2024-05-15 (disclosed) · US
Storm-1811 email bombing and fake IT support calls, 2024
Disclosed by the affected organisation.
From mid-April 2024 Microsoft observed Storm-1811, a group known to deploy Black Basta ransomware, flooding targets' inboxes by signing them up to many subscriptions, then phoning as IT support to fix the spam. Callers talked users into opening Quick Assist and entering a code, then installed tools leading to Black Basta. From late May the group also used Microsoft Teams accounts named as help desk. CISA and the FBI later added the email bombing and Teams tactics to their Black Basta advisory.
Timeline
- 2024-04-15 From mid-April 2024 Microsoft observes Storm-1811 misusing Quick Assist in social engineering attacks.
- 2024-05-10 CISA, the FBI and partners publish their joint advisory on Black Basta, which they say had affected over 500 organisations.
- 2024-05-15 Microsoft publishes its analysis of the Storm-1811 campaign.
- 2024-06-01 Microsoft's June 2024 update reports the group using Teams messages and calls from tenants named as help desk from the end of May.
- 2024-11-08 CISA updates the Black Basta advisory to describe email bombing followed by fake technical support over calls and Teams.
Lessons
- Tell staff that a sudden flood of subscription email followed by a call or Teams message from IT is a known attack pattern.
- Block or remove Quick Assist and other remote tools where they are not used, and give IT a support tool with authentication.
- Restrict or monitor Teams chats and calls from external tenants, especially ones with help desk style names.
Scam types: Email bombing followed by fake IT support · Techniques: Voice phishing (vishing)
Sources
- CISA and FBI: #StopRansomware: Black Basta (AA24-131A) (Law enforcement, primary, accessed 2026-09-24)
- Microsoft Threat Intelligence: Threat actors misusing Quick Assist in social engineering attacks leading to ransomware (Vendor research, secondary, accessed 2026-09-24)