Google and the FBI warned in June 2026 that a ransomware group has been sending fake IT workers into offices to steal data or help remote attackers connect to company systems. As TechCrunch reported, the campaign has targeted law firms and involved imposters using USB drives or remote access tools on victims’ computers. The lesson is simple and slightly uncomfortable: social engineering no longer has to arrive by email. Sometimes it signs in at reception.
According to reporting based on warnings from Google and the FBI, a ransomware group known as Silent Ransom Group has escalated its tactics by sending people in person to victim offices. These imposters allegedly pose as IT workers, gain access to employee computers, and then either copy data directly using USB drives or help remote attackers connect to the machine.
TechRadar reported that the group targeted dozens of U.S. businesses between January and May 2026, with particular focus on legal, professional, and financial services firms. The legal sector is an obvious target because law firms hold highly sensitive information: contracts, litigation strategy, financial records, acquisition plans, privileged communications, and personal data.
This is not the classic mental image of ransomware. No mysterious email attachment. No dramatic red lock screen. No shadowy figure in a basement. In this version, the attacker may be standing next to someone’s desk, looking helpful, holding a laptop bag, and saying something that sounds completely routine.
That is what makes it so effective.
Most organizations have trained employees to look for suspicious links, strange attachments, and urgent payment requests. That training still matters. But attackers are adapting to the fact that people are now more alert online, so they are blending digital deception with physical presence.
A person who appears to be from IT carries instant authority. Employees are used to IT needing access. They are used to urgent troubleshooting. They are used to someone saying, “I just need to check something on your machine.” In many workplaces, challenging that person can feel awkward, rude, or risky. Nobody wants to be the person who slows down a fix, embarrasses a colleague, or questions someone who seems official.
That hesitation is the opening.
This is why social engineering is not only a security-awareness topic. It is a culture topic. Employees need permission to pause. They need clear procedures for verifying identity. They need managers who will back them when they challenge suspicious requests. They need a workplace norm where “let me verify that first” sounds professional, not paranoid.
Attackers understand human politeness, hierarchy, helpfulness, and discomfort. They know that a confident person with a plausible story can bypass a surprising amount of technology. Lovely manners, terrible outcome.
The fake IT worker tactic exposes a common weakness in human risk management: organizations often assume employees will challenge suspicious behavior, but they do not always make that behavior socially easy.
Think about the moment itself. Someone walks in claiming to be IT. They may know names, systems, office layout, or ticket details. They may sound calm and authoritative. They may create urgency. They may imply that the employee is blocking an important fix. The employee has to decide, in real time, whether to comply, challenge, escalate, or refuse.
That decision is shaped by culture. In a healthy cyber culture, people know what to do and feel safe doing it. In a weaker culture, employees improvise, avoid confrontation, or assume someone else has already checked.
This also connects physical security and cyber security. Reception, facilities, office managers, executive assistants, IT teams, legal teams, and everyday employees all become part of the control environment. The front desk is no longer just a front desk. It is part of the attack surface, with better lighting and worse coffee.
Organizations should start by reviewing how visitors, vendors, contractors, and IT support staff are verified. Employees should know what legitimate IT support looks like, how appointments are confirmed, and what to do if someone asks for access outside the normal process.
The practical controls are not exotic. Use visible ID checks, visitor logs, escort requirements, restricted areas, locked screens, USB controls, and clear rules for remote access tools. Make it easy for employees to verify IT visits through a known internal channel, not through a phone number or link provided by the person asking for access.
Training should also include roleplay or scenario-based practice. Employees need to rehearse the words they can use: “I’m happy to help, but I need to verify this first.” That tiny sentence can be a very powerful control when people are confident enough to use it.
Leaders should also make sure reporting channels are fast and non-punitive. If someone feels uneasy after an interaction, they should know exactly where to report it. A weird hallway moment can be the early warning signal that prevents a much larger incident.
The fake IT worker warning is a near-perfect human risk management story because it shows how cyber incidents often begin with ordinary human moments: trust, politeness, pressure, authority, helpfulness, and uncertainty.
Cyber culture is not built by telling people to “stay vigilant” and hoping they develop superhero instincts. It is built by giving people practical habits, clear escalation routes, and the confidence to challenge requests that do not feel right. That includes in-person interactions, not just inbox behavior.
For Cybermaniacs, this is exactly why human risk management has to move beyond phishing simulations and annual training. Modern social engineering crosses channels. It moves from email to phone to Teams to reception to someone’s actual desk. Organizations need people who can recognize manipulation, verify authority, and act safely across all of those moments.
The attacker may be pretending to fix the laptop. The real target is the human operating system.
Fake IT worker attacks involve criminals impersonating IT staff, vendors, or support personnel to gain access to offices, computers, systems, or employees. In the 2026 warnings from Google and the FBI, imposters reportedly entered offices and used USB drives or remote access tools to help steal data.
Public reporting says the campaign has focused heavily on law firms, professional services, and financial services firms. These organizations hold sensitive data that can be used for extortion.
They exploit trust and authority. Employees are conditioned to cooperate with IT support, especially when the request sounds routine or urgent. If verification procedures are unclear, people may comply to be helpful.
Use visitor verification, escort requirements, clear IT support procedures, USB restrictions, remote access controls, and fast reporting channels. Train employees to pause and verify before giving anyone access to a device or system.
Because the control depends on human behavior in a pressured moment. People need the knowledge, confidence, and culture to challenge suspicious requests without fear of looking difficult or slowing work down.