Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Fake Microsoft Teams update phishing is installing remote access tools

What small and medium-sized businesses should look out for today.

High Monday 27 July 2026, 16:12 UK time
Today’s look-out: Phishing lures installing remote access / RMM tools via fake Teams updates

What to look out for today

A Microsoft Teams-themed phishing campaign is using “secure document” lures to push people onto a counterfeit download page that claims Teams must be updated before the shared file can be opened. The aim is to get the user to install legitimate remote monitoring/remote access tools (e.g. RMM tools and ScreenConnect) that can then be abused for unauthorised access.

Separately, keep an eye on “shadow AI agents” (AI tools/agents created by staff without IT visibility) which can quietly gain access to mailboxes, files and workflows.

Why this matters to smaller businesses

  • It looks normal: Teams file-sharing and “update required” messages fit everyday work patterns.
  • Legitimate tools can be misused: Remote access software isn’t malware on its own, but in the wrong hands it can enable account takeover, data theft and ransomware.
  • High impact, low effort: One user install can give an attacker a foothold that bypasses many traditional detections.
  • Hidden access paths: Unmanaged AI agents can introduce new permissions and automations that security and IT teams aren’t monitoring.

Warning signs

  • An email or Teams message saying a document is “secure” and requires a Teams update before it can be viewed.
  • Being redirected to a lookalike store/download page rather than your normal Microsoft update path.
  • Unexpected prompts to download/install software when trying to open a file shared by an external party.
  • New or unknown remote access tools appearing on devices (or new “support” icons/services running).
  • Users reporting “IT support” pop-ups or someone asking them to approve access/installation urgently.

How attackers may exploit the situation

  • Initial access: Phish staff with a realistic “shared document” message.
  • Tool-based control: Get the victim to install a legitimate RMM/remote access tool, giving persistent interactive access.
  • Follow-on actions: Explore file shares and cloud drives, create new accounts, change inbox rules, and move towards payment fraud or ransomware disruption.
  • Abuse of trust: Once inside, attackers may message colleagues from a compromised account with the same “document” lure.

What to do today

  • Warn staff (5-minute message): “No document should require you to install or update Teams to open it. If prompted, stop and report it.”
  • Control remote access tools: Ensure only approved remote support/RMM tools are allowed; block or alert on unapproved ones.
  • Harden installation rights: Limit who can install software on company devices and review any recent installs of remote access tools.
  • Check for persistence: Look for newly installed remote support apps and new device management agents on endpoints.
  • Review AI tool usage: Ask teams what AI agents/connectors they have enabled (email, Drive/SharePoint, CRM, finance tools) and whether they’re approved.

Ask your IT provider

  • Do we have an allow-list for remote support/RMM tools, and alerts when new remote access software appears?
  • Can you quickly report on newly installed applications across company devices in the last 7–14 days?
  • Are we monitoring for unusual outbound connections and remote-control activity that indicates hands-on-keyboard access?
  • What’s our process for staff to report suspicious “update required” prompts, and how quickly do we triage them?
  • Do we have visibility of third-party app/AI agent authorisations in Microsoft 365/Google Workspace, and a way to review/remove risky ones?

Patch watch - only one short paragraph, and only if relevant

If your business uses workflow automation platforms (e.g. n8n) or relies on an outsourced provider that does, confirm they apply vendor security updates promptly and restrict who has “editor” access to automation workflows. Even when an issue is “authenticated-only”, SMEs often have too many admin/editor accounts and weak separation between dev and production.

One action today

Send a same-day staff alert: “If a shared document asks you to ‘update Teams’ or install anything to view it, stop and report it — do not install remote support tools.”

Related Actions On Cyber resource

CTA: Actions On Cyber – ‘Phishing triage checklist for office teams (what to forward to IT, what to screenshot, what to report immediately)’

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.