked as entry points because they were already sitting on employee machines, ready to use. A narrower, IT-issued list takes that option away before a call ever comes in.
- Watch the network. The backdoor STAC4749 installed was disguised as ordinary Windows audio software, exactly the kind of anomaly that endpoint monitoring is built to catch. Segmenting networks so one compromised laptop cannot reach every server limits how far an attacker gets even after a successful call. Employee habits and technical controls work best as a pair. Neither one covers everything on its own.
- Rehearse the response. Building muscle memory takes more than one team. Security teams own the monitoring and access controls that catch what slips through. Training and simulation platforms, including Adaptive Security, give employees practice spotting these calls before an attacker ever dials, using realistic run-throughs of the same voice, video, and chat tactics these campaigns rely on. Each layer covers ground the others cannot reach alone.
The Next Version Of This Call
Worth preparing for now: every call in this campaign came from a person working off a script. The same trick gets sharper with a cloned voice behind it. Voice generation tools can now reproduce a colleague’s tone from a few seconds of audio pulled off a company town hall or a voicemail greeting. The habits above, verifying through a known channel and treating remote access as a deliberate decision, are the same habits that will matter when the caller’s voice is generated rather than performed. Building them now gets a company ready for that version of the call before it arrives.
Chaos is believed to be run by former members of Royal and BlackSuit, two ransomware operations that grew out of the Conti cybercrime syndicate. The FBI and CISA have linked Royal alone to more than $275 million in ransom demands from over 350 victims worldwide. STAC4749 shows that lineage does not need a new exploit to keep collecting. It needs one employee to trust a familiar voice for ninety seconds. Companies that treat those ninety seconds as a skill worth practicing, backed by the technical controls that catch what training misses, make that path a great deal harder to walk.
Get started with Adaptive Security
Related articles

What Is Shadow SaaS: Unmanaged Applications, Hidden Risks, and the Governance Framework That Reduces Organizational Exposure

Ransomware vs. Malware: Key Differences, Real-World Impact, and Building a Defense Strategy That Covers Both

What Is Shadow IT in Cyber Security: Definition, Risks, and How to Manage Unauthorized Technology Across the Organization
Get started