Call or Text - 
Orlando & Central Florida:
407-554-5534
Naples & Southwest Florida:
239-653-0252
cybernetic_logo_white
Schedule a Free Consultation

That “IT Support” Call Could Be the Attack: A New Microsoft 365 Threat Targets Business Leaders

09/18/2026
2149445127(1)

A phone call from “IT support” may feel more trustworthy than an unexpected email. The caller may know an employee’s name, title, company, and email address. They may even sound patient and professional.

That familiarity is exactly what makes a newly reported Microsoft 365 attack so dangerous.

In September 2026, Arctic Wolf described an active campaign in which criminals call business leaders while pretending to represent an internal IT department or help desk. The callers direct their targets to convincing account-registration or passkey websites. If the employee follows the instructions, the attackers may gain access to Microsoft 365 and other cloud services.

The lesson for small businesses is simple: phishing no longer arrives only through email. It can begin with a helpful-sounding phone call.

How the Fake IT Call Works

The campaign is being tracked as PREY-0058. According to Arctic Wolf, the attackers have frequently targeted directors, vice presidents, executives, and IT personnel.

The call may claim that the employee needs to:

  • Register a new passkey
  • Reconnect Microsoft 365
  • Confirm a security change
  • Update multifactor authentication
  • Resolve an account or sign-in problem

The caller then sends or dictates a website address that appears to relate to the company or Microsoft 365. The page is controlled by the attacker, even if it looks like a normal sign-in screen.

When the victim enters a password and approves a verification request, the attacker may capture enough information to take over the active cloud session. This can let the criminal access email, SharePoint sites, OneDrive files, and other connected services.

Why Multifactor Authentication May Not Be Enough

Multifactor authentication, often called MFA, is still an important security control. It normally requires something beyond a password, such as an app approval, security key, or device-based confirmation.

The problem arises when an employee is persuaded to approve the attacker’s sign-in.

In this campaign, the criminal is not necessarily breaking the MFA system. The attacker is manipulating the person into completing the authentication process for them.

That is why unexpected verification requests should never be approved simply because someone on the phone says they are from IT.

Businesses should also work toward phishing-resistant sign-in methods, such as properly configured passkeys or physical security keys. These methods can provide stronger protection against fake login pages, but they still require careful setup and clear employee instructions.

Why Business Leaders Are Attractive Targets

Executives and managers often have access to more information than an average employee. Their accounts may contain contracts, employee records, financial discussions, customer information, strategic documents, or confidential email.

They are also busy. A convincing caller who creates urgency may be able to pressure an executive into acting before checking the request.

Small companies are not immune. In a smaller Orlando business, one owner or office manager may have access to nearly every shared document, mailbox, vendor relationship, and financial workflow.

A compromised account may therefore expose a large portion of the company’s information without the attacker ever installing traditional malware.

Establish a Simple Verification Rule

Every business should adopt one clear rule:

Employees should independently verify unexpected requests involving passwords, passkeys, MFA, remote access, or account changes.

That means ending the call and contacting the real IT provider through a known number, support portal, or previously saved contact.

Do not use a telephone number, website, or contact method supplied by the unexpected caller. Caller ID is not enough because displayed numbers and names can be misleading.

Employees should understand that pausing to verify a request is not rude or uncooperative. It is the correct security response.

Warning Signs Employees Should Recognize

Treat a support call as suspicious when the caller:

  • Contacts you unexpectedly about an account problem
  • Creates pressure to act immediately
  • Sends an unfamiliar login or passkey-registration link
  • Asks you to approve an MFA notification
  • Requests your password, verification code, or recovery code
  • Wants to install remote-access software
  • Discourages you from contacting your usual IT provider
  • Claims the request must remain confidential

A legitimate technician should be comfortable with independent verification.

What Small Businesses Should Do Now

First, tell employees that criminals may impersonate internal IT staff by phone, text message, or collaboration platform.

Next, document how genuine support requests will be handled. Employees should know the official telephone number, support portal, and people authorized to request account changes.

Businesses should also review:

  • Whether MFA is required on every Microsoft 365 account
  • Whether stronger, phishing-resistant authentication is available
  • Which employees have administrative or broad file access
  • Whether former employees and unused accounts have been removed
  • Whether unusual sign-ins and large file downloads are monitored
  • Whether employees know how to report a suspicious call quickly

These controls help reduce both the likelihood and potential impact of an account compromise.

What to Do After a Suspicious Call

If an employee only received the call and did not follow its instructions, report the attempt internally so other staff can be warned.

If the employee visited the website, entered information, approved an authentication request, installed software, or allowed remote access, contact the company’s trusted IT provider immediately. The account, active sessions, authentication methods, email rules, file activity, and device may all need to be reviewed.

Avoid trying random fixes or deleting information that could help determine what happened.

Cybernetic Networks helps Orlando and Central Florida businesses secure Microsoft 365, strengthen account protections, train employees around real-world scams, and investigate suspicious sign-in activity. If an unexpected “IT support” call has raised concerns, our team can help you verify the situation and protect the business without adding unnecessary confusion.

Source Links

Quotes from our Customers

Posted on Google Google
Lori Hall Patel profile picture
Lori Hall Patel
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Fantastic service!
Posted on Google Google
Yaritza Quintero Luis profile picture
Yaritza Quintero Luis
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Cybernetic Networks Inc. provides excellent tech support for the office. Himala is always responsive, knowledgeable, and quick to resolve any issues I run into. I truly appreciate his reliability and professionalism—highly recommended!
Posted on Google Google
Carlos Villoch profile picture
Carlos Villoch
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
From the very first call to Cybernetic, the team was responsive, knowledgeable, and genuinely committed to solving my issues. Their proactive approach and genuine care are what really stood out above any other IT Support Businesses. If you’re looking for IT support that’s dependable, friendly, and truly invested in keeping your technology running smoothly, this is the team you want. I can’t recommend them highly enough.
Posted on Google Google
KIMBERLY profile picture
KIMBERLY
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I would highly recommend Cybernetic Networks Inc. to anyone looking for reliable and trustworthy tech support.
Posted on Google Google
Tom moore profile picture
Tom moore
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Himala and his team at Cybernetic Networks have been amazing. We have been a customer of Cybernetic Networks for well over 14 years now, both personally and professionally. Himala and his team are professional, reachable and on the cutting edge of technology. We have enjoyed doing business with Cybernetic Networks for many years and still rely on their knowledge, skills and technology every day.
Posted on Google Google
Daniel Fusco profile picture
Daniel Fusco
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Himala and his Cybernetic team have never let me down! For over 10 years now they have been fixing my technical issues, set up all my new networks and computers and have safeguarded me from any hackers or malware. You can trust this company to navigate you as your company grows and to keep you on track with the latest in security and safety.
Posted on Google Google
Beth Wolff profile picture
Beth Wolff
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Cybernetic Networks has been advising and supporting all our IT issues and purchases for the last 18 years. They are very responsive and extremely knowledgeable- always providing us with timely services.
Posted on Google Google
Brian Wolff profile picture
Brian Wolff
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I am a solo practicing neurologist and have had all my IT needs covered through Cybernetic Networks since 2007. They are the best! All of their tech support staff is extremely knowledgeable and efficient. Just as importantly, they are quickly responsive whenever we need their assistance. I couldn’t be happier with their service and give them my highest recommendation!
Posted on Google Google
Patti Muzzonigro profile picture
Patti Muzzonigro
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I couldn't be happier with Cybernetics - they are experts, always respond quickly , and solves any issues I have.
Posted on Google Google
sue myhelic profile picture
sue myhelic
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
It is not often you find small business companies that are not only rewarding to work with, but also have integrity, truth and skill. I have worked with this company for over 20 years, and the service is outstanding. I can easily recommend that if you need an IT company, this is the one to get. Full STOP! Look no further, you will be happy that you did. Sue Myhelic, Gulf Breeze Real Estate, Naples, Florida.