Fake IT Support

    Real IT Will Not Rush You

    Calls or chats requesting remote access, software installs, resets or MFA approval need independent verification.

    Everyday Cyber SafetyEveryday usersIT & help deskLeadership

    Illustrative scenario

    How It Looks in Real Life

    After a flood of spam emails, someone messages you on Teams as “IT Helpdesk”, offers to stop the spam and asks you to open a remote support tool and share the code.

    Understand it

    How the Attack Works

    Attackers create a problem (spam floods, fake alerts) and then offer to fix it. Remote access or an approved MFA prompt gives them direct control of your device or account.

    Red flags

    Warning Signs

    • Unsolicited contact from “IT” on chat, phone or a personal number.
    • Requests to install remote access tools or read out a session code.
    • Requests for your password, a verification code or an MFA approval.
    • External or newly created accounts using IT-sounding names.

    Safer habits

    What to Do Instead

    • 1End the conversation and contact IT through the help-desk number or portal you already know.
    • 2Never share passwords or codes; real IT does not need them.
    • 3Report the contact so others can be warned.

    Response playbook

    Already Interacted?

    For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.

    If you: approved app permissions or a sign-in request
    1. 1Report it straight away so IT can revoke the session or app consent.
    2. 2Remove the unfamiliar app from your account’s connected apps or permissions page.
    3. 3Changing your password does not remove app permissions or tokens already issued.
    If you: installed software or ran a command
    1. 1Disconnect the device from the network (Wi-Fi off or cable out) but leave it powered on.
    2. 2Report to IT or security and describe exactly what you ran or installed.
    3. 3Do not delete files, wipe the device or run cleanup tools yourself; evidence helps the investigation.
    4. 4From a different, trusted device, change passwords for accounts used on the affected machine.
    If you: entered credentials or shared a code
    1. 1Report it to IT or security immediately for a work account; speed matters more than embarrassment.
    2. 2Change the password from a trusted device by typing the real address yourself.
    3. 3Sign out of all sessions from the account security settings. A password change alone may not end active sessions.
    4. 4Review recovery email, phone number and forwarding rules for unexpected changes.

    Knowledge Check

    What Would You Do?

    “Hi, this is IT. We see malware on your laptop. Please install the support app from support-fix.example.com so we can clean it.” What do you do?

    Fictional example for learning. Not a test score or certification.

    Sources

    Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.

    All Awareness Guides

    Make Safe Habits Part of Your Culture

    Plain-language awareness sessions for everyday staff, developers and business teams.

    Email Us