What Happens If Your IT Provider Gets Phished?
You rely on your IT provider to keep your systems safe. But what if they become the target? A recent phishing campaign has hit IT providers in 46 countries, with the US as the top target. If your provider uses remote monitoring and management (RMM) tools, your business could be at risk. So, what happens if your IT provider gets phished? The attacker could gain access to your entire network, steal data, and disrupt operations. But you can take steps to protect yourself.
The RMM Phishing Threat Explained
RMM tools like ConnectWise Automate, Kaseya VSA, and NinjaOne are used by IT providers to manage your computers remotely. They are powerful—and that’s why attackers want them. In this campaign, cybercriminals send fake emails that look like they come from these tools. When an IT technician clicks a link, they unknowingly give attackers access to every client they manage. That includes you.
How to Protect Your Business
You don’t need to be an IT expert to reduce risk. Start by asking your provider these questions:
- Do you require multi-factor authentication (MFA) on all RMM accounts? If not, insist on it. MFA blocks most phishing attacks.
- Do you use conditional access policies in Microsoft 365 or Google Workspace to restrict logins to trusted locations?
- Are you monitoring for suspicious RMM activity, such as logins from unusual locations or outside business hours?
- Do you have a incident response plan that includes notifying clients like us?
If your provider hesitates, consider it a red flag. A good provider will welcome these questions and show you their security settings.
Specific Settings to Check
If you have direct access to your own IT systems, ensure these settings are enabled:
- In Microsoft 365: Turn on security defaults or use Conditional Access to require MFA for all users, especially admins.
- In Google Workspace: Enforce 2-step verification and use advanced protection for admins.
- For RMM tools: Enable IP allowlisting so only known IP addresses can access the management console.
- Enable alerting for any new RMM agent installation or script execution.
These steps make it much harder for attackers to succeed.
What to Do If You Suspect a Breach
If you think your provider has been compromised, act quickly:
- Contact your provider immediately and ask for details.
- Change all passwords for your critical accounts, especially email and financial systems.
- Monitor for unusual activity, such as unexpected emails sent from your domain or unauthorized logins.
- Consider hiring a third-party security expert to assess the damage.
Time is critical—the faster you respond, the less damage attackers can do.
Choosing a Secure IT Provider
When evaluating IT providers, look for those who prioritize security. They should have clear answers about their RMM security, offer AI-powered IT services that include threat detection, and be transparent about their practices. At KloudFokus, we build security into every layer of our managed IT services, so you can focus on your business.
Don’t wait for a breach to happen. Contact us today to review your IT security and ensure your provider is not the weak link.
