TL;DR:
- Attackers are impersonating managed service providers by using real MSP names, spoofed caller IDs, and lookalike email domains to convince staff to hand over remote access or credentials
- Unlike generic “Microsoft tech support” scams, these attacks are personalised — the caller knows your MSP’s name, often your name, and sometimes references recent legitimate support tickets
- Mitigation is mostly a process question: establish a callback protocol for any unsolicited IT contact, and confirm all remote access requests by calling your MSP’s known number directly
The classic tech support scam has been with us for well over a decade. You get a call claiming to be from Microsoft, or BT, or your bank’s fraud team. They’re urgent. There’s a problem with your computer. They need access. Most people have learned to hang up.
What’s less understood is that a more targeted version of this scam is increasingly being aimed at small businesses — one that replaces “Microsoft” with the actual name of your IT support provider, and replaces the generic script with details specific enough to be genuinely convincing.
What MSP Impersonation Looks Like
A member of your staff receives a call from someone identifying themselves as being from your managed service provider. They use the correct company name. They might have your name. In some cases they’ll reference a recent real support ticket or mention your organisation’s name in a way that a cold caller shouldn’t know.
They explain there’s an urgent issue — a security alert on your account, unusual login activity, an expired certificate that needs immediate renewal. They need to connect to your system to fix it. Can you download AnyDesk? Can you give them the code? Can you confirm your Microsoft 365 admin password so they can push the fix?
This works because it exploits the trust relationship your business has with its actual IT provider. People routinely grant remote access to their MSP; they’re supposed to. An attacker who can plausibly claim to be that MSP can leverage that standing authorisation.
How Attackers Get the Information
The personalisation that makes these calls convincing comes from several sources:
Open source research. Your MSP’s name is often findable. It may be on your website (“Managed IT by Acme Tech”), in LinkedIn posts from staff (“grateful to the team at Acme Tech for the quick response”), or in procurement information if you’re a public sector or charity organisation that publishes supplier details. Your company’s staff names and email addresses are typically available on LinkedIn or your website contact pages.
Dark web credential data. Leaked credentials from previous breaches may include your MSP’s name if it appeared in email communications in breach databases. Attackers with access to credential marketplaces can look for data associated with your domain and find contextual information.
Compromised MSP systems. In some cases the attacker has access to an MSP’s ticketing system or email. If your MSP has had a breach (and some have), the attacker may have real ticket information. This is the most concerning scenario because the level of detail is indistinguishable from a legitimate call.
Previous successful attacks. Information gathered from other businesses served by the same MSP can be used to build convincing scripts for the next target.
The Immediate Goal
In most cases the attacker wants one of:
Remote access to your machine. AnyDesk, TeamViewer, Splashtop — any legitimate remote access tool will do. Once connected, the attacker can install malware, exfiltrate files, or move to other systems.
Admin credentials. Microsoft 365 admin access, your domain registrar, your router management interface — anything that gives them elevated access they can use now or sell later.
Banking access. Some variants progress to “we need to transfer funds to fix the issue” or request access to business banking to “verify account security.”
The urgency framing exists to short-circuit your normal caution. A security problem that needs to be solved in the next ten minutes doesn’t leave time to call back on a number you trust.
How to Protect Your Business
The single most effective mitigation is a callback protocol. If you receive any unsolicited contact claiming to be from your IT provider — call, email, or message — do not engage with the inbound communication. Hang up, close the email, and call your MSP’s main support number from a number you already have saved. Ask whether they just tried to contact you. If they did, you’ll know within thirty seconds. If they didn’t, you’ve stopped the attack.
This process works regardless of how convincing the caller is, what information they have, or how urgent they say the problem is. The callback breaks the attack chain at its critical point.
Establish who is authorised to receive IT calls. In a small business, having a designated person (or a small group) who handles IT requests reduces the surface area. Train that person specifically on MSP impersonation.
Set up a safe word or code with your MSP. Some MSPs will agree to a verbal code or confirmation process for outbound calls — a short phrase that your IT provider uses to confirm they’re really calling you. Ask your MSP whether they offer this.
Verify the email domain, not just the display name. Lookalike domains (acmetech-support.co.uk instead of acmetech.co.uk) are cheap to register. Check the actual sending domain on any email requesting action, not just the name displayed in your email client.
Be sceptical of urgency. Legitimate IT providers rarely demand that you install software or provide credentials under time pressure. If a caller is pushing you to act in the next few minutes, that’s a signal to slow down, not speed up.
If You’ve Already Granted Access
If someone has connected to your machine under these circumstances, assume it’s compromised. Immediately:
- Disconnect from the network if you can do so safely
- Call your actual IT provider on their real number and explain what happened
- Change passwords for any accounts you accessed during or after the remote session — prioritise email and banking
- Report to Action Fraud (0300 123 2040 or actionfraud.police.uk)
The longer a compromised system stays connected, the more damage is possible. Speed matters here.