The message that looks like it came from your own IT company
Picture a Friday afternoon. The week was long, everyone is trying to wrap things up, and one of your employees gets a chat in Microsoft Teams. The name on it says something like "IT Help Desk" or "Support Staff." There is a small tag beside it that says External. The message says there is a problem with the account and asks the person to approve a login prompt, read back a code, or let a technician take over the screen for a few minutes.
It looks routine. It arrived in Teams, not email, so it feels internal. That is exactly the point.
Nobody at your real IT company messages you first to ask for a password, a code, or access to your computer. That one rule, if everyone on your team knew it cold, would stop most of what is happening right now.
This is not a thought experiment
In June, the threat research team at Palo Alto Networks published findings on a campaign they call Spring Ring. Between January and April of this year, attackers used Microsoft Teams accounts dressed up as internal IT help desks to approach more than 150 employees at a minimum of 10 companies. The fake technicians picked names like "IT Protection Department." They chatted first, then called. A conversation that worked often ran ten to fifteen minutes, long enough to walk a person through steps that would look obviously wrong in writing.
The same team reported a wider shift. In the first four months of 2026, phishing that arrived through collaboration tools made up 42 percent of the phishing alerts in their telemetry, up from 30 percent in the four months before. Email filters have gotten better, and people have learned to be careful with email. Chat is newer, and we still treat it like it is safe.
Why a stranger can reach your staff at all
Here is the part that surprises most owners. Microsoft leaves external chat turned on by default. Unless somebody deliberately changes that setting, anyone in the world with a Microsoft Teams account can start a chat with your employees. There is no flaw to patch and no update to install. The attacker is using Teams exactly the way it was built.
So the door is not broken. It is not locked, and most owners have never checked whether theirs is open.
What to actually do
Start with the human rule, because it is free and it travels. Tell every person on your team, in plain words: nobody from IT will ever message, call, or chat you out of the blue to ask for a password, a code, or control of your computer. If it happens, close the chat or hang up, then call the person you actually know, on a number you already have. Do not reply. Do not call back the number they handed you.
Then look at the setting. Someone on your IT side can open the Teams admin settings and decide who your staff is allowed to chat with from outside the company. Most small businesses only need to talk to a handful of known partners. Everyone else can be shut out. That is a configuration change, not a purchase.
And watch the prompts. If your phone buzzes with a login approval you did not start, that is not a glitch. Someone is trying to get in. Deny it, and tell someone.
The uncomfortable part
Most of us were trained to be suspicious of email and relaxed about everything else. The attackers noticed. Chat, text, and phone calls are where they work now, because that is where our guard is down. A message can carry a name you trust and still come from a stranger.
You do not need new software for most of this. You need one clear rule that everyone knows, and a look at a setting almost nobody has opened. Those two things are worth more than any product you could buy this year.
Call us at (906) 662-4481, or contact us for a free assessment.