Someone calls and says they are from your IT provider. They know the business name and may mention a real product you use. Then they claim there is an urgent problem and ask for a password, a payment or access to a computer.
Do not rely on the caller's name, phone number or knowledge of the business. Those details can be copied from websites, social media, invoices or previous data breaches.
How the scam works
The caller wants the employee to act before checking. They may claim to represent a familiar provider, report an urgent fault, ask for remote access or request a password, sign-in approval or unusual payment.
If the employee follows the instructions, the caller may gain access to email, files or other business systems.
Warning signs
Be careful when an unexpected caller pressures you to act, asks for a password or sign-in approval, wants remote access or refuses to let you verify the request. An unusual payment method is another reason to stop.
A displayed caller number is not proof of identity. Phone numbers can be copied or disguised.
Use a simple verification process
End the call
Tell the caller you will contact the provider through the normal support process. A genuine technician should accept that you need to verify an unexpected request.
Call a trusted number
Use the number saved in your business records, service agreement or provider portal. Do not call a number given by the person you are checking.
Protect passwords and sign-in codes
Do not give a password or approval code to an unexpected caller. Your IT provider should have an agreed process for support access and account recovery.
If a technician needs you to enter a password during a verified support session, type it yourself and follow the provider's normal procedure.
Confirm remote access
Only open a remote support session after you have verified the request. Staff should know which remote support tool the business uses and what a genuine connection looks like.
Report the attempt
Tell the real IT provider and the person responsible for security. If anyone installed software or shared a password or code, stop using the affected device and get advice immediately.
Make the process clear to staff
Keep the provider's trusted phone number somewhere staff can find without using a suspicious email. Explain who can approve remote access and what information support staff may request.
Had an unexpected support call? Contact JCPIT for advice. If a technical review is needed, we will confirm the affected device, required access and scope before checking for unknown access tools.