A sophisticated ransomware scam is targeting businesses across the UK, and it is catching people off guard because it looks and sounds entirely legitimate. Rather than relying on a suspicious link or an obvious phishing email, attackers are posing as IT support staff and contacting employees directly, by phone and through Microsoft Teams. If your team would not immediately know how to respond, this article is essential reading.
How This Ransomware Scam Works
The attack begins before the phone even rings. First, attackers flood a target employee’s email inbox with a massive volume of spam. The sheer quantity arrives so quickly that the inbox becomes unusable within minutes. The employee is overwhelmed and looking for a solution.
That is when the call comes in.
Someone claiming to be from IT support, or in some cases specifically from Microsoft, contacts the employee and offers to fix the problem. They sound professional, they know about the inbox issue, and they have a solution ready. The timing feels helpful rather than suspicious.
At this point, the attacker asks the employee to install remote access software, such as AnyDesk, or to use a built-in Windows tool called Quick Assist. Either option gives the attacker full control of the employee’s device. From there, they move through the business network, collect sensitive data, and deploy ransomware across your systems.
Ransomware locks your business out of its own data. Files become inaccessible, operations can grind to a halt, and the attacker demands a substantial payment in exchange for restoring access. Even if the ransom is paid, there is no guarantee the data will be returned intact.
The Microsoft Teams Angle Makes This Ransomware Scam Harder to Spot
What makes this particular ransomware scam especially difficult to detect is that attackers have extended it beyond phone calls. Cyber criminal groups have begun creating Microsoft Teams accounts specifically designed to impersonate internal IT support.
They choose usernames such as “Help Desk” and register under fake Microsoft tenant domains that look plausible at first glance. Domains like “securityadminhelper.onmicrosoft.com” appear official enough that many employees would not question them. The attacker then sends a direct Teams message to an employee, explaining that they need access to the device to resolve an issue.
Because the message arrives inside Teams, a platform your team already trusts for internal communication, it carries far more credibility than a cold phone call. An employee who would be suspicious of an unknown caller might respond without hesitation to what looks like an internal chat from the IT department.
This is a deliberate and effective escalation of the original attack method, and it requires a specific response from businesses using Teams.
What Happens If a Ransomware Attack Succeeds
The consequences of a successful ransomware attack extend well beyond losing access to files. For businesses of any size, the impact can be severe and long-lasting.
Operationally, ransomware can shut down your systems entirely. Customer-facing services may go offline. Staff cannot access the tools or data they need to work. Depending on how quickly the attack spreads through the network, recovery can take days or weeks.
Financially, the costs accumulate quickly. There is the potential ransom demand itself, which can run into tens of thousands of pounds. There is also the cost of IT recovery work, the revenue lost during downtime, and the reputational damage that comes from a visible breach. In some cases, where personal or client data has been accessed, there may also be regulatory consequences under UK data protection law.
Furthermore, there is no guarantee that paying a ransom resolves the situation. Some businesses pay and still find their data has been leaked or that their systems remain compromised. Therefore, prevention is always the more reliable strategy.
You can read more about how to protect your business on our cyber security page and in our article on cyber attack recovery.
Who Is Most at Risk Within Your Business
Any employee who uses email and Microsoft Teams is a potential target, but some are at greater risk than others. Staff who are less familiar with cyber threats, newer team members, and anyone in a role that regularly deals with IT or administrative requests are particularly vulnerable.
The inbox-flooding technique is designed to create panic and a sense of urgency. Someone who is already stressed about a broken inbox is far less likely to pause and question the motives of a caller who claims to have the answer. Attackers understand human psychology and exploit it deliberately.
For businesses across Sussex with hybrid or remote teams, the risk is compounded. An employee working from home and unable to quickly walk over to a colleague or the IT desk to verify a request is more likely to act on what they are told over the phone or in a chat message.
How to Protect Your Business from This Ransomware Scam
The good news is that clear, practical steps can significantly reduce your exposure to this attack. None of them require significant technical expertise, but they do require consistent communication across your team.
Start by making your entire team aware that this scam exists. Describe exactly how it works. Explain the inbox-flooding tactic, the follow-up call, and the Teams message approach. When employees know what to look for, they are far more likely to recognise it when it happens.
Establish a simple rule: no one should ever grant remote access to their device in response to an unsolicited contact. Not by phone. Not by Teams message. Not by email. If someone calls or messages claiming to be IT support and asks for device access, the employee should end the contact and check directly with your actual IT team before doing anything.
This verification step is the single most effective protection against this type of attack. It does not matter how convincing the caller sounds. A genuine IT support team will always be happy to be verified through a known internal number or email address.
On the technical side, review how your Microsoft Teams environment is configured. Restrict external communications so that only messages from trusted, verified domains can reach your employees. Enable chat logging so that any suspicious contact can be reviewed. Our managed IT services include Teams configuration reviews as part of a broader security assessment.
Additionally, make sure your business data is backed up regularly and that those backups are stored separately from your main systems. A robust backup process does not prevent a ransomware attack, but it dramatically reduces the leverage an attacker has over your business. Our article on how to back up your business data covers this in detail.
What This Means For Businesses
This ransomware scam is notable because it exploits trust rather than technology. It does not rely on a vulnerability in your software or a weakness in your firewall. It relies on an employee being deceived into opening the door willingly.
That means the most important investment your business can make is in awareness. A team that understands this threat, knows the warning signs, and has a clear process to follow is far more resilient than one relying entirely on technical defences.
Business owners and directors should treat this as an operational priority. Brief your team. Set a clear policy on remote access requests. Make sure everyone knows who your actual IT support contact is and how to reach them. These are small steps that carry significant weight.
If you manage your own Microsoft 365 environment, review your external communication settings in Teams this week. If your IT is handled by a managed provider, ask them to confirm that appropriate restrictions are in place.
Final Thoughts
The ransomware scam described here is effective because it is clever. It creates a problem, then arrives with a solution. By the time the employee realises something is wrong, the attacker already has access.
Awareness is your strongest defence. Talk to your team, set clear expectations, and make verification a non-negotiable habit before anyone grants remote access to a device. A moment of caution is always worth more than a costly recovery effort.
They should not follow any instructions from the caller or grant any access to their device. They should end the call politely and immediately contact your actual IT support team using a known internal number or email address. If the call came through Teams, they should report the account to their IT team so it can be investigated and blocked.
Check the domain associated with the account sending the message. Internal colleagues will appear under your organisation’s own domain. If a message comes from an external domain, even one that looks official, treat it with caution. Legitimate IT support will never ask for remote device access through an unsolicited Teams message.
Remote access software allows another person to view and control your computer over the internet. Tools like AnyDesk and Windows Quick Assist are legitimate when used by your actual IT team. In this scam, the attacker uses them to take full control of the employee’s device without the employee realising the access has been handed to a criminal rather than a support technician.
Antivirus software provides an important layer of protection, but it cannot fully protect against an employee who has been socially engineered into granting remote access voluntarily. The attacker in this scam uses legitimate tools that antivirus software may not flag. Human awareness and clear policies are equally important alongside technical defences.
Disconnect affected devices from the network immediately to limit the spread. Contact your IT support team or a specialist cyber security provider as quickly as possible. Do not pay any ransom without first seeking professional advice, as payment does not guarantee data recovery and may expose your business to further risk. Report the incident to the National Cyber Security Centre and, where personal data has been affected, to the Information Commissioner’s Office.