Hackers Pose as IT Support on Microsoft Teams to Take Remote Control of Computers

Cybersecurity experts warn that hackers are posing as IT support workers on Microsoft Teams to trick employees into giving remote access.

Hackers pose as company IT support workers on Microsoft Teams to trick employees into granting remote access to their computers.

Cybersecurity experts have issued an urgent warning after discovering that internet hackers are posing as company help desk technicians on Microsoft Teams to take remote control of office computers.

Disguised as helpful internal technical support workers, the scammers reach out to employees through unsolicited chat messages and direct voice calls, claiming that the worker’s computer has an urgent technical problem.

Once the scammer gains the worker’s trust, they trick the victim into opening built in Windows features like Quick Assist to voluntarily grant complete remote access.

Once connected, the internet thieves silently install hidden computer viruses, steal private corporate files, and attempt to compromise full company networks.

The critical threat investigation was published in detailed security reports on Wednesday, September 2, 2026, after cyber intelligence researchers at Unit 42 and Palo Alto Networks tracked widespread social engineering campaigns.

Tracked by analysts under the operation name Spring Ring, the wave of fake help desk calls targeted over 150 employees across at least 10 major organizations.

Instead of breaking past tough firewalls or exploiting complex system software bugs, the bad actors relied entirely on live phone conversations and fake chat profiles to trick workers into handing over computer access.

The primary reason this sneaky attack method works so well is that workers naturally trust messages sent through everyday office chat applications like Microsoft Teams.

Hackers create external Microsoft accounts with professional display names like IT Help Desk, IT Assistance, or Network Support, making their profile pop ups look like routine messages from internal company managers.

During the live call, the attacker uses technical jargon and creates artificial urgency, convincing the worker to approve remote assistance requests.

Because the victim voluntarily clicks the approval buttons, standard security programs do not flag the connection as a virus attack, allowing the hackers to walk right past normal digital security doors.

Explaining how bad actors bypass technical firewalls by convincing everyday employees to open computer doors voluntarily, threat intelligence researchers at Palo Alto Networks Unit 42 said in a report shared with Cyber Security News that “the campaign matters because it abuses tools and services many organizations already allow”.

Detailing why live voice conversations allow fake technicians to easily manipulate victims and overcome initial doubts, analysts at Unit 42 stated that “rather than relying only on a malicious link or credential harvesting page, the attacker uses real time conversation to overcome suspicion and adapt the lure to the victim’s responses”.

Warning that employees must carefully verify all technical support requests before clicking screen approvals, security analysts emphasized that “when the legitimate program opens, it loads the nearby malicious DLL rather than the normal Windows copy,” allowing harmful code to run quietly under the cover of trusted systems.

By exposing how hackers pretend to be IT workers on chat apps, security analysts are helping businesses protect their networks.

Verifying all technical support calls through official company channels and never granting remote access to unverified callers ensures that office computers, private files, and company databases remain safe from internet thieves.

About the Author

Jennifer Sakmufuwo Baba

Jennifer Sakmufuwo Baba is a tech analyst, senior staff, and writer covering artificial intelligence, cybersecurity , and emerging technologies at TechRegard. Based in Nigeria, she's passionate about translating complex tech developments into compelling, accessible stories for diverse audiences. Her work focuses on how technology shapes innovation across Africa and globally.