Workforce and access social engineering · Also called spam bombing, Teams help desk scam, Quick Assist scam, Storm-1811 social engineering, fake IT support call
Email bombing followed by fake IT support
Email bombing with fake IT support is an attack in which criminals flood an employee's inbox with sign-up emails, then call or message them on Microsoft Teams posing as the company help desk offering to fix the spam. The employee is talked into starting a remote support session, which hands the attacker control of the computer.
How it works
- The attackers sign the employee's email address up to many subscription services, burying the inbox in spam.
- Soon after, they call or send a Teams message posing as IT or the help desk and offer to help with the spam problem.
- They ask the employee to open Quick Assist or another remote support tool and enter a code, which gives them control of the device.
- They may ask the employee to sign in to a fake web form, then install remote management tools and malware, in some cases leading to ransomware.
Red flags
- Your inbox suddenly fills with sign-up and newsletter emails you never requested.
- Shortly afterwards, someone from IT calls or messages you on Teams, unasked, offering to fix it.
- The Teams message or call is labelled External.
- The helper asks you to start Quick Assist or another remote tool, enter a code, or type your password into a web page.
If you are targeted
- Stop: end the call or chat, and do not start a remote session or enter any code.
- If a session is already running, disconnect it at once and tell your IT or security team using a number or channel you already know.
- Let IT isolate the device and reset any credentials you typed in during the session.
- Report it to your security team, then to the national service; our Report a scam page lists where, such as ic3.gov in the US.
Prevention
For individuals
- Only let someone connect to your computer if you contacted your IT support yourself.
- Check for the External label on Teams messages and calls, and treat unexpected ones from IT with suspicion.
- Never share account details or approve sign-in requests over chat.
For organisations
- Block or uninstall Quick Assist and other remote management tools that are not in use, and standardise on one support tool with authentication.
- Restrict inbound Teams contact from unmanaged accounts and allow external chat only from trusted domains.
- Tell staff exactly how IT will contact them and prove who it is, so an unexpected helper stands out.
- Require phishing-resistant authentication for employees on critical apps.
By the numbers
Figures are for the reporting category this scam falls under, not this scam alone.
| Tech and customer support scam losses reported to the FBI IC3 in 2025 | $2.13B | US, 2025, FBI IC3 |
Real cases
2024-05 · US · Disclosed
Storm-1811 email bombing and fake IT support calls, 2024
Delivered through: Voice phishing (vishing)
How official datasets classify it
- FBI IC3
- Tech/Customer Support
- MITRE ATT&CK
- T1667, T1566.004, T1219
Questions
- Why would scammers flood my inbox with spam?
- The spam is the setup. Microsoft has reported a group that floods inboxes, then calls or messages the victim on Teams posing as IT support and offers to fix the problem through a remote session.
- How do we stop fake IT support on Teams?
- Restrict external Teams contact to trusted domains, remove remote support tools you do not use, and tell staff how real IT will reach them, so they hang up on anyone else.
Related scams
- Callback phishing (fake subscription renewal)
- Tech support pop-up scam
- Help desk password and MFA reset impersonation