top of page

Would You Recognize a Phishing Attack If It Didn't Arrive by Email?

2 minutes ago
7 min read

When most of us hear the word “phishing,” we picture an email. Maybe it has a suspicious link, an unexpected attachment, a strange sender address, or a message urgently asking us to reset a password.


But what if the next phishing attempt your employees encounter doesn't arrive in their inbox at all?


What if it's a Microsoft Teams message from someone claiming to be IT? A phone call from someone offering to fix a problem with their computer? A QR code asking them to sign in? Or a request to approve access to an account?


Would your employees recognize it as a potential threat?


That's becoming an increasingly important question for businesses because attackers don't need to rely on email alone. They're looking for other ways to reach employees, earn their trust, and convince them to take an action that gives the attacker access.


What If “IT Support” Isn't Really IT Support?


Imagine you're working at your computer when an unexpected Microsoft Teams message appears. The person says they're with IT and there's a problem with your account. They know enough to sound legitimate and tell you they can fix the issue quickly if you follow a few instructions.


Would that immediately feel suspicious?


Microsoft recently reported observing attackers using Teams external collaboration to impersonate IT and help desk personnel. In these attacks, the goal can be to convince an employee to allow remote access to their computer using legitimate support tools. Microsoft has also documented incidents involving Teams voice phishing in which attackers posed as IT support and attempted to persuade employees to grant access.


That's what makes this type of attack so interesting. The employee isn't necessarily opening a strange attachment or clicking an obviously suspicious email. They may believe they're talking to someone who is trying to help them.


The attack looks like support.


And that means cybersecurity awareness has to extend beyond the inbox.



Employee reviewing potential phishing attacks through Microsoft Teams, a phone call, QR code, and unexpected sign-in request.

Phishing Has Moved Beyond Email


The basic idea behind phishing hasn't changed. Someone is trying to gain your trust long enough to convince you to do something you normally wouldn't do.


What has changed is where that conversation can happen.


Microsoft Teams and other collaboration platforms give businesses an incredibly useful way to communicate, but employees also need to understand that an unexpected message or call deserves the same scrutiny as an unexpected email. Microsoft advises Teams users to verify the identity of external contacts and pay attention to warnings associated with suspicious external conversations.


QR codes create another challenge because we've become so accustomed to scanning them. They're on restaurant menus, parking meters, event materials, advertisements, invoices, and signs. Most of us don't think twice before pointing our phone at one.

Cybercriminals know that.


The Federal Trade Commission has warned that malicious QR codes can send users to convincing fake websites designed to steal passwords or other information. A fraudulent QR code can even be physically placed over a legitimate one, making something as ordinary as paying for parking an opportunity for fraud.


Phone calls add another layer. Someone claiming to be from IT may say there's an urgent security problem and ask an employee to verify information, approve a request, or allow remote access. If the caller sounds knowledgeable and helpful, an employee may believe they're doing exactly what they're supposed to do.


The technology used in the attack doesn't necessarily have to be sophisticated. Sometimes the most effective tool is simply a convincing person on the other end of the conversation.


The Red Flags Are Changing


For years, one of the most common pieces of phishing advice was to look for spelling mistakes, strange wording, or poorly designed emails.


That's still worth noticing, but it isn't enough anymore.


A phishing message can be well written. A fake website can look professional. A caller can know your name and where you work. Someone impersonating technical support can sound calm, knowledgeable, and helpful. Even the remote-support software they ask an employee to use may be completely legitimate.


Instead of only asking, “Does this look fake?”, employees should learn to ask another question:


“Was I expecting this?”


An unexpected request from IT should be verified. An unfamiliar Teams contact deserves a closer look. An unexpected request for remote access should cause an employee to stop and contact their IT team through the method they normally use. An MFA approval request they didn't initiate should never be approved simply to make the notification disappear.


That doesn't mean employees should become suspicious of every message or phone call they receive. It means they should feel comfortable slowing down when something is unexpected.


Phishing attack examples using IT support calls, Microsoft Teams messages, QR codes, and account requests instead of email.


Would Your Employees Know What to Do?


This is where the conversation becomes less about cybersecurity technology and more about your people.


Imagine someone contacts one of your employees tomorrow and says, “Hi, this is IT. We've detected an issue with your Microsoft account and need to connect to your computer.”


Would the employee know whether that's how your IT company normally communicates? Would they recognize an external Teams contact? Would they know whether they're allowed to grant remote access? Most importantly, would they know exactly who to contact to verify that the request is legitimate?


If the answer to those questions isn't clear, that's something worth addressing.


Employees don't need to become cybersecurity experts. They do need a simple process for what to do when something doesn't feel right.


Give Your Employees Permission to Stop and Verify


Cybercriminals often rely on urgency because urgency discourages people from thinking too carefully about what's happening. An account is supposedly going to be disabled. A password expires today. Suspicious activity has been detected. The boss needs something immediately. IT needs access right now.


Instead of trying to teach employees every possible type of cyberattack, businesses can reinforce a much simpler habit:


If something is unexpected, stop and verify it before taking action.


Verification is important, but so is how the employee verifies the request. They shouldn't use the phone number, link, or contact information supplied by the suspicious person. Instead, they should contact the company or their IT provider using information they already know and trust

.

That small pause can make a big difference.


Cybersecurity Awareness is Only Part of the Picture


Teaching employees to stop and verify is important, but employees shouldn't have to carry the entire responsibility for protecting the business.


Technology can provide additional layers of protection.


Multifactor authentication can make a stolen password less useful. Security tools can help identify suspicious links, sign-in attempts, malware, and unusual activity. External communication settings can help businesses control how people outside the organization interact with employees. Remote-access tools can also be reviewed so employees aren't unknowingly using software that the business doesn't need.


Microsoft's recent Teams attacks are a good example of why these layers matter. The attackers weren't necessarily exploiting a flaw in Teams itself. They were using legitimate collaboration and remote-support capabilities while convincing employees to trust them. Microsoft recommends organizations review external Teams communication and unnecessary remote-access tools as part of reducing that risk.


In other words, cybersecurity shouldn't depend on an employee making the perfect decision every single time.


Your people and your technology should be working together.


Make It Easy for Someone to Say, “This Seems Weird”


There is another part of phishing awareness that doesn't get talked about enough.

What happens after an employee becomes suspicious?


Imagine someone receives a strange Teams message and isn't sure whether it's legitimate.


Do they know who to ask?


Can they easily contact your IT team?


Will they worry about bothering someone over something that turns out to be harmless?


And if they already clicked something, will they report it immediately or hesitate because they're embarrassed?


That last part matters.


Employees should know that reporting something quickly is more important than trying to quietly figure it out themselves.


A simple message to your team can go a long way:


If something seems unusual, we'd rather you ask.


The goal isn't to make employees afraid of technology. It's to create an environment where stopping, questioning, and verifying something unexpected is normal.


Employee reviewing potential phishing threats from email, Microsoft Teams, a phone call, QR code, and unexpected account approval request.


Try This With Your Team


You don't need an hour-long cybersecurity presentation to start this conversation.


At your next staff meeting, give employees these four scenarios:


A Teams message from “IT” asks to remotely access your computer. What do you do?


Your phone suddenly asks you to approve an MFA request you didn't initiate. What do you do?


You receive a QR code telling you that you need to sign in to review a document. What do you do?


Someone calls claiming to be technical support and knows your name, company, and email address. What do you do?


Then listen to the answers.


You're not trying to catch anyone getting something wrong.


You're trying to find out whether everyone understands the same process.


Ideally, employees should know three things:


Stop. Verify. Report.


If the request was unexpected, don't immediately act on it.


Verify the person or request through a communication method you already trust.


If something still seems suspicious, report it to whoever manages your technology.


That may be one of the simplest cybersecurity procedures your business can put in place.


So, Would You Recognize a Phishing Attack If It Didn't Arrive by Email?


Maybe.


And that's exactly why this conversation matters.


Phishing hasn't stopped being phishing just because it arrives through Teams instead of Outlook, a phone call instead of a message, or a QR code instead of a link.


The delivery method can change.


The request can change.


The technology can change.


But the attacker is still trying to accomplish something very human:


Get someone to trust them long enough to take the next step.


That means your employees don't need to memorize every new attack technique.


They need to develop an instinct for unexpected requests.


Was I expecting this?


Is this how IT normally contacts me?


Why am I being asked to provide access?


Can I verify this another way?


Those few seconds of hesitation can be valuable.


Because sometimes the most important cybersecurity tool isn't another piece of software.


It's an employee who feels comfortable saying, “Wait. Let me verify this first.”


Make “Stop and Verify” Part of Your Cybersecurity Plan


At TriTech, we help businesses across Southeastern Wisconsin protect more than just their inboxes. We look at cybersecurity as part of the bigger technology picture, including Microsoft 365, user accounts, devices, networks, backups, security tools, and the people using them every day.


You don't need your employees to become cybersecurity experts.


You need them to know what to do when something doesn't feel right.


And you need technology and support behind them when they make that call.



 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page