The FBI put out an alert this year about a crew that's been working U.S. law firms for about three years. What makes it worth your attention isn't the malware. There isn't any.
They call your office pretending to be your IT department. Sometimes an email comes first — no link to click, just a number to call, which is exactly why your email filtering doesn't catch it. Whoever picks up gets talked into granting a remote desktop session, and the files walk out the door.
If that doesn't work, the FBI says they'll send someone to the office in person to plug a drive into a computer.
What stays with me is how ordinary the whole thing looks. A helpful voice, a little urgency, a legitimate remote support tool. Nothing on the screen says "attack."
For a firm, the damage isn't a tech problem. It's calling clients to tell them their file was taken. It's the matter that stalls while everyone deals with the incident instead of the work. It's a renewal conversation with your carrier you'd rather not have.
The fix is embarrassingly low-tech: everyone in the office knows IT never cold-calls asking for access, and when in doubt you hang up and dial the number you already have.
Worth five minutes at your next staff meeting.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email