Southwest Networks - Managed IT Services & Cybersecurity

Fake IT Support

Published July 31, 2026

About This Video

In this Episode I talk about what would happen if Fake IT support walked into your office and wanted access to your server or other equipment. Would staff let them in? A Law Firms staff did and demanded $20 Million dollars to get the data back. #SouthwestNetworksIncPalmDesert ➡ Download our Free IT Buyers Guide: https://www.southwest-networks.com/it-buyers-guide ➡ Interested in working with us, book a quick and easy call: https://www.southwest-networks.com/discoverycall Connect with us! https://www.southwest-networks.com https://www.facebook.com/southwestnetworks https://www.linkedin.com/company/southwest-networks-inc ⏰ Timecodes ⏰ 00:00 Introduction 00:34 Fake IT showed up at a Law Firm 03:02 The worry isn't just the $20 Million 04:13 How to Protect yourself

Full Transcript

Auto-generated from the video's captions. Minor transcription errors may exist.

Welcome back to another episode of Cappuccino Chat. This time we're talking about a little bit kind of a different story here and that is what happens if fake IT support shows up at your front door. All right, so this time we've got kind of a different story to talk about and that is what happens when fake IT support shows up at your front door. Keep in mind as we go through this story, it could be your internet provider, gas company, water company, phone company, any other company that does support for your business. So, keep that in mind as we go through this. Now, last month, someone called the law firm's front desk, claimed to be IT support, then showed up at their office and walked out with enough data to demand $20 million ransom. The FBI got involved and a formal warning went out. This group called Silent Ransom Group, which isn't very silent if they're calling you, but that's what they call themselves, is about big law firms. And maybe you're thinking, well, that's not my business because you heard this story. But I got to tell you, it is. So, please stay with me till the end to kind of talk this through. Uh, just to make sure that you understand that this is about all of our businesses. So, now here's what makes this group just a little bit different from the usual fish fishing scam. which basically that's what this is, right? But they're not just sending you an email. They're actually calling your receptionist or your office, talking to someone, letting them know they're coming, making it sound very legit. Then they're actually showing up at your front door, maybe wearing a logo shirt, carrying a laptop bag, usual kind of geeky look, right? They look like somebody's going to fix your stuff. And then they're allowed into your server room or your electrical room or your wherever your internet comes in. Then they're plugging in actual storage and getting your data. They're pulling it physically off your computer. So they didn't have to install any software. They didn't have to get remote access. They actually walked right in. That's what worries me about this. So this isn't a hacker, you know, in some basement somewhere. This is a trained operator walking through your lobby door and saying, "Hey, I'm here. I'm going to make everything better." When they're actually there to steal from you and you're letting them in. Now again, the FBI focused on law firms, but this isn't about law firms. So if you're a CPA, a financial adviser, maybe a medical practice, or really just any professional services company, your risk level is the same of this kind of attack. So because you hold the personal financial tax records, health information, billing details, credit card stuff about all your clients and even some of your employees. So that's the exact kind of data these groups are looking for because you got to remember the ransom only works if what they took matters to somebody. If they took that data from you, it would both matter to you and the clients you serve. So we're we're on the hook for this. Now the thing that kind of worries me about this isn't just the $20 million where that would be devastating to any of us, but it's that they have to only get this kind of thing right once. your staff, your IT provider, everybody there only has an option of being correct 100% of the time because when these attackers get in one time, that's all it takes. So, it's very difficult to make sure, right? We want to have internal policies and procedures in place to help us walk through this, talk about it in our company meetings. We want to make sure that we can do what we h can to make sure our staff is well informed. So every phone call, every person who walks through the front door, anybody who picks up an internal extension and goes, "Hi, this is John from IT," they need to be aware of these kinds of things because thinking that this will never happen to you, is where the gap really is and what really worries me because that's when people let their guard down and that's when these type of attacks actually happen. So, good news is this kind of attack, right? It's kind of low tech defense. We don't need a lot going on here, right? First, set up some kind of verification protocol with your IT provider, your internet provider, gas company, and the like. Right? So, when somebody does show up, say, "Okay, hey, what account number do you have on there?" Right? Let me call back to your office. I wasn't expecting you. Nobody, you know, I'm not aware of what's going on. We didn't call you. let me call the number on my build to get verification of what's going on. That way, anyone claiming to be from IT support, you stop them cold. They never get access. Second, you got to train your front desk uh people on physical access. So, again, anyone showing up unannounced, doesn't matter if they got a polo shirt saying they're with the internet provider or with your IT company, you want to make sure that you can verify who they are. Now, you may know them already. That's a little bit different story. when you find somebody that you're not aware of, you've never seen them before, that's when this protocol kicks in. So, again, verify from a phone number, something on your own records like an account number, maybe a PIN that you've already set up. I know for us with a lot of our uh bills that we pay, like the gas company, internet provider, stuff like that, there's a little code that they want you to set up a PIN. Make sure you set that up and get verification of what that is. Third, just remind your staff that big companies like Microsoft, Google, a legitimate vendor likece, your IT support, they're not going to just show up out of the blue and demand immediate attention and want to get access without first prepping you for what's going on. They're going to make sure you're aware. Now, these people did call in and make it seem like something. So, you need to have that protocol in place. But the piece I want to point out is the urgency. When they say, "Hey, if this doesn't happen, you know, you're going to lose everything and I don't know when we can get you back up if you don't let me, you know, take a look at your internet connection." And those kinds of things, that's the dead giveaway that there might be something wrong here because again, no one's going to show up and act like that. So, if someone at your office maybe has already taken a call like that or had somebody walk in, make sure they let staff know. Make sure you call your IT provider. Make sure maybe you follow up with your internet provider, your gas company. We want to make sure that these people aren't just left unattended in the back because they seem legitimate because odds are they might not be. So, as with anything IT related, if you have any questions, please feel free to reach out to us here at the office 760-770-52 0.

Ready to Protect Your Business?

Schedule a free consultation with our team. No obligation, no pressure — just a clear picture of where you stand.

Or take the free IT security assessment first — see exactly where you stand in minutes.