Skip to main content
Right of Boom
January 27, 2025

Microsoft Teams vishing attacks that trick employees into handing over remote access!

As the threat landscape continues to evolve, Managed Service Providers (MSPs) are seeing a new, sophisticated phishing campaign targeting Microsoft Teams users. In a recent Cyber Call, we discussed how attackers are blending spam floods, impersonation tactics, and Teams’ default settings to trick users into installing remote access software like AnyDesk.

Here’s how the attack works: victims are hit with a wave of spam to create confusion. Threat actors, often using LinkedIn or company websites to gather information, then impersonate IT support and initiate Microsoft Teams chats or meetings. Because Teams allows external communication by default, the attacker gains easy access to internal staff. The attacker poses as a helper addressing the “email issue” and convinces the victim to install a remote tool—providing them full access to internal systems. From there, it’s just a few clicks away from data theft or ransomware.

These attacks are especially effective against high-value individuals like executives, and they thrive on urgency and distraction. The phishing tactics are credible, well-researched, and personalized—making traditional training alone insufficient.

MSPs must take action. First, educate clients about this specific attack pattern. Raise awareness that unsolicited Teams messages—even ones that appear helpful—should be verified through official channels. Next, reinforce security awareness training with real-world scenarios and up-to-date content focused on social engineering tactics.

Technical defenses are essential. MSPs should audit their clients’ Microsoft Teams settings and consider disabling or restricting external messaging. Enforce MFA across all systems, ensure endpoint protection is in place, and inventory assets regularly. Review incident response plans to ensure they’re not just theoretical, but tested and ready to deploy.

Lastly, evaluate vendor agreements and data-handling policies to understand where responsibilities lie. MSPs that take these steps now can protect their clients from falling victim to one of the most sophisticated phishing threats we’ve seen in recent months.

The bottom line? The Teams phishing attack is here, and it’s targeting the tools your clients rely on most. But with education, smart configuration, and vigilance, MSPs can turn this challenge into an opportunity to strengthen trust and resilience across their client base.

Guests

Andrew Morgan
Eric Tilds
Chris Loehr

Video Transcript

All right, so we're live. We'll give it about 10 seconds. They're gonna start to hear us, but I'm just going to, all right. Hey, welcome Eric. Uh, let me know Mr. Monroe, if you can see us and hear us. Okay. And then, uh, I'll give it a minute or so, um, and let people, people are coming in here, so, um, and I know we're about 10 seconds delayed, but, but it'd be great, Eric, if you can let me know. Yeah, I heard Keith that you guys got rain, but then I heard there's mudslides now as a result.

At least that, that's, thanks, Eric. That at least that's what they're saying. Uh, anyway, so Plus I got the toxic air. So from all that rain, it's kicking up all the toxic stuff. So, Yeah. And Water and everything else. Eric, is it flowing? I know you're, you know what, probably a few hours away, a but are you getting any of it your way? Uh, the, the, the toxicity in the ash?

No, it's kind of going the other way, but, uh, we did get our first rain here in about 11 and a half months, so, uh, that's all good news. 11 and a half months. Yeah. First measurable rain. That's crazy. Yeah. Alright. Alright, well, let's kick things off. Welcome everybody. Happy Monday to you all for the last, hard to believe Monday of January. That's, that's, that's crazy, right? Phyllis? We're already gonna tick off one month in 2026. Um, it's, yeah, it's crazy. Unreal. Absolutely unreal.

Um, so, um, I, you know, I was reading this article on this, uh, Ving attack and, and I'll look down for a minute. But basically here's the scenario, and I've been reading about these more and more, and I wanted to bring Chris Laer on be because he's gonna do something that write a boom, uh, that, that's really impactful and he's gonna talk about it. So even if you don't come to write a boom, you can kind of get a subset of what he's doing and how you can use it in your MSP, this tabletop.

But basically, I'm gonna sum it up here and then I'll read a little bit specifically what's going on. But threat actors are targeting organizations by sending them large amounts of spam email. They will then set up Microsoft Teams infrastructure. They will pose as the help desk.

Um, they'll obviously, you know, understand who they're targeting, whether they get that through, you know, stolen credentials and, you know, through access brokers and some set set of like that, or, you know, through LinkedIn, very ala the MGM attack, right? That happened, you know, uh, a little over a year ago.

And, um, lo and behold, if you are a somebody that's getting all the spam and someone's coming over teams, although external, but for the lay person would think, wow, it's the help desk coming to save me. And the executives have told us, you know, about the spam issue and they want us to help you right away, please download this remote, uh, remote control tool so I can help you. So that's the kind of the letting setting the stage.

Um, specifically, I'll just kinda read this one in particular and I'll put the URL in air from you, but it's, um, you know, uh, I'll quote Sophos that's been tracking this. They, they dubbed this threat actor as a stack five four, uh, 5 1 4 3 and stack 5, 5, 5, 7, 7 7.

The company said both threat actors, uh, are operating their own, um, Microsoft 365 service tenants as part of their attacks and took advantage of default Microsoft Teams configs that permit users on external domains to initiate chats or chats or meetings with internal users. By the way, um, this is one of John Strand and Black Hill's go-to, uh, for their pen testing right now. It, and it's like hot knife through butter. Um, so, you know, what I wanted to kind of do is, uh, twofold.

One, let me introduce Chris, who you all know, I should say majority of you know, who we were gonna talk to a little bit about this, but he's doing something at Write a Boom that is very similar in nature. And then before we get going, uh, my good friend Todd Schwartzman of 20 some odd years reached out to me as he got this email in MSP outta Dothan al, um, Alabama, and says, Hey, we just dealt with this with one of our clients.

Um, which was my concern, by the way, why I wanted to address this, because this is something I believe MSPs and their clients are going to be dealing with on a fairly regular basis in 2026. I'm sorry, 2025 dating myself here. So, so Chris, with that, let me start with you. Quick intro, I'll roll the Todd and, and then we'll get things going. Yeah, sure. Thanks Andrew. Chris Laer with Solace based out of, uh, Austin, Texas, we're incident response and managed security provider and MSSP.

Yeah, too many too, too many acronyms today, but, uh, yeah, so, uh, been involved in doing this stuff for, for a long time and, uh, yeah, just like Andrew said, you know, when it comes to write a boom, we're gonna be doing a session again this year, uh, pre-day session that's, uh, around instant response, specifically around a black BA situation. Excuse me.

So what we're gonna see there is we're gonna incorporate things that really have happened in, in a black BA attack and provide it in a tabletop type scenario over two hours, uh, really with the MSP as the focus. Um, so if you've attended, you know, my incident response sessions in the past, it's gonna be really similar. We don't sugarcoat anything.

Uh, we, we bring real, what real life examples from what we see, uh, what MSPs do well, what they don't well, what they don't do well, and, uh, and call 'em out for it and all those types of things. So that's what we're gonna do. And the, and the cool thing this year is, um, so it's gonna be, um, with Nom Morganton who's been on here, who has the Exigence platform, but we're also gonna have Clark Harshberger with us from CrowdStrike. So he's the director of IR for CrowdStrike.

So he's gonna be able to bring in a lot of, uh, a lot of content as well and experience and stuff, uh, to the floor as well. So it's, it, I mean, I'm, I'm stoked just to be able to do this, but uh, with him, with him involved, it's gonna be even even more special. Yeah.

And for those of you that don't know, Chris, Chris, just a one last anecdote is that you had an MSP for many years, and then when you guys got purchased by, uh, CFC, the insurance company that really wanted your IR and defer, you know, prep, you know, really the, that subset of the company, you, you, you know, sold off that piece, but so you have the perspective of both sides is my simply my Point. No, that is absolutely correct.

I mean, we were, you know, we've been around 22 years and roughly 17 of those we had an MSP side of our business and we always kept those separate, but I, I was in and when both sides of the business. And so when it came time for us to be acquired, um, you know, there was really no, no motivation to have the IT side. So we divested that. Now that's rolled up into what is the Integris. Uh, but, but yeah. Hey, and I don't want, hey, I'm deeply love MSPs, deeply involved in it.

Uh, I, I am involved in a number of different advisory councils and advisory boards, uh, regarding MSPs. So, uh, yeah, that's why I'm here to educate and, you know, and again, not to sugarcoat anything. 'cause I don't wanna see MSPs making the same mistakes that other MSPs do. Yeah. Alright, so switching gears. Todd, thanks for coming on. Um, you know, I'll just set the stage. MSP, um, what Todd what, 30, 40, 50? I forget how many people you guys are in Dothan now? Uh, about 65 right now. 65.

Congrats on all the growth, man. When we started, it's half. He's, he's Hired half Now. When we met Todd, what was there, like 10 if that were there? That many? I don't know. I don't even know. It was, that's back in oh four or something. Yeah. Yeah. Awesome growth. So, so Todd, you see this email, I'm like, Hey, this is what we're gonna talk about today. Yeah. And you're like, Hey, timely, we dealt with this just recently, so can you give everybody out there?

Hey, here's an MSP 65 employees dealing with the exact same things you all do every single day. So walk us through this, Todd. Yeah. Excellent. Yeah, one of our, uh, longtime customers, they've been a customer since before I met you actually. And, uh, they, uh, user reported, uh, email bombing, you know, just mass spam, hundreds of messages a minute going to his mailbox.

And, uh, turns out this was happening to a few other people, all executives at this company, which has been in the press a lot for good things. They're just growth. They're in a good industry around four or 5,000 employees. But he let us know morning, and this happened about six weeks ago, so called our help desk, said, Hey, getting a lot of spam. Got our, one of our 365 experts in there looking at it, looking to spam filters and adjusting it to, uh, you know, address the email bombing.

And, um, around 10 minutes later we get an alert from Huntress that this person downloaded any desk. And once the install happened, uh, it started downloading some malicious scripts and trying to run 'em against his machine, which hunters shut down and isolated the host. Well, in the middle of all this, we get a, um, we get a call or, um, what is it? We get an email from the end user saying, Hey, thanks for helping me with my email issue. And my guy's like, wait, we weren't talking to you yet.

That communication happened like five minutes later. And, uh, so the bad guys made a teams call to this end user, said, Hey, I'm gonna technical support, going to help you look into this. Got to download any desk. Um, did their thing in the middle of all end user got suspicious and realized it was coming from this other domain that he never heard of before. And he looked it up and it's some structural reinforcement company out of, uh, Indonesia, I think.

So their tenant got compromised or they're impersonating, who knows at this point. But, um, so yeah, in the middle of all this, our help desk, another help desk guy says, Hey, something weird's going on. He called in and said that he got a call from somebody in via teams. And long story short, everything kind of came together at that point, and, uh, we figured out what was going on and, uh, the bad guys never got really a chance to do anything.

They tried to enumerate the domain, but it was a work group laptop. 'cause this guy travels all the time. So all I did was enumerate like two accounts and the work group name and, uh, everything else was shut off by Huntress at that point. So yeah. So we looked a little deeper and it's like, well that's weird 'cause this tech support iteration or engagement is nothing like our normal tech support engagements. The person that experienced this, he's, he's been at that customer forever.

He's dealt with us dozens of times, but just caught him in that moment, oh no, something bad's happening and my savior on a white horse is gonna gonna protect me and, you know, let 'em in. So yeah, that's, uh, that's the high points. Wow. Wow. So, so Todd hindsight, right? Always being 2020, now that you guys have been through this, any, you know, one thing that, um, when I think about is training, right?

Important, we need it, et cetera, but it's, I wouldn't say necessarily always keeping up real time fair in like, Hey, this is the threat du jour, what's going on right now, now that you've lived this, any thoughts on how you might approach secured awareness training? I, and again, feel, I, I'd love for you to either sit in here or remote on YouTube to listen how Chris is gonna do this via tabletop. But, but yeah. Give I love your perspective. Yeah.

The, uh, well, this customer's had security awareness training for quite a while, but this particular person hadn't done a course in 11 months. Interesting. Um, we first thought this was like a BEC type thing, but this had nothing, this was strictly social engineering coming from outside the organization. So nothing was ever compromised other than inviting somebody in. Um, and the nature of their business, they have to engage with people all over the place, you know, via teams and whatnot.

So it's not unusual that some third party could, you know, call them. They're having meetings multiple times a day. Mm-hmm. So with third parties, you know, running teams or Zoom or whichever platform. Interesting. And the other thing, um, Phyllis, let me ask you this. You know, one thing Todd said that was really telling, Hey, this is a decent, so this is probably, you know, this is on the MSP side, right?

Three, 4,000 employees larger, whether it's co-managed or not, not important right now, Todd, but larger side of the M of SMB that we deal with Yeah. And doing well in the news. So Phyllis, it's clear that threat actors are paying attention now, is that, you know, automation, paying attention these days to, hey, in the morning, dump every story of this type in mind feed and with a, with a chat bot, and let me see who's making news.

But it, it, it's certainly showing relevance of, Hey, I'm gonna target these executives. Um, what what are your thoughts on, you know, on, on this in general from, you know, your perspective if you put your intel hat days back on? Oh, yeah. I mean, this is definitely, um, you know, it's just so funny that you were talking about this as well.

Well, just because I had been looking at this, um, as well, just, just, um, from other people talking to me about it, because it is becoming more prevalent and people are being targeted, right? And we see this, um, a lot more, and it's just interesting that, um, you know, you, we think that video chat gives us some sort of sense of, um, you know, kind of security. I see you, you see me, and you just see people are being targeted in organizations.

And, you know, if you're talking about nation states, this happens often, right? So, so you wanna target someone who is worth the time, someone who is going to have, um, access to high value data and someone who publicly, if something happens than perhaps it's more, it's impactful. So I think, um, perhaps criminals on the smaller scale will also be doing the same thing, right? It just makes sense. Yeah. Yeah. Who's gonna have the most data? Who's going to be the most forward facing?

Who's going to be the person who's talking to other people, who's going to be the face of the organization? So it makes sense to me. Yeah. Interesting. It's, yeah. Great. Great. Well, thanks for, uh, thanks for the perspective, Todd. Like I said, awesome. Thank you for, like I said, really important that you are here.

That this isn't just theoretical, this is, you know, and, and again, it's interesting and, and maybe, like I said, just those of you out there listening that have larger customers that are, you know, in the news, you know, be, I would use that as a kind of a key to say, Hey, this is something we should probably tabletop are your key executives in the know on how to handle this kind of stuff, um, et cetera.

So Yeah, one improvement that this triggered is we're gonna redo our onboarding documentation Oh yeah. Interest, so we can do those custom videos and everything. So we're gonna add to the how you engage with us to just do the extra step Interesting. Um, And like say, Hey, this is how we'll normally engage with you. So if it's outside this channel, be suspicious. Hang up the phone and just call us. Yeah, absolutely.

Hey, Eric, I got, I, I I, I, I, I fibbed, I'm gonna give one more question to you and then then I'll hand it to Phyllis. You were dealing with something tangentially phishing related. So when you hear this, you hear executives and you know, you think the legal side and you know, the MSA, you know, what we do, what we don't do, anything get triggered in you as, you know, MSPs are dealing with these, you know, executives, higher value. Hey, did you do the executive security awareness training?

Did you not do it? Yeah. Yeah. And, and you know, you and I talked, you know, last week about, about an, an an an issue that, that I was dealing with that kind of brings out the human side of the phishing attack. And, you know, the, the short story is, is that I have a, a client, and, and Chris knows this as well, that, um, they, the, the threat from the employer that my client fell victim to a phishing attack. He was a C-level ex, was a C-level executive, uh, fell victim to a phishing attack.

The bad guys got in, they stole a bunch of money from the company, and now the company wants to have this former executive be personally liable in some, to some extent for the damages associated with the phishing attack. And by personally liable, I mean, they essentially wanna take away stock options, right? Or the rights to exercise certain stock options, which I think is a really, really slippery slope. Um, and, but you, you know, stock options are subject to equity agreements.

Equity agreements are written very much in favor of the company to give the company broad discretion. And one of the issues that was, that if there was gonna be any, if there was any quote unquote financial, I forget the exact term, financial, um, impropriety. Like impropriety, yeah. Was, was the name, was the, the clause that said, look, we can claw back your stock options if there's any financial impropriety.

Well, is falling victim to a phishing attack and then having the threat actors steal the money? Is that financial impropriety? I don't know. I hope we're gonna settle this before they get to trial, but, um, but, but it, it, it kind of puts a human face to this because people right can, can get in a lot of trouble for this thing. And, uh, and, and it's, like I said, I think it's a really, really, really steep, slippery slope.

Um, I hope that it doesn't, uh, go anywhere beyond this, but it's, uh, it's certainly scary. Yeah. Thanks for sharing that, Eric. Really? Yeah. So, so, uh, Phyllis, I'm gonna turn it to you, uh, to ask Chris some questions. Chris, you have quite a few options, so I'd like you to be careful, um, because Phyllis is gonna claw those back momentarily. You know, just one Is wrong though.

Just one commentary on, you know, um, that situation that Eric is talking about, just because, um, um, you know, people, we always say, oh, don't be afraid to report. Don't be afraid to do these things. But people perhaps don't report when something bad happens because they don't wanna be, they don't wanna get in trouble, they're worried they're gonna be held liable, um, yeah. For, you know, damages. And so, And it should be noticed.

It should be noted by the way, Phyllis, that in that situation, the company provided absolutely zero security awareness training to my client, Or, or, and, or big, big thing you started, rightly so is, Hey, can you show me the logs? Can you show me what the forensics Yeah. And they were insured And they didn't make a claim and they didn't bring in forensics. And it's, it's just a mess. It's a mess. That is a mess. Anyway, so Chris, um, yes.

You know, what gave you the, the foresight and, um, the impetus to, um, have this black baa, if I'm saying that correctly, um, breach simulation at right of boom. And maybe Chris, can you, can you, for those out there listening going, what is a black ba Can you set the stage real quick on that? Yeah, yeah, that's a good question. So Black BA is one of the ransomware as a services organizations out there, if you wanna call 'em that.

So you could, you go, you can go research and see a lot of these ransomware as a service organizations tie back to others. So there's a whole kind of like family tree of these guys out there. Uh, but you know, for a while there, and they're still, they're still around, but for a while there, they were one of the most prevalent groups out there doing, uh, doing attacks. And so, especially what we see in the small to medium sized space, we saw them a lot.

And so, um, what, you know, what kind of inspired this, you know, um, you know, when we were having conversations with Andrew and know him about the, about how we wanted to do it this year is we did want to, you know, purely focus it on, on a situation and a scenario and not go through multiple scenarios or whatever. And this one seemed to be fitting because the fact that they're emulate imitating or, or, or a support organization.

And for MSPs, that means they may, they may not necessarily be directly imitating you, but when, if it's the support, the, your client's gonna assume it's them. And so it just makes no sense that it's gonna hit closer to home, uh, in this type of scenario.

I mean, you know, for years we saw a lot of these, we saw these threat actor organizations, ransomware of service, you know, focus on MSPs to attack MSPs, but we're not seeing that as, as much anymore, but we are seeing where they're trying to take advantage of the relationships that is, or, or whatever the case may be.

And, you know, I, I can also say that, you know, we see, we see where these ransomware groups might not try to attack an Ms P to get to their clients, but they will find a client with a particular issue, find out they have an SP, and then through some other methods, start to find out that whatever that issue with that one client is, is commonplace for the rest of the MSP's clients. Mm-hmm.

So we'll start to see them launch a tax against the other MSP's clients, not necessarily going through the msp, but seeing stuff like that. So sometimes shared credentials, uh, the same configurations on firewalls or VPNs and those types of things. So yeah, really this content is to be as much as relevant as we can to something that's currently happening, as well as something that kind of hits the MSPs, you know, in the kidneys to where they feel it and, and takes, takes some lessons away.

Those, can I ask Chris a quick question there? Just, Just tell him No. Yeah. I was about to say no, Andrew, I have the floor. No, I'm just kidding. You have the floor. Absolutely. Hey, so Chris, a a lot of MSPs on their website have, you know, our team in today's day and age, are you recommending get rid of our team? Because again, if I'm a threat actor, hey, it's Chris Lair, like I'm going to solace page going, Hey, it's Chris.

Yeah, I mean, it's, well, I would say a few, you know, back in 20 18, 20 19, I used to kind of criticize people for having all that information on their website. Not just MSPs, but companies in general, because you could tell that's where the threat actors got the, their information from. Uh, I, I still say you need to make it a really good reason to put that out there.

And if you're gonna do something, have somebody that's pretty obviously like, like obvious, like your CEO that's gonna be easily identifiable other ways. But at the same time is there's so many sources available now for this information. I mean, that helps. But I mean, these guys, these bad guys, they use ZoomInfo and all sorts of other sources to get stuff. So it's, it's, it's a tough thing.

I think, you know, when we were talking about Eric's client, I mean, he's an exec, he's gonna be targeted. So, um, you know, and the other thing I, I didn't want to, to forget is this style of attack where they deluge you with emails to either cause a distraction or to cause stress or urgency or whatever. This is being used in this type of attack. But we're also seeing it be used.

I, I had somebody call me up where their, their, uh, bank, their online banking, what they used for a CH and wires the exact same method, dilu, they, the credentials were stolen. And while the bad guy was in there doing the fraud and the online banking system, they deluged the company with emails. So they were so distracted with all these emails, they're trying to figure out what's going on, they're not paying attention to what's going on in their bank account.

And they lost a quarter of a million dollars in one day as a result of that. So, you know, back, you know, Todd, Todd dropped. And on the security awareness training, the thing that I would emphasize is, Hey, this is the stuff that you at least have to have a conversation about and say, well, man, maybe it's just some weird spam thing going on. No, that's usually an indication that somebody's trying to create a distraction or something for you.

So it's, it's less about identifying to me and to my opinion, you know, a, a bad email. It's more about seeing these other things that could be used to distract you and, and to do things while you're distracted. Got it. Thanks bud. Yeah. Interesting. So if, um, folks, uh, go to the tabletop at right of boom, um, how is it that you are going to, um, you know, kind of start off the black ba ransomware attack during the tabletop?

Yeah, so basically when you create the, the tabletop, I mean, we aren't giving anybody any indications of what we're doing ahead of time, right? So we're gonna, now what we do is we do level set the expectations. 'cause you know, Andrew knows we've been doing this for a long time, and, you know, we get in these scenarios and there's always one guy in the room going, well, that would never happen to us because we have this in place. We have that in place.

I mean, you just had this one guy in the corner. So we level set that and say, we know we're not going to account for all the different controls everybody might have in this room, but we put forth the different scenarios and then, uh, we basically allow people to start making decisions on which way they would go or not. And then we provide feedback on that. It's incredibly interactive. There's gonna be people walking around.

I mean, it's, it's going to be, um, you know, people will be able to, you know, take somebody, like if Todd was in the room, Todd would be able to interject as well as ask questions. So that's the idea. Uh, and we usually will cover, um, we'll cover the technical side, legal side, you know, what we see people do wrong in regards to how they communicate with their staff when something like this goes on and that type of stuff. So that's how it's all gonna be.

And when we do those different steps in the scenario, those different chapters or whatever you want to call it, they'll kind of introduce those different elements. So it's, it's technical is just one, one piece of it. We, we want to get emotion in there, we wanna get, you know, somebody in there throwing curve balls and, and doing those types of things. That's, that's, that's what we do in our session. That's awesome.

So like, what do you think, you know, this is kind of off script, but when you do this kind of exercise, what are you hoping, like are key takeaways for folks that attend? So like, Hey, here's what you expect. You're gonna, you're gonna go through this, but then when you walk away, you'll be able to say, okay, this works, this doesn't work. Or what are they gonna do when they go back? Yeah. Right.

So the, the key takeaways is, number one is to go back and, and educate their MSP their organization internally first. And, you know, talk about the lessons learned and to also review things that they do, whether, you know, a lot, most MSPs today, especially the ones attending, right? And boom, are usually in good shape about documenting the things of what happens since something like this occurs. Who's supposed to document what, what you're not supposed to document.

So I think we've, we've moved the needle there, uh, but we do want them to go back and, and kind of spread the word within their organization and potentially update incident response plans, policies, that type of thing. And then the second piece is to be able to take that to their, to their clients and, you know, a, to educate their clients and make sure that they're aware of the risk and that type of thing.

But b, I do think having these types of conversations does lead to additional sales as well. So maybe, uh, you've been wanting this client to, to do something more with regards to security, take different things to another level, introduce another product, whatever the case, and it's been tough sledding, well, now you can come back from right, a boom, not only our session, but everything else you learned throughout the write of boom.

And to be able to incorporate that in and potentially get your clients to, to add more products and services also, that's just, Gary's not on, I had to say that it's, But it's also a good, it's, it's about stories, right? I mean, Chris, you know, now you have a, like, again, the, the B right, the B word, it's about the business. And now you can say, Hey, look, I wanna kind of run through this scenario that we just dealt with, right? And how it impacted a business.

And that's staying away from the technical conversation, the security, you know, bits and bytes conversation that don't necessarily drive the outcomes we want. Um, No, that's exactly right. And the bring forth examples of different types of businesses, right? So just like last week I got a call from a law firm who had been, been hit by some form, and I think, uh, the, the ransomware wasn't able to, uh, encrypt again. They did have tres, and it did stop things.

And, and, but they did have some data get out. But when that guy called me, he's like, look, he goes, I have insurance. I talked with my broker. My broker can't get any movement going on there. He goes, personally, I'm losing more money by the hour because my attorneys can't bill. And he goes, plus, because they kind of isolated everything, he goes, plus my attorney yesterday was in court and he didn't have his, he, he wasn't, he didn't have his stuff with him.

And the judge showed him no empathy and just lit him up, I guess, about he didn't really care that their office had been a victim of a cyber attack. And that is, so, he's like, I don't care what goes on. I'm gonna hire you guys. I'll deal with insurance after the fact, but I'm losing more money.

So I think that's what we have to stress with people now when they're talking to, with their clients about the businesses, is really kind of get down to these examples and share these stories and talk about, Hey, you might not think you could, you're losing money right away, but in your case, you might, in your other case, you might be able to survive three days.

But the other thing is just to understand the pain that you go through for weeks and even months after the fact when dealing with these situations. I mean, look at, you know, the example Eric showed, I mean, that that email compromise was months and months and months ago, and now it's just coming, coming the way. So if you don't take action, you're gonna be in a lot of trouble. But if you do take action, you just have to understand that it's not gonna be an overnight situation.

It's gonna carry on for a while. So that's what we try to convey in these, in these events, and hope people take those lessons and communicate them to others. I think that's really a great point. You know, you bring up the example of the law firm. My, my, my good friends are lawyers, and it's against company policy right now to print anything out, because there is work at home and all these things. You're not allowed to print anything out.

So everything goes down and you're at court, then what do you, what do you do? That's just another real world example of where you can look at the impact of business, what would happen to your business. That's exactly right. Yeah. Or we, we've had a situation, another kinda law firm where they had an, they had some order to destroy, like certain stuff they had, they under ordered to destroy it, and they did, but they, they forgot one spot, Dropbox, and the Dropbox got compromised.

So then they had to go and explain, uh, to people, well, how that happened, why that happened. And it was, it, it, it ended up being not as painful as they thought it would be. Mm-hmm. But those are the things you have to share with people in those lessons is it's just the smallest thing can disrupt your business and cause mistrust with your staff, mistrust with your clients. It's, it's terrible. Yeah. Um, no, those are, those are great examples.

Speaking of training and, and, and, you know, understanding your company policies, we often talk about, um, anti phishing training, this, that, and the other. And we see phishing still being successful today, and I'm sure you'll go over that, um, at the tabletop. Why is it that fishing still works today, even though we've, we have beat that drum to death? Yeah.

I mean, fishing is, I mean, fishing is, the thing is, is it's, they, I don't wanna call it spraying prey, but it is, they just spray, spray, spray, right? And I, and when we have people that are victims of the phishing attacks, we have people that are really like you, they, they feel incredibly bad because they know that they were like the one person that was advocating for, for phish testing and training and that type of stuff, it was just a bad day for them.

They were overwhelmed, or there was just a lot going on in their personal life, and then they got distracted and they fell for it. I mean, I, I know of an MSP that came to me, uh, a pretty prominent MSP and, and they fell for fish. Their, their financial staff, uh, fell for Phish. And it was in the six figures as far as the loss goes. And these guys, I know these guys, I mean, they practice and preach this all the time, and it even happened to them, you know, in their own back office.

So, uh, it, I, I just see it a lot of that, it, it's, we, it's not so many where we're seeing people get phished that are just totally, like, not trained or, or ignorant of, of what's going on out there. It's just these people, it just, it takes one little, one little, I guess, moment of their lives where they weren't focused on it and they, they get duped. And, and also Chris, I think it's the, the change, you know, we always talk about TTPs, right?

Phyllis, it's the, it's the change in the tactics. I mean, yes, we still have people clicking on links. Yes. We still have, you know, token hi hard hijacking things like that, mobile QR code. But, you know, take this scenario that we're talking about right now, these, this pretty clever, I mean, for your average person that isn't immersed, right? Take us all here, we live and breathe this and think about it and talk about it on a continuous basis.

But your average person, that's a pretty believable clause, right? You got hammered with spam, the help desk. 'cause they even, you know, the way Todd said, Hey, you helped me out. Thanks. Right? Right. And they're fast. Well, and they're fast. And I think AI helped them in the most rudimentary forms just with the way they communicate and the language stuff. So, I mean, it just comes across so genuine and so clearly now that it is tough to distinguish.

I mean, even on our side, our CEO was impersonated video wise, and it was really, really good. I mean, it, it fooled a lot of people. It didn't, you know, there was no adverse outcome as a result of it. But I mean, it doesn't matter who you are. I mean, these guys are, are creative. They're taking advantage of a very common tool set that's out there. I saw a statistic, I think this is like 83% of the organizations in the US use some form of Office 365 5, right? Yeah.

So I mean, So I think, you know, right here we're making the case for, hey, anyone can have a bad day. The well-trained person, the really savvy security person. So that phishing email, um, may is probably gonna work, you know, ransomware's going to hit. So, um, what happens next, um, Chris, and, and how is it that, um, MSPs should prepare for that?

Yeah, so one thing in, in just viewing the chat, I mean, some people, I mean, I think the, let's, let's just take Todd's example where he says he, his client has, they do a lot of meetings and they do a lot of communicating with external parties. So it wasn't uncommon for somebody to reach out, okay, well, that there, there are risks there that they accepted.

So, you know, without, without speaking for Todd or he, but whatever, but you know, when, when you make a decision to have those external parties involved, do you completely understand the risk associated with doing so? Right? And are there additional things that you should do as an organization when an external person comes in to kind of verify or validate them? Right? So those are some questions we need to ask.

The other side of things is, and we've seen this even with business email compromises where they're moving laterally into other parts of 365, like SharePoint is, is I think people we're pretty lax because we're so attuned to on-premises stuff and that we need file folders and all that kind of stuff, secure SharePoint, we're not concerned with this in 365, it's behind MFA, but we just weren't really thinking and, and articulating, again, the risk to our clients to say, Hey, look, all that stuff you got dumped out there in SharePoint, it's really easy to dump it out there.

People are saving videos, phone conversations, documents, contracts, you name it, it's all out there. Those guys move laterally. It's all there access and to take. And so I think as, as, as providers, we need to get in front of, you know, I say get in front of this, but get in front of this as quickly as possible to, you know, just better articulate what the risk is.

And so when people are doing this, they understand, hey, you're accepting the risk by doing nothing further, or these are the additional things you need to do, uh, to better protect your data and to protect your people. Um, but it's, it's a tough one. I mean, I mean, take, I mean, I just know, like with teams on your phone as an example, there's a lot of stuff that you can do on your iPhone between apps and teams that you can't do on your Windows device.

And there are ways to lock that down, but it's painful. But if you're used to doing that on your device, and when those features are taken away, it can upset workflow and, and kind of do things. So there's a lot of work and effort involved to understanding these things and to make sure that things are locked down enough to where it doesn't impede the business. And if it does impede the business, the client understands that that's the best direction to go. That's also just interesting with BYOD.

Like, you know, a lot of people just use their personal phone as an option for work. And so then, you know, what are the rules around, well, you're gonna lock down my personal phone. Like, y you know, it's, it's very interesting to think about My device. What visibility do you have?

I mean, the, the mobile devices are the toughest one, especially now because, you know, on your mobile carriers, we, we see that for some reason, the IP address they give you is associated with some other geography in the country. Hmm. And so it, it'll trip an alert says, Hey, you know, we see your device coming from St. Louis and you're in San Antonio. It doesn't make any sense, but for some reason that IP address given out by the provider does that.

So there's just a lot of stuff weird going on with that, Andrew. Yeah, I was gonna say, I wanna make sure Eric, and Yeah, it's Eric's turn. Sorry, Bob, Bob get it gets, gets in some, some, uh, some time here. But, um, you know, this is where I'll just give a plug as always for Eric Woodard and the ci IS controls is that this is where you gotta have a shared responsibility model when it comes to your inventory, which he does really well when it comes to mobile.

If they're using mobile and they're not letting you protect it and ringfence it and do the things you need to do, Chris, on a security control basis, then hey, that's your responsibility. So with that, Eric, over over to you. Thank you. Thank you. And I'll, I'll be quick. So, uh, so Chris, Andrew mentioned briefly, uh, at the onset, the MGM attack, right? And, and of a, of a year plus ago. And, and that was a, a situation with impersonation, right?

Somebody impersonated, someone called into the help desk, one thing led to another. So one of the things that, that you're gonna be simulating is, is impersonation. So how do attackers use this to make things worse during a ransomware or similar attack? So, I mean, the impersonation stuff usually happens, you know, at the beginning. And a lot of times the ransomware attack, we don't see the impersonation.

It happens sometime and before that to where that person was tricked into providing credentials or whatever the case, or, or either even some type of information, tribal knowledge or whatever you wanna do that allow the threat actor in. Um, so we haven't seen, you know, once, once the attack happens, you know, we're dealing directly with the threat actor and, um, and dealing with them on that side.

But, you know, not to say that, uh, you know, not to say, not trying to give anybody ideas here, so I wanna be careful here, but that we've seen cases where the threat actor, you don't pay them or you stall or whatever, they, um, they, uh, threaten to go to a regulator or whatever. So, you know, you could see at some point where a threat actor tries to imitate somebody to a regulator to even make your life more miserable.

And if that happens in the near future, I'm gonna be mad that, uh, somebody took my idea and ran with it. But, but yeah, I can definitely see that happen. So I've sat through a bunch of your tabletops before, and one of the things that, that, that you often do a really good job at is, is simulating the behavior of leaders in organizations. And, and I guess this is a, a rhetorical question, but do the leaders tend to be calm, cool, and collected, or does it tend to turn into an all out panic?

No, I, I would say overall they do, but there's always that one out of a hundred that goes sideways. And it's just weird how it works. I mean, we've had situations where, uh, you know, we have people that necessarily aren't in it directly, but they may be in a financial position and in the company, and they just start stirring things up from, from the side. I, I where what's interesting is, and and with, with non-profits, it seems more prevalent than anywhere.

Everything seems to be going smoothly. But then they bring their, they have to bring somebody from their board in, and the board member, the director is who just stirs things up, or he wants to bring in their own people or whatever the case may be. And that gets really, really ugly.

Um, and then, uh, I have seen where, uh, even with, um, even more so now, and I don't know if that's just because the fear factor involved, but where we've seen, you know, the MSPs start to get very uncooperative about doing the things that we need to do for investigative purposes or, or whatever the case may be. And that's not a good look either, but yeah. So we're gonna incorporate some of that stuff.

So I haven't seen too many where, uh, you know, the CEO is just all irate and demanding stuff. I mean, we've had one case in particular happen that I might incorporate some of that stuff into. Uh, but yeah, it, it, it still happens. Okay. So, so when the breach happens, the fallout isn't all just, you know, operational bits and bytes. There's a lot more to it than that.

So how does something like a security incident impact a company's reputation, its reputation with its customer's, reputation with its partners and, and others? Yeah, I think the first really thing it does is it seems to impact the employees the most, right? The employees seem to lose the trust immediately, and they start to worry more about what's gonna happen with their data and that type of stuff more so than anyone else.

And then the next, the next one would be, um, more like partners and stuff. So especially in healthcare, where we see their vendors won't support them until there's some type of evidence that says, Hey, the bad guys are out and they're now more secure. So that's where we see a lot of those, those relationships deter. And then I would say last would be with the clients. Um, and I would say it just kind of depends, right? I mean, it's interesting.

We've had the number of small companies, you, you're talking less than 20 people, but their clients are massive, and they might have four or five just massive clients, and that gets, that gets pretty tricky and dodgy. Um, or they have, their clients are the government, so they might not be a DOD uh, agency, but another government, federal government agency that you have to deal with, then that gets dicey.

And then I would say the, you know, the worst case is in when you have to deal with, um, we see a lot of people that don't realize they have regulators that they report to, that they didn't realize they report to. And I know it sounds weird, but take the New York Department of Financial Services as, as an example, a lot of people don't realize 'cause they're in another state, that all they have to do is a very minimum requirement for them to fall under that regulatory body.

And the, and when they find out about that, it's when they've had one of these attacks and it's a rude awakening. So that's just kind of where we see a lot of these conflicts arise when we're working these cases. So you've mentioned the, the MSP's role in, in all of this. Can you talk to us about why the MSP's sales conversations with their customers should start with a business impact analysis?

Yeah, and I mean, the business impact analysis, if perform correctly, and if, you know, if you, if the client understands its purpose and has significant input into it, then they'll have, they'll have the buy off on it. And that's really what kind of open it should open a business leader's eyes to why you're asking them to do the things they need to do. So, and, and to understand all the facets of their business, all the pieces, the link always come back to that keystone pipeline example.

The pipeline itself, it was running fine. It was all the back office stuff that was impacted. So since the back office stuff was impacted, the pipeline had to stop. So, you know, so you could have the greatest security on that pipeline, which you should have. But on the back office stuff, if you're not doing the same stuff there, you're gonna get yourself in trouble a lot.

And so doing a BIA if done right will show your, your, that your clients from, Hey, here are the dependencies in my business. Here are the critical points. Hey, maybe at this time of the month it's more important than this other time of the month or this time of the year, and so on and so forth. So understanding all those things.

I mean, yeah, I take a ski resort business, there are times you definitely don't wanna be hacked in the ski resort business and sometimes where you don't wanna be hacked, but it's a little bit easier to, to deal with. So another good example. Appreciate it, Bob, to you. All right.

So I mean, Chris, the one thing that everybody kind of wants to know, um, at least in this MSP, where do you know, where do you feel like are the, um, where do most companies fall short in being able to deal with a, a group like this? Like the Black master folks? Yeah, so a lot of people, number one falls short is they might have an instant response plan, but it just isn't something that they can do.

Like they took a template, just kind of filled it out as if it was a form and didn't really relate it back to their business. And who, who are the applicable parties in their business that can actually do the things in the incident response plan that it says that need to be done. So that's number one. Number two is we do, we do see a lot of people that have no idea what to do from an insurance perspective.

They don't know who to call, they don't know their policy, they don't even know how the policy works, that type of thing. So that's, that's, or they don't have, yeah, the same accountant ones that don't have insurance. Uh, but you know, when you have insurance understanding what those things need to be done. And I think in the, in the fall short things, it's just people just don't have an understanding of these things aren't very difficult, right?

So I always tell people, this isn't like James Bond type stuff where yeah, I mean, it's, it's configurations, it's, you know, it's that decision to, um, you know, use, use that firewall for another year, for another two years and just eek it out so you don't have to spend another thousand bucks on another one, or whatever the case may be. Um, or, you know, it's on the, it's on the hardening and the configuration side of things. It's, you know, hey, you need to migrate.

They want to go to 365, well that's fantastic, but there needs to be a project and we need to talk about security and hardening and those types of things. Also, training people, I think, especially in small business side, they don't appreciate, um, how much it you should really train people on, Hey, look, you're still using Outlook. It's a little different world now so that, you know, when you're using on-premises exchange, maybe this is the stuff you had to deal with when you move over to 365.

Some of those things still apply, but there's some new things now that you need to be, to be concerned about. So I just think that you, you're, you're not trying to burden these small companies down with a bunch of extra steps that are meaningless, but they are things that enterprises do, uh, as a normal part of their practice. Uh, and those things need to be kind of sized down and done correctly on in the small business as well.

Yeah, I mean, it, it's one thing to have an IR plan, it's a whole nother thing to actually go and practice it and get used to deploying it, right? I mean, being able to actually execute on it.

And I think that's, for me, that's the thing I see missing is they, like you said, they'll check a box, they've got something written down, but it never, if they've never actually sat in and exercised to try, and even if it's not their IR plan, just being in an exercise in general, you know, helps them get smarter about how to, to really work those problems. Right? And so I, Yeah, I always tell people, I, you know, I came from the banking world, right?

And still to this day, you have to do IR tabletop testing, you gotta do disaster recovery, tabletop testing, you gotta do pandemic tabletop testing. And the one things the banks learned through the pandemic tabletop testing is all that pandemic stuff they did ahead of time didn't prepare 'em for covid. Right? Now, I'm not blaming them.

'cause I don't think, I think anybody, if anybody was prepared for covid, then you gotta get some conspiracy theories going, but at the same time, it taught em a lesson that says, Hey, look, you can't shortchange this, you can't cut the corner on this stuff and does need to be, um, you needs to relate to something that that's gonna really potentially impact you. And, um, that's the case. Yeah. Yeah. So how close is your tabletop gonna kind of get to?

Because I, you and I have both sat in, I mean, you sit in on a million of these, I've been in on a bunch of these myself, right? And actually actual, actual incidents, right? And there is a world of pressure, um, especially from the MSP side because we dealt with the SolarWinds deal, right? So that was something that we were fielding ourselves since we were a client of SolarWinds.

So how, how close does your tabletop get to that, the level of chaos that goes on in something like this from a ransomware standpoint? Because there's a lot of pressure in these things, right? There Is a lot of pressure, but I know that there are other tabletop exercises that, that, that others do, uh, that are more like introducing super chaotic stuff. And that's not the idea of this one. I mean, I think those super chaotic ones, those guys do a great job of that.

And I've been involved in those, participate in, and they're great. And I think those are really good from a technical perspective. Um, we try to slow that down a little bit. I mean, we only have two hours and that's usually supposed to represent two weeks typically, uh, just say on average. But what we're trying to do is just try to incorporate those things and, and, and bring, so we do, I will incorporate real life stuff.

We'll just anonymize it, blend it with things and that type of stuff to introduce it. But I don't want there to, I don't want people to, uh, go run down to the local, uh, CBD store and have to pop a bunch of gummies after I'm done. I want 'em to learn stuff, you know? Yeah. So I mean, what are, what do you feel like the top two or three things are that NMSP can learn and, you know, to kind of be prepared for an, you know, ransomware event or attack of this type?

Yeah, I think one thing is, I mean, it depends on your customer base, but you can't treat 'em all the same. And your customers, I mean, you can't take a, you know, cookie cutter thing and apply it to all your companies, all your clients, especially if they're in different industries, different things. I mean, we see companies that operate in different time zones that can impact things.

I mean, we've had a number of cases where they have operations, they're based here, a bulk of their operations is here, but they have something in Asia, they have something somewhere else too. And those are impacted as well. They might not have been infected, but because you're down, they're down. And that kind of complicates things a lot.

So, I mean, there's just a lot of things that I think MSPs need to take the next step in understanding truly what an impact can have an incident like this can have, uh, even if it's a simple, just you lost some money or there was just a data breach or, you know, it's a full operational impact. I mean, I, I still say that the data breach side of things is, is the most punitive 'cause you have to deal. 'cause I mean we've had attorneys on here.

I mean, they'll tell you that the, the number of records, uh, that are impacted used to be a higher threshold for, for class action attorneys to want to be involved. But the numbers keeps getting low and lower. So there's a lot of, you know, ambulance chasing class action attorneys out there looking for the latest breach to go class action on, you know, somebody. Yeah.

So I mean, since we're talking about, I mean I think it's a good place to wind up 'cause it all comes back down to this in my opinion, but let's just talk about cyber insurance. How does the presence or absence of it really kind of affect, um, the aftermath of a situation like this? Yeah, so we can start with the absence.

So the problem is when it's the absence of cyber or we do have people that have cyber insurance that have really high deductibles and that then it makes them just unfortunately count pennies. And, um, and, and that that it's very difficult to work very quickly and to get people back up and running and throw resources at it and do that type of thing.

I mean, you can have a situation where there's a live threat actor involved and that could, you know, take six or seven of my people getting in there to get that threat actor out, right? And to understand what the situation was, how long the threat actor been in all that kind of stuff. Well, you're talking about them working, you know, eight to 10 hours a day. Let's just say it's, you know, you can do 80 hours.

So when you have insurance, that eases your, your pain of having to worry about that financially. So when you don't have insurance, the number one issue is, is your account pennies. We also see people that are apprehensive to bring in legal in for the same exact reason. And so, you know, I tell people it's, it's, it's equally important.

It's very rare that we have a case where you don't need some type of legal representation and advice in there from a breach attorney and, and the, and, and, and the breach attorneys, we work with them, all of them, you know, try to provide reasonable rates and do that type of thing and try to do minimize things and not have a hundred calls a day to drive up, drive a breaks. But when you don't have insurance, it just comes down to a dollar issue right there when you do have insurance.

Um, yeah, I mean it helps, but it also helps to understand what insurance is gonna do, the questions they're gonna ask, that type of thing. I mean, you gotta make sure that what you put on your application policy is accurate and reflects right that you're not wrong if you said you got MFA on everything, you better have MFA on it. If you have, if you said you have a hundred thousand records, uh, that you store that have PII, you better have a hundred thousand or less.

I mean, those types of things is what, what bites people. So you don't want to go in a situation where coverage is questionable, um, because that just makes things ugly as well. Yeah, there's so many facets to this, right? Because it, most people don't know if you have cyber insurance, you actually can get kind of a free consultation with your incident coach that's associated with that policy in advance. It's free. They'll, they'll talk to you, tell you what to expect, how that's all gonna go.

Right. And Eric will tell you sometimes it makes sense for you to get a different incident coach than the one the insurance provider may have as your primary. Right. Because you know, one's working on your behalf, one's working on the insurance behalf, even though they're NDA. There's so much we could talk about about just that, that little bit. Yeah. But that's, um, but I'm with you.

I, I, you know, the, the big deal is just if you have it, make sure it's enough, make sure you understand how to use it, make sure you know how to, in your incident response plan, you know how to really start all those conversations correctly. So Yeah, make sure it's updated, right. You acquire somebody or that type of thing.

You need to make sure you go back and figure that out because we've been in those situations too, where there's just a, a, a policy, but it only covers an entity, not the entire organization itself. And that causes issues too. Yeah. And don't leave your damn policy on your network. Take that thing off your network and store it somewhere else for goodness sake. Exactly Right.

I mean, in a very recent case, you know, the forensics we looked at the very first search term when the threat actor was in there was I-N-S-U-R Yeah. Was the very first, first term they looked for. So they're looking for that policy. So you, you need to have access to it and b you don't want them to have access to it. So that's the two sides of that. Yeah. Yeah. Most of your providers will keep a copy for you online so you can get to it all to band. So another little thing that You learn.

Yeah, good. See we have an app. You can get to it through your app, so Yeah. Yep. Alright, Andrew, back over to you. Yeah, no, it's a, it's such a great point about the policy, um, because, you know, we, we know that they're looking for it. It's almost like the same thing with the bank bank statements, Chris. It's like, hey, um, we want 300 grand, we don't have 300 grand. I got your statement, I know you have 300 grand. Right?

It's those things that are on the network or the policy that they're gonna go right for, right Chris? Yeah. That, or I mean, we've had people, victims where they have their Instagram accounts. They say, we don't have any money, but they, on their Instagram accounts it's shown, shows them driving in their new Lambo or taking their wife and vacation over in France or whatever the case may be. So Yeah, it could be your financials or whatever you've decided to put out on social media. Yeah.

There's, it's gonna be tough to argue that you don't have any money when you have all that stuff posted out There. That's right. That's right. So, so in closing, you know, with one minute Ann says, Hey, what about the good news? I, I think the good news is one, um, Chris, your, your session was like literally sold out. Not that it was for sale, you know, like it was occu, like it was sold out in the sense of there's no room. Right. Very Fully subscribed, fully Meed. Thank you.

Don't beg me to come in. There's no way to get you in. Yeah. And, and so that was a, you know, and, and, and the fact that, you know, a few years ago MSPs weren't monetizing incident readiness tabletops. And this falls into, you know, the VCIO, sorry, vc. So category we're seeing. Mm-hmm. So I'd say, and like you said, the opportunity to educate, um, this is a whole nother area that, um, is really important, uh, for MSPs.

And, um, so that's what I would say the good news is, um, and, and the fact that you all are, are here with us. So, um, with that, um, Chris, thanks a million for coming on and talking about this. Bob, as always, thanks for coming on and filling in Eric as well. Um, Phyllis, great to see you back and, uh, in, in all that. Wishing everybody a fantastic, uh, week ahead. We'll look forward to seeing you next Monday. Take care. Thanks.

Related Videos