In this guide
Appearance
Appearance
By Scot, 10+ years in IT support and helpdesk ·How these guides are checked
Hang up and call the help desk back on a number you look up yourself — from the intranet, the directory, or a previous ticket email — never one the caller supplies. No legitimate IT process asks you to read out an MFA code, approve a push you did not trigger, or reveal your password.
Checked against Microsoft Learn - end of support and retirement and Google Chrome Releases between 5 Aug 2026 and 12 Sep 2026. Nothing published in that period has been linked to this guide.
The most effective impersonation attack is not a stranger pretending to be a bank — it is someone pretending to be your own help desk. This article explains why internal impersonation works, which requests are never legitimate no matter who is asking, and the one verification habit that defeats all of them.
In this guide
Internal impersonation succeeds on three ingredients, and it helps to name them before you meet them.
Nothing about this is a comment on how careful you are. These calls succeed on trained, security-conscious people, because the whole design is to make the request feel like part of a normal working day.
This is the shortest path to safety: instead of judging whether a caller sounds genuine, judge what they are asking for. Four requests are always illegitimate, regardless of who is asking, how senior they claim to be, or how urgent it sounds.
Note: A request that arrives before you asked for help is worth extra attention. If you opened a ticket five minutes ago and someone calls about it, that is ordinary. If nobody was expecting to hear from IT and IT calls anyway, verify first.
There is one defence that works against every version of this attack, including ones that have not been invented yet: end the conversation and re-establish it on a channel you chose.
Tip: Save your help desk number in your phone contacts today, while nothing is going wrong. The moment you need it is the moment you are least able to search for it calmly.
A real IT department will never be annoyed at being called back to verify. Support teams train people to do exactly this. A technician who reacts to a callback with irritation, pressure, or "there isn't time for that" has told you everything you needed to know — genuine work survives a two-minute pause.
Not every version of this arrives by phone. The written ones carry signals worth learning.
In Microsoft Teams:
In Outlook:
EXTERNAL into the subject line.[email protected] is not from yourcompany.com.Note: The hardest case is a message with no External tag and a perfectly correct internal address, sent from a colleague's genuinely compromised account. The tags cannot help you there — the callback rule still can. Verify through a different channel than the one the message arrived on.
Voice cloning now needs only a few seconds of recorded speech, and plenty of people have that much audio in a public webinar, a podcast, a conference recording, or a voicemail greeting. A voice that sounds like your IT manager is no longer evidence that it is your IT manager.
Two practical responses:
If the answer does not come, end the call and use the callback rule. This applies equally to a finance request from a familiar executive voice and to a support request.
Deep dive: How to Spot Deepfake Audio and Video Scams.
If you approved something and the feeling arrived a minute later, you are in the most recoverable situation there is. What matters now is speed, and speed comes from acting rather than replaying the conversation. Work through whichever of these apply.
Note: Reporting fast is the whole game, and no support team treats it as a failure. The cases that turn expensive are the ones nobody mentioned for three days.
Deep dive: What to Do If You Clicked a Phishing Link and How to Run a Personal Security Checkup in 15 Minutes.
INFO
Verifying a caller costs two minutes and never causes harm. Approving a request from someone you could not verify can cost your organization weeks. When the two are weighed against each other, the callback wins every time — which is why help desks teach it rather than resent it.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| Caller knows your ticket number, manager, and internal jargon | Researched or previously breached data | Detailed knowledge is not identity. End the call and dial the help desk number from your intranet (Step 3). |
| Caller ID shows your real help desk number | Caller ID spoofing | Caller ID is trivial to fake. Hang up and dial the number yourself rather than trusting the display. |
| Caller says a callback will delay the fix | Manufactured urgency | Genuine work survives a two-minute pause. Pressure not to verify is the strongest signal available. |
| Teams message has no External tag | Compromised internal account | Tags cannot flag a genuine account in the wrong hands. Verify on a different channel — phone the colleague on their directory number. |
| You cannot find the help desk number anywhere | Intranet page never bookmarked | Open any previous ticket confirmation email — the reply address and support number are in it. Then save the number in your phone contacts. |
| A remote-control session is already running on your screen | Remote-access tool installed | Close the session, turn off Wi-Fi and unplug the network cable, leave the computer on, and call the help desk from your phone. |
IT Tip Tuesday
Get a short, actionable IT tip in your inbox every week.
Nothing loads from beehiiv until you click. Once it does, the form sets beehiiv's own cookies and loads beehiiv's own analytics.