Active High impact Ransomware Checked 6h ago

Fake IT-support Teams calls spread Chaos ransomware

A financially motivated group is calling employees on Microsoft Teams while posing as internal IT support, then talking them into giving remote access to their computers. Researchers at Sophos, who track the group as STAC4749, say dozens of organizations in the US and Canada have been hit since February 2026, and in several cases the intruders installed Chaos ransomware, in one case within about 17 hours of the first call. As of late August 2026, hospitals including Nebraska Medicine and the University of Nebraska Medical Center have begun warning their own staff about the same style of fake IT-support Teams call.

Started
Feb 1, 2026
Latest activity
Sep 3, 2026
Attributed to
STAC4749 (Chaos ransomware operators)Likely
Where
United States, Canada
Sectors
Multiple sectors, Manufacturing, Energy, Technology
Scale
dozens of organizations across the US and Canada, some reports citing 100+

Current status

On 2026-09-03, TechRadar repeated Microsoft's warning that the campaign was ongoing, with no new victim or closure reported.

Active: Confirmed and still going. Attacker activity or disruption is continuing.

Who is behind it

A newer, separate Microsoft Teams vishing campaign called Spring Ring surfaced around 2026-08-31 to 2026-09-02, tracked by Unit 42 and using a different technique (abusing Teams external access plus a PetitPotam NTLM relay attack against domain controllers). No source found ties Spring Ring to STAC4749 or Chaos ransomware, so it is reported here only as context, not as an update to this incident.

Impact

Attackers gain remote access to a victim's computer through a fake IT-support Teams call, then use that access to move through the network and, in a number of confirmed cases, deploy Chaos ransomware that encrypts files for ransom.

What to do

Never grant remote-control access or install software because of an unsolicited Teams call, even if the caller knows your name or department; verify IT support requests through a separate, known channel before acting.

Timeline

  1. Sep 3, 2026

    TechRadar repeated Microsoft's warning that the Teams helpdesk-impersonation campaign was ongoing. It named no new victim and reported no closure.

    Active
  2. Sep 2, 2026

    Microsoft reported an ongoing Teams helpdesk-impersonation campaign in which attackers gained remote access, installed malware, mapped company networks, and moved toward domain controllers. Microsoft did not identify STAC4749 or Chaos, and no new victim organization was named.

    Activemicrosoft.com
  3. Aug 22, 2026

    Becker's Hospital Review reported that Nebraska Medicine and the University of Nebraska Medical Center warned staff about Microsoft Teams calls impersonating IT support, calling it the latest hospital alert tied to a known ransomware scam of this type; no confirmed breach at either hospital was reported.

    Activebeckershospitalreview.com
  4. Aug 4, 2026

    Sophos X-Ops published details naming the cluster STAC4749, describing activity from February to June 2026 hitting dozens of firms with at least three confirmed Chaos ransomware deployments.

    Activesecurityonline.info
  5. Jul 30, 2026

    BleepingComputer reported that Teams vishing calls impersonating IT support were leading to Chaos ransomware infections at North American organizations.

    Activebleepingcomputer.com
  6. Jul 30, 2026

    BleepingComputer and other outlets reported the campaign remains active, with dozens of US and Canadian firms targeted.

    Activebleepingcomputer.com
  7. Jul 29, 2026

    Sophos X-Ops published research detailing the campaign, tying it to Chaos ransomware and at least three confirmed encryption incidents.

    Activesophos.com
  8. Feb 1, 2026

    Sophos observed the STAC4749 Teams vishing campaign begin targeting North American organizations.

    Emergingcyberpress.org

Sources

Related reports