Fake IT support calls via Teams and Quick Assist: how your Mexico team can verify who is asking for remote access
On September 8, Mexican media reported a scam as simple as it is effective: someone poses as IT staff, messages an employee on Microsoft Teams and asks them to open Quick Assist to fix a problem nobody reported. If you run a site in Mexico from abroad, your local team is exactly who they call.
Grupo en Concreto broke the story, and it rides a bigger wave: according to Milenio, digital fraud complaints in Mexico already total 6.3 million. Here is how it works, how your people spot it and who may touch your equipment.
How the scam works
First they flood the inbox with junk. Dozens of newsletters in an hour, on purpose, so the user feels something is wrong.
Then the Teams call. They say they are corporate IT from headquarters. For a receptionist in Querétaro who has never met anyone from the Ohio office, that sounds normal.
Then they ask to open Quick Assist, the Windows tool that lets someone else see and control the screen. If it is missing, they send a link to AnyDesk, which does the same. The user reads out the code, they connect, and from there they hunt for the server.
Five red flags your Mexico team should know
- Nobody opened a ticket. There is no ticket number anywhere.
- They rush. Fix it now or everything goes down, they say.
- The chat comes from outside your organization. Teams tags it as external.
- They ask for a Quick Assist code, a password or the code that just hit the phone.
- They cannot name your support contact or your contract number.
In our experience the second one works best across time zones. Nobody wants to be the person who broke the plant while the boss in Madrid was asleep.
What real support never asks for
| Situation | Real technician | Impostor |
|---|---|---|
| How it starts | A ticket someone opened or an alert with a number | A chat or call nobody expected |
| Channel | The one in your agreement: email, WhatsApp or portal | Teams from an external account |
| Passwords | Never, they have their own credentials | Asks for them to verify you |
| Tool | The agreed one, with a log of who connected | Quick Assist or AnyDesk in a hurry |
That is how ProcessBi works with foreign companies in Mexico: every job starts from a ticket with a number, we reach your local staff through the channel in the agreement, and we never ask for passwords. No ticket number, hang up and call us. An IT support plan with an SLA puts in writing who serves your site and with which tool; the remote side is covered in remote IT support for companies in Mexico.
If someone already gave access
Unplug the machine from the network: cable out or Wi-Fi off. Do not power it down or wipe it, your support needs to see what was done.
Report it through the official channel, not the chat where the call came in. From another device, change the email password and anything open in that session. And warn the site: if they got in through accounting, reception is next.
Lock down Teams for your Mexican entity
In the Teams admin center, under external access, block chats from accounts that belong to no organization and limit allowed domains to headquarters and your real providers. Ten minutes, and most of these calls never reach anyone.
If nobody at the site uses Quick Assist, block it by policy too. One policy from headquarters covers every branch in the country.
What about your operation in Mexico?
If someone at your Mexican site gets a support call today, do they know who to check with before opening Quick Assist? If you hesitated, that is the gap.
At ProcessBi we start with a free assessment: we review your Teams settings, agree on the ticket process your local staff will recognize, and put in writing who may touch your equipment.
Book your free assessment — we reply the same business day.
Your path
Running IT in Mexico from abroad
5 of 32- Smart hands ✓ Read You are here 2 min
- Remote support ✓ Read You are here 3 min
- Nearshoring checklist ✓ Read You are here 2 min
- Retail rollouts ✓ Read You are here 2 min
- Fake IT support ✓ Read You are here 3 min
- Backups that restore ✓ Read You are here 3 min
- Secure M365 ✓ Read You are here 3 min
- Windows 10 deadline ✓ Read You are here 4 min
- Audit app access ✓ Read You are here 3 min
- CEO fraud ✓ Read You are here 4 min
- Office 2016 cutoff ✓ Read You are here 3 min
- Patch today ✓ Read You are here 4 min
- Patch VMware ✓ Read You are here 4 min
- Office 2021 EOL ✓ Read You are here 3 min
- Starlink for sites ✓ Read You are here 3 min
- Cardless access ✓ Read You are here 4 min
- Control AI on PCs ✓ Read You are here 4 min
- ScreenConnect flaw ✓ Read You are here 4 min
- Server 2022 EOL ✓ Read You are here 3 min
- Exposed cameras ✓ Read You are here 3 min
- Domain trust fix ✓ Read You are here 4 min
- Patch Cisco ISE ✓ Read You are here 3 min
- Protect the plant ✓ Read You are here 3 min
- Move to 25H2 ✓ Read You are here 4 min
- Outages and UPS ✓ Read You are here 3 min
- IT maintenance ✓ Read You are here 4 min
- Third-party scripts ✓ Read You are here 3 min
- License audit ✓ Read You are here 4 min
- Bajío fiber corridor ✓ Read You are here 3 min
- Check Point flaw ✓ Read You are here 4 min
- Cashless payments ✓ Read You are here 3 min
- AI that hacks alone ✓ Read You are here 3 min
- Field services →