VoIP

Fake IT Help Desk Calls: How to Stop Phone-Based Phishing

Recent warnings describe criminals calling employees while pretending to be the IT help desk, then stealing their Microsoft 365 logins. Here is how a small business can spot these calls and set rules that stop them.

Office manager at a desk holding a desk phone handset and pausing mid-call with a cautious expression
On this page
  1. What the recent warnings say
  2. How a fake IT call turns into a break-in
  3. Warning signs your staff should know
  4. Set a simple call-back rule
  5. Make your phone system part of the defense
  6. Tighten the technical side
  7. If someone already fell for a call
  8. How Rise Technologies can help
  9. Sources

The phone rings at the front desk. The caller says they are from IT, that the company is rolling out a new sign-in check, and that they just need you to visit a page and approve a prompt on your phone. They sound friendly, they know your name and your boss's name, and the caller ID looks right. A few minutes later, a criminal is inside your company email and files.

This kind of scam is called "vishing," short for voice phishing: phishing done over a phone call instead of an email. Several security warnings in the past few weeks show it is being used against ordinary businesses, not only large ones. The good news is that a few clear rules, which cost nothing, can stop most of these calls cold.

What the recent warnings say

  • Executives are being targeted with fake IT calls. In early September 2026, the security firm Arctic Wolf described a campaign it calls PREY-0058. According to The Hacker News, the attackers phone directors, vice presidents and other senior staff while posing as the internal IT help desk, talking about routine multi-factor or "passkey" setup. Industries hit include construction and engineering, healthcare, real estate and property management, finance and professional services.
  • Healthcare offices are in the crosshairs. On October 1, 2026, a Robinson & Cole privacy alert reported that the Health Information Sharing and Analysis Center (Health-ISAC) warned of a group called ShinyHunters using voice phishing and medical-themed lookalike websites against healthcare organizations, with more than a dozen organizations targeted.
  • Government agencies are seeing it too. The Center for Internet Security reported in an August 2026 analysis that criminals pose as help desk staff to get employees to share one-time codes or approve sign-in prompts, and also do the reverse: they call the real help desk pretending to be an employee who needs a password reset.

New York regulators have flagged the same pattern. In February 2026, the New York State Department of Financial Services warned that attackers impersonating IT staff were calling employees on both work and personal phones, using spoofed caller ID to look legitimate.

How a fake IT call turns into a break-in

The Arctic Wolf research, as summarized by Help Net Security, shows how the pieces fit together:

  1. The caller sends the employee to a sign-in page that looks like the company's own, often with the company name built into the web address.
  2. The employee types their password and approves the multi-factor prompt (the second check, such as a code or a tap in an app, that normally protects the account).
  3. The fake page passes everything through to the real Microsoft sign-in and keeps the "session token," the digital pass that keeps you signed in. Security researchers call this an adversary-in-the-middle attack.
  4. With that pass, the attackers browse SharePoint, OneDrive, email and other connected apps, copy large amounts of data and then demand payment not to leak it.

Notice that the employee did use multi-factor authentication. The trick works because the person approved the prompt for the attacker. That is why the defenses below focus on people and process as much as on technology.

Warning signs your staff should know

  • An unexpected call from "IT" about a new security setup, a password reset or an urgent account problem.
  • A request to visit a website, read back a code, or approve a sign-in prompt you did not start yourself.
  • Pressure to act right now, or a request to keep the call quiet.
  • A web address that contains your company's name but is not your company's usual domain.
  • A caller who knows names and job titles. That information is easy to find online and proves nothing.

Caller ID is not proof either. As the DFS advisory points out, criminals can fake the number that appears on your screen.

Set a simple call-back rule

The single most effective habit is this: never act on an IT request from a call you did not make. Instead, hang up politely and call back using a number you already know, such as the help desk number in your office handbook or your IT provider's main line. Real IT staff will not mind. Criminals will vanish.

Write the rule down and make it company policy, so no employee feels rude following it. Tell staff plainly that your IT team or provider will never ask them to read out a code or approve a prompt they did not request.

Make your phone system part of the defense

  • Publish one help desk number. Put it on a sticker on every desk phone and in your staff handbook, so everyone knows exactly where a real IT call-back should go.
  • Teach staff to tell internal and outside calls apart. On many business phone systems, a colleague calling from inside shows an internal extension or name, while an outside call does not. A "help desk" call arriving as an outside line deserves extra suspicion.
  • Protect the receptionist and front desk. They answer the most calls and are often the first target. Give them a short script for transferring or declining unusual requests.
  • Include personal mobiles in the conversation. Attackers call personal phones too, so the call-back rule should apply wherever the call lands.

Tighten the technical side

Training helps, but the advisories also recommend changes that make a mistake less costly:

  • Move to phishing-resistant multi-factor authentication. Health-ISAC and CIS both point to FIDO2 security keys and passkeys, which are tied to the real website and will not work on a fake sign-in page.
  • Verify identity before any help desk reset. If someone calls asking for a password reset or a new phone added to their account, confirm who they are through a separate channel first.
  • Limit access to what each job needs. DFS recommends regularly reviewing permissions. Someone who does not need every SharePoint folder should not have it.
  • Restrict where and how people can sign in. Microsoft 365 "Conditional Access" rules can block sign-ins from unexpected locations or unmanaged devices, which Arctic Wolf recommends against this campaign.
  • Watch for odd sign-ins. Alerts for new devices, unusual multi-factor activity or large downloads give you a chance to catch an intruder early.

If someone already fell for a call

Act quickly and without blame, so people feel safe reporting mistakes. Change the person's password, sign them out of all sessions, remove any new multi-factor methods that were added, and review recent account activity. DFS also recommends reporting incidents to the FBI's Internet Crime Complaint Center at ic3.gov. Regulated businesses in New York should check their own reporting obligations.

How Rise Technologies can help

Rise Technologies is a New York-based IT consulting and support company that has served businesses across New York, Long Island and the Tri-State area for over 10 years. Our certified engineers can review your Microsoft 365 sign-in settings, monitoring and patching through our security management services. As an authorized Panasonic phone system dealer, we also set up VoIP and business phone systems, including hosted PBX. If you would like a clear picture of where your gaps are, start with an IT assessment.

Want help putting a call-back policy and stronger sign-in protection in place? Call us at (516) 545-0065 or request a free quote, and we will walk you through your options.

Sources

Written by the Rise Technologies team

We're a New York-based IT consulting and support company with over 10 years in business, helping businesses across the Tri-State area stay secure, connected and productive.

About us
Get in touch

Let's talk about your technology needs.

Tell us a little about your business and we'll get back to you with a free quote. Prefer to talk? Our team is a phone call or chat away.

Request a free quote

Tell us what you need and we'll get back to you.

No spam. We only use your details to respond to your request.

Call now Free quote