Fake IT-support Teams calls spread Chaos ransomware
A financially motivated group is calling employees on Microsoft Teams while posing as internal IT support, then talking them into giving remote access to their computers. Researchers at Sophos, who track the group as STAC4749, say dozens of organizations in the US and Canada have been hit since February 2026, and in several cases the intruders installed Chaos ransomware, in one case within about 17 hours of the first call. As of late August 2026, hospitals including Nebraska Medicine and the University of Nebraska Medical Center have begun warning their own staff about the same style of fake IT-support Teams call.
- Started
- Feb 1, 2026
- Latest activity
- Sep 3, 2026
- Attributed to
- STAC4749 (Chaos ransomware operators)Likely
- Where
- United States, Canada
- Sectors
- Multiple sectors, Manufacturing, Energy, Technology
- Scale
- dozens of organizations across the US and Canada, some reports citing 100+
Current status
On 2026-09-03, TechRadar repeated Microsoft's warning that the campaign was ongoing, with no new victim or closure reported.
Active: Confirmed and still going. Attacker activity or disruption is continuing.
Who is behind it
A newer, separate Microsoft Teams vishing campaign called Spring Ring surfaced around 2026-08-31 to 2026-09-02, tracked by Unit 42 and using a different technique (abusing Teams external access plus a PetitPotam NTLM relay attack against domain controllers). No source found ties Spring Ring to STAC4749 or Chaos ransomware, so it is reported here only as context, not as an update to this incident.
Impact
Attackers gain remote access to a victim's computer through a fake IT-support Teams call, then use that access to move through the network and, in a number of confirmed cases, deploy Chaos ransomware that encrypts files for ransom.
What to do
Never grant remote-control access or install software because of an unsolicited Teams call, even if the caller knows your name or department; verify IT support requests through a separate, known channel before acting.
Timeline
-
Sep 3, 2026
TechRadar repeated Microsoft's warning that the Teams helpdesk-impersonation campaign was ongoing. It named no new victim and reported no closure.
Active -
Sep 2, 2026
Microsoft reported an ongoing Teams helpdesk-impersonation campaign in which attackers gained remote access, installed malware, mapped company networks, and moved toward domain controllers. Microsoft did not identify STAC4749 or Chaos, and no new victim organization was named.
Activemicrosoft.com -
Aug 22, 2026
Becker's Hospital Review reported that Nebraska Medicine and the University of Nebraska Medical Center warned staff about Microsoft Teams calls impersonating IT support, calling it the latest hospital alert tied to a known ransomware scam of this type; no confirmed breach at either hospital was reported.
Activebeckershospitalreview.com -
Aug 4, 2026
Sophos X-Ops published details naming the cluster STAC4749, describing activity from February to June 2026 hitting dozens of firms with at least three confirmed Chaos ransomware deployments.
Activesecurityonline.info -
Jul 30, 2026
BleepingComputer reported that Teams vishing calls impersonating IT support were leading to Chaos ransomware infections at North American organizations.
Activebleepingcomputer.com -
Jul 30, 2026
BleepingComputer and other outlets reported the campaign remains active, with dozens of US and Canadian firms targeted.
Activebleepingcomputer.com -
Jul 29, 2026
Sophos X-Ops published research detailing the campaign, tying it to Chaos ransomware and at least three confirmed encryption incidents.
Activesophos.com -
Feb 1, 2026
Sophos observed the STAC4749 Teams vishing campaign begin targeting North American organizations.
Emergingcyberpress.org
Sources
- Microsoft Teams vishing attacks lead to Chaos ransomware attacks BleepingComputer Jul 30, 2026
- Hackers abuse Microsoft Teams in ransomware campaign through fake IT support Cybersecurity Dive Jul 30, 2026
- Microsoft Teams Vishing Campaign Deploys Chaos Ransomware Through Fake IT Support Calls Cyberpress Jul 30, 2026
- Chaos in Teams vishing Sophos Jul 29, 2026 unverified
- Microsoft Teams Vishing Campaign STAC4749 Deploys Chaos Ransomware SecurityOnline Aug 4, 2026
- Hospitals warn staff: That Microsoft Teams 'IT' call might be a scam Becker's Hospital Review Aug 22, 2026 unverified
- Impersonating IT support: how threat actors turn a remote session into enterprise-wide access Microsoft Security Blog Sep 2, 2026
- IT helpdesk impersonation hits Microsoft Teams once again, with the hackers hiding their activity within legitimate tools TechRadar Sep 3, 2026
Related reports
- Fake Teams support calls deliver Chaos ransomware Aug 4, 2026
- Microsoft Teams calls trick users into Chaos ransomware Jul 30, 2026
- Microsoft Teams phishing scams steal corporate accounts Jul 24, 2026
- Microsoft Entra accounts hijacked via fake callers Jul 15, 2026
- Okta warns of fake Microsoft 365 calls Jul 10, 2026
- Okta warns of fake IT passkey scam Jul 10, 2026
- Microsoft Passkey scam steals accounts Jul 8, 2026
- Microsoft Teams chat abused to spread EtherRAT malware Jul 6, 2026
- Microsoft Teams call installs EtherRAT malware Jul 6, 2026
- Microsoft 365 users get fake passkey calls Jun 28, 2026
- Fake Microsoft Passkey Prompts Steal 365 Accounts Jun 28, 2026
- Microsoft 365 passkeys hijacked by phone scams Jun 24, 2026