For years, one of the most common pieces of computer security advice has been simple: be careful about suspicious emails.
That advice is still important?but it is no longer enough.
Cybercriminals are increasingly using other ways to reach people, including Microsoft Teams messages and calls, fake Microsoft sign-in pages, unexpected multifactor authentication prompts, and even legitimate remote-support tools.
Microsoft recently reported that threat actors have been expanding into Teams-based social engineering as part of increasingly sophisticated, multi-stage attacks.
For small businesses, that means employees need to think about phishing as more than just an email problem.
Microsoft Teams has become part of everyday business communication for many organizations. That familiarity can also make an unexpected message feel more trustworthy than an unfamiliar email.
Attackers know that.
Microsoft has documented attacks in which criminals contacted employees through Teams while pretending to be IT or helpdesk personnel. The message might claim there is a security problem, an account issue, a spam-filter update, or another problem that supposedly requires immediate attention.
The goal is often not simply to get someone to click a link.
The attacker may try to start a conversation, build credibility, and persuade the employee to take another action.
That could include:
Microsoft emphasizes that this doesn't mean Teams itself has been compromised. Attackers are taking advantage of people's trust in a familiar business tool.
One particularly important warning sign is an unexpected request to give someone remote access to your computer.
Microsoft has investigated attacks in which criminals impersonating IT support persuaded users to open legitimate Windows remote-support software such as Quick Assist.
Because the software itself is legitimate, the request can appear convincing.
But once remote access is granted, the person on the other end may be able to interact directly with the computer.
If someone unexpectedly contacts you claiming to be Microsoft, your IT department, technical support, or another service provider and asks you to give them remote access, verify who they are before proceeding.
Don't rely on the phone number, Teams account, email address, or link supplied by the person contacting you.
Instead, contact your IT provider or organization using contact information you already know to be legitimate.
Multifactor authentication, or MFA, remains an important security measure because it makes a stolen password alone much less useful to an attacker.
But criminals increasingly try to trick people into completing the second step for them.
For example, an attacker who has obtained or guessed a password may generate an authentication request on the real user's phone.
The victim suddenly sees a notification asking whether to approve a Microsoft sign-in.
If you didn't just attempt to log in, don't approve it.
An unexpected MFA prompt can be an indication that someone else is trying to access your account.
The same applies if someone calls or messages you and tells you that you're about to receive a verification request and need to approve it.
That should immediately raise a red flag.
Another common technique is to direct someone to a website that looks almost identical to a legitimate Microsoft 365 or other online login page.
The branding can look convincing.
Instead of judging a login page by how professional it looks, ask yourself how you arrived there.
Did you open Microsoft 365 yourself?
Or did somebody send you a message telling you that your account needed immediate verification?
An unexpected login request following an unsolicited message, phone call, or Teams conversation deserves additional scrutiny.
Small businesses don't necessarily need employees to become cybersecurity experts.
They do need everyone to develop a few good habits:
1. Treat unexpected Teams messages with the same caution as unexpected emails.
2. Don't grant remote computer access to someone who contacts you unexpectedly.
3. Never approve an MFA request unless you initiated the login yourself.
4. Don't enter passwords into a website simply because someone told you that your account needs immediate attention.
5. When something doesn't feel right, stop and verify it using a phone number or contact method you already trust.
That final step can be particularly effective.
A legitimate problem can still be addressed five minutes later after you've verified the request.
A fraudulent request is much harder to undo after credentials or remote access have already been provided.
Firewalls, antivirus software, email filtering, multifactor authentication, and other security tools remain important.
But attackers frequently look for ways around those protections by convincing a person to grant the access they need.
That's why employee awareness has become an important part of business technology security.
The question is no longer simply:
?Does this email look suspicious??
It is increasingly:
?Was I expecting this request, and can I independently verify who is asking me to do this??
That mindset applies whether the request arrives by email, Teams, phone, text message, or an authentication notification on your phone.
PC Pros provides IT support, computer services, networking, security assistance, and troubleshooting for small businesses in Virginia Beach and nearby areas.
If you're unsure about a suspicious message or authentication request?or would like help reviewing the security of your business computers and Microsoft 365 environment?contact PC Pros at (757) 227-1414