A caller says they can fix your email. Before letting them connect, ask: did you call them? A convincing offer of help can put the accounts on that computer at risk.
How the fake IT support scam works
The approach often starts with an everyday problem: email stops working, an account needs attention, or a meeting requires an update. Someone claiming to be IT offers to help and asks the employee to install a tool or approve a connection. A flood of unwanted emails can make a follow-up call seem more convincing.
ScreenConnect and Microsoft Quick Assist are legitimate tools. The scam is getting an employee to give control to someone who should not have it. Attackers may also disguise remote-support software as a document or meeting app. Microsoft has reported both Quick Assist social-engineering scams and campaigns that used disguised installers to deploy ScreenConnect. Those reports describe misuse of legitimate tools—not a ScreenConnect vulnerability.
What could an attacker reach in your business?
What someone can do depends on the connection and the employee’s access. They may see what is on screen or, if given control, use open accounts and files. A computer used for both email and payments deserves particular attention. For example:
- A dispatcher may be signed in to email, customer systems, a load board, or billing.
- A bookkeeper may have payroll, invoices, tax records, and payment tools open.
- A buyer may have supplier messages, orders, and banking details at hand.
- Access to an office computer does not, by itself, mean someone can control factory equipment.
Six ways to make remote support safer
Make it normal to pause and check before anyone connects:
- Call your IT provider using a number you already have, or sign in to its portal yourself. Don’t use contact details from an unexpected call or message.
- Tell staff who provides support, how a real support request starts, and which tools are approved. Make sure seasonal and part-time staff know who to ask.
- Ask IT to list the remote-support tools on your computers, who uses each one, and which computers they can reach. Include software that lets a provider reconnect later.
- Have IT approve unfamiliar software and review who can install it. Keep the process practical so staff can still get help from legitimate vendors.
- Never change supplier bank details, approve an unexpected MFA request, or sign in to banking because an unverified caller asks you to.
- Assign someone to review support access and alerts. Use individual support accounts and MFA where available, and remove access when a vendor relationship ends.
If someone has already connected
End the session. If you think access is still happening, disconnect the office computer from the network and call your verified IT or security contact from another device. If the computer is connected to machinery or safety systems, follow your approved operating procedure before disconnecting it.
Keep the messages, caller details, times, and download information. Tell your IT contact what happened, even if you only approved part of the request. Don’t try to clean up the computer yourself.
Ask IT to check for other remote-access software and determine which accounts or sessions may be affected. Removing ScreenConnect alone does not confirm that access has ended. If a payment may be at risk, call your bank using a number you already trust.
Common questions about remote access scams
Is ScreenConnect malware?
No. ScreenConnect is legitimate remote-support software. But if someone installed or used it without your approval, they may have gained access. Ask your IT provider to check who set it up and who can connect.
Does MFA stop someone controlling a signed-in computer?
MFA helps protect sign-ins, but it may not stop someone from using accounts that are already open on a computer they control. Verify remote-support requests separately.
Does closing the support window remove the attacker?
Not necessarily. Other software or account access may remain. Ask your IT provider to investigate.
How Securing Your Business can help
Security Awareness Training gives staff practice spotting suspicious requests. Managed Phishing Testing & Staff Training adds email simulations and follow-up lessons; an email simulation by itself does not test how staff handle a support call.
The $1,995 Business Security Baseline reviews agreed internal safeguards and evidence. Mention remote support when discussing scope. The free Zero-Access Business Exposure Review checks public signals only—it cannot verify what software is installed on your computers.
Give your team a safer way to handle support requests
Security Awareness Training helps staff practice recognizing suspicious requests. For a review of internal safeguards and available evidence, ask about the Business Security Baseline.
