
Most business owners train employees to be careful with suspicious emails. That is still important, but attackers are no longer staying in the inbox.
Recent security research from Sophos found that attackers have been using Microsoft Teams calls and chats to impersonate IT support staff. Their goal is simple: convince an employee to allow remote access to their computer. Once inside, the attackers may install tools, move deeper into the network, steal information, or prepare for ransomware.
For a small business, this is especially dangerous because the request can feel normal. Employees are used to getting messages from coworkers, vendors, and support teams. A quick Teams call from someone claiming to be “IT” may not feel like a cyberattack in the moment.
In these attacks, the criminal may contact an employee through Teams and claim there is a computer issue, security update, account problem, or urgent support task. They may sound helpful and professional. They may even use a name or account that looks believable.
The next step is usually the important one. The attacker tries to get the employee to start a remote support session, install a tool, approve access, or follow instructions that give the attacker control of the device.
That one decision can open the door to a much larger problem.
Security researchers reported that some incidents connected to this kind of Teams voice phishing led to ransomware activity. That means a short fake support conversation could eventually become downtime, locked files, lost productivity, customer notification headaches, and expensive recovery work.
Small businesses often rely on Microsoft 365, Teams, SharePoint, OneDrive, and Outlook every day. That makes collaboration tools part of normal business life.
The risk is not that Teams itself is bad. The risk is that attackers go where employees already work. If your staff expects IT support to contact them through chat or calls, criminals can copy that pattern.
This is a business operations issue, not just a technical issue. A fake support request can affect:
For many small businesses, even one day of downtime can be painful.
The best protection is a clear company rule that every employee understands:
No one should approve remote access from an unexpected call, chat, or email until the request is verified through an approved process.
That process does not need to be complicated. It can be as simple as calling a known support number, checking with a manager, or contacting your managed IT provider directly through an official support channel.
Employees should not rely on the name, profile picture, caller ID, or urgency of the message. Those can be copied or faked.
Small businesses can lower the chance of this scam working by putting a few practical controls in place.
First, define how IT support is allowed to contact staff. If your provider normally uses a ticketing system, phone number, or known support email, write that down and share it with the team.
Second, limit who can install remote access tools. Employees should not be able to install new remote control software without approval.
Third, review Teams settings and external communication policies. Many businesses do not realize how open their collaboration settings are until there is a problem.
Fourth, train employees with specific examples. “Watch out for phishing” is too vague. A better message is: “If someone contacts you in Teams and asks to control your computer, stop and verify first.”
Fifth, monitor unusual sign-ins, new remote access tools, and suspicious activity on business devices. These are the kinds of warning signs that can help stop a small incident before it becomes a full outage.
The most important habit is slowing down. Attackers want employees to act quickly, especially when they are busy, stressed, or trying to be helpful.
If a support request feels unexpected, urgent, or unusual, it is okay to pause. Real IT support will understand. A criminal will pressure the employee to keep going.
A few minutes of verification can protect days of business operations.

Himala and his team at Cybernetic Networks have been amazing. We have been a customer of Cybernetic Networks for well over 14 years now, both personally and professionally. Himala and his team are professional, reachable and on the cutting edge of technology. We have enjoyed doing business with Cybernetic Networks for many years and still rely on their knowledge, skills and technology every day

Himala and his Cybernetic team have never let me down! For over 10 years now they have been fixing my technical issues, set up all my new networks and computers and have safeguarded me from any hackers or malware. You can trust this company to navigate you as your company grows and to keep you on track with the latest in security and safety

I am a solo practicing neurologist and have had all my IT needs covered through Cybernetic Networks since 2007. They are the best! All of their tech support staff is extremely knowledgeable and efficient. Just as importantly, they are quickly responsive whenever we need their assistance. I couldn’t be happier with their service and give them my highest recommendation!

I couldn't be happier with Cybernetics - they are experts, always respond quickly , and solves any issues I have.

Cybernetic Networks has been advising and supporting all our IT issues and purchases for the last 18 years. They are very responsive and extremely knowledgeable- always providing us with timely services.

It is not often you find small business companies that are not only rewarding to work with, but also have integrity, truth and skill. I have worked with this company for over 20 years, and the service is outstanding. I can easily recommend that if you need an IT company, this is the one to get. Full STOP! Look no further, you will be happy that you did. Sue Myhelic, Gulf Breeze Real Estate, Naples, Florida.

Himala and his team from Cybernetic Networks, Inc. has been an integral part of our successful retail business for the past 20 years. He is extraordinarily knowledgable and always available for our IT needs. Thanks to Himala and his team we are always up and running.