The Fake Tech Support Call That Almost Worked
A real incident at a Tech 360 Solutions client. Details that could identify the business have been changed or removed, with their permission.
Here's an uncomfortable question: if tech support called your office right now about a problem you actually have, would anyone on your team think to question it?
One of our clients found out how hard that is.
What happened
The client is a local manufacturing company. They run their accounting through QuickBooks, and one day their bookkeeper hit a real problem with it. She did exactly what she should have done: she opened a legitimate support ticket.
Then her phone rang. Tech support, calling about a QuickBooks issue.
They weren't from QuickBooks. As far as we can tell, the timing was a coincidence, scammers cold-call businesses claiming to be QuickBooks support all day long, and this call happened to land while she had a real ticket open. But think about what that coincidence did. Every reason to be suspicious of a random support call evaporated. She had a problem. She'd asked for help. Help called.
The person on the line sounded like support. They walked her through troubleshooting steps that felt legitimate. Then came the reason QuickBooks supposedly wasn't working: the company's QuickBooks Enterprise invoice was overdue, and service wouldn't be restored until it was paid. They had her download software to fix the issue, and that software included their own payment portal, where she entered the company credit card to settle the invoice. The card was charged. There was no overdue invoice. The software was theirs, not Intuit's.
How convincing was it? The program they installed was named QuickBooks Support Manager, and it came bundled with a file called IntuitFileScanUtil, dressed up to look like it belonged to the company that makes QuickBooks. Nothing about it looked wrong on screen.
What stopped it
Every computer we manage runs endpoint detection and response software, in this case Huntress. When the scammers' software landed on her machine, it got flagged as malicious, name and all.
We contained it the same day. Working from the remediation plan Huntress's security team provided, we killed the running program, deleted every file it had installed, rebooted the machine to complete the cleanup, and then audited the affected folders by hand to confirm nothing else was left behind.
The damage: one company credit card that needed cancelling, and one fraudulent charge to dispute. No customer data was touched. No accounting records. No ransomware.
A compromised card is an annoying afternoon. It's also close to the best possible outcome for this kind of incident.
The version of this story with no monitoring
It's worth sitting with what the situation looked like the moment before Huntress fired.
The scammers had software of their own choosing running on the bookkeeper's computer. They had a working payment channel she trusted. They had a believable reason to call back: overdue invoices come in installments, support cases need follow-up, there's always a next fee. And nothing on that machine looked wrong to the person using it.
In a shop with no monitoring, that's not where the story ends. That's where it starts. Nobody is coming to flag the software, because nothing is watching for it. The arrangement continues until someone happens to notice, and the ways these things get noticed without monitoring are all expensive: charges piling up on a card statement, the accountant asking questions, or something worse breaking loudly enough that it can't be missed.
Our client's version was over the same day with one bad charge. The difference wasn't luck, and it wasn't anyone at the company catching it. It was that the computers were already being watched before anyone knew there was something to watch for. Monitoring you buy after the incident doesn't cover the incident.
What changed afterward
Catching an incident is not the same as being done with it. Afterward we:
- Enabled multi-factor authentication on their hosted QuickBooks environment, so a stolen password alone can't get anyone in
- Documented the incident end to end, what happened, what was touched, what was done, so there's a record if it's ever needed
- Went over the scam with their staff, not as a scolding, but so the next call like this gets recognized in the first two minutes
I want to be clear about the bookkeeper, because it matters. She had a real problem, filed a real ticket, and took a call that appeared to answer it. That's not carelessness. That's a normal workday. These scams work on competent people doing reasonable things, which is exactly why the safety net has to be technical, not just training. Training helps people spot the tenth version of a scam. It's the monitoring that catches the first.
What to check at your own business
You don't need to be our client to close the door this scam walked through. Ask yourself:
- Does your team know that an incoming call is never proof of who's calling? The rule that would have stopped this cold: hang up and call back through the number on the vendor's official website or your existing account, every time, no matter how much the caller seems to know. Real support won't mind.
- Would anyone pay a surprise overdue invoice over the phone? Urgent payment demands during a support call are the con itself. Real vendors bill through the channels you already use, and a service shutoff threat that arrives by phone deserves a callback, not a card number.
- Would anything on your computers notice a malicious download, or does that depend on someone spotting it? Basic antivirus is not the same as monitored endpoint detection. Ask whoever handles your IT which one you actually have.
- Is multi-factor authentication turned on for your accounting and banking logins? If a password is the only thing standing between a scammer and your books, that's the finding.
If you read those four and weren't sure about a couple of them, that's worth a conversation. Book a 15-minute review and we'll go through it with you, no strings attached.
Tech 360 Solutions provides managed IT and cybersecurity for small businesses in the Kansas City metro. Built for HIPAA, FTC Safeguards, and other regulated environments.