# Fake IT Department Texts: The Scam Targeting Remote Workers

> A text message signed "IT Support" asks you to reset your password or approve a login: a breakdown of corporate smishing, MFA fatigue, and the reflexes to adopt when working from home.

- Source: https://www.envoyer-sms-gratuit.com/en/blog/2026-09-09/arnaques-sms-teletravail-materiel-informatique-entreprise
- Published: 2026-09-09 (9 September 2026)
- Author: L'équipe Envoyer SMS Gratuit
- Language: en
- Categories: Guide
- Tags: Cybersécurité, Smartphone, Guide, SMS, Protection des données, France 2026

---
"IT SUPPORT: your Microsoft 365 account expires in 12 hrs. Reset your password before lockout: portail-rh-connexion[.]net"

The message lands on a Thursday at 8:47 a.m. You're at home, your first meeting starts in thirteen minutes, the coffee machine is running and your work laptop is already showing a login prompt. You don't recognise the number — but then again, you don't know your IT department's number by heart either. You've never had it. So you tap the link.

That's what sets this apart from the fake parcel text or the bogus fine: this scam doesn't play on the fear of losing money, but on **the fear of being locked out of your work**. And it targets a very specific profile: the isolated employee, working from home, with nobody in the next office to ask "did you get this one too?".

![Man in a suit holding a smartphone in both hands, with a bank card and envelopes on a desk](/images/blog/2026-09-09-arnaques-sms-teletravail-materiel-informatique-entreprise/body-1.jpg)

## Why scammers moved from consumers to employees

A hacked bank account is worth a few thousand euros at best, and the bank often blocks the transaction anyway. A hacked work account is another matter entirely: access to internal email, shared files, invoicing tools, sometimes the company VPN. For an attacker, the return on investment isn't remotely comparable.

ANSSI (France's national cybersecurity agency) documents this year after year in its *Panorama de la cybermenace*: **credential theft** remains one of the most common entry points for ransomware attacks against French companies and public bodies. And cybermalveillance.gouv.fr, the government's public assistance scheme, has ranked phishing as the number one reason professionals request help for several consecutive years.

Text messaging has become the vector of choice for a reason that is both simple and slightly galling for IT departments: **personal phones sit outside the company's filters**. A work inbox is protected by an antispam gateway, antivirus software, quarantine rules, sometimes a red "external sender" banner. A text message received on a personal smartphone has none of that. It arrives raw, in the same thread as messages from family.

## Anatomy of a fake "IT department" text

These campaigns almost always follow the same framework. Recognising it is enough to defuse 90% of attempts.

### 1. A sender name that sounds internal

The message appears under an alphanumeric sender ID — "SupportIT", "MS-Securite", "DSI-Alerte" — or under an ordinary mobile number. Essential reminder: **the sender name displayed on a text message is not proof of identity**. It is declared by the sender at the moment of dispatch. In France, Arcep and the Fédération française des télécoms rolled out a filtering mechanism for spoofed sender IDs in 2023-2024 (the "MEF", a sender authentication mechanism), which has considerably reduced the spoofing of registered brand names. But a 200-employee company generally hasn't registered its short name with the operators: the scammer then has nothing to spoof — they simply invent one.

### 2. A dated deadline

"Within 12 hours", "before tonight", "final reminder". The short deadline isn't a stylistic detail: it's the heart of the machinery. It prevents the one action that genuinely protects you — calling someone to check.

### 3. A credible, administrative pretext

The most common pretexts observed in reported campaigns:

| Text message pretext | What the scammer actually wants |
|---|---|
| "Your password is expiring" | Your credentials, on a fake login page |
| "New security policy, re-enrol your device" | To get you to install a profile or a remote-control app |
| "Approve the unusual login" | To get you to approve *their* login via your two-factor authentication |
| "Update your bank details for payroll" | Your bank account details, to divert your salary |
| "The CEO needs you, reply to this number" | To open a conversation and move on to CEO fraud |

### 4. An endless link

The domain mimics corporate vocabulary — `portail-rh`, `intranet-connexion`, `sso-securite` — followed by an unusual extension. On a smartphone screen, the address is truncated. That's precisely why the scam works better on mobile than on a computer: you only ever see the start of the link.

## MFA fatigue: when two-factor authentication becomes the weapon

This is the most insidious mechanism of 2025-2026, and the least known to the general public.

You've enabled two-factor authentication on your work account. Excellent instinct. Except the scammer already has your password — harvested in a data breach, bought for a few euros. They attempt to log in. Your phone receives a notification: "Approve this sign-in?". You decline.

They try again. Three times. Ten times. At 2 a.m. Then the text arrives: *"IT Support: we are testing your account's security, please approve the pending notification."*

Exhausted, irritated, and reassured by a message that seems to explain the glitch, the user taps "Approve". The attacker is in. This technique has a name: **MFA fatigue**, or *push bombing*. It has been used in several major documented breaches in recent years, and both the US agency CISA and ANSSI now recommend abandoning simple button approval in favour of *number matching* — the code you have to copy from the login screen.

> Absolute rule: a login notification that **you did not trigger yourself, in that very second** must always be declined. No exceptions, no matter what explanation arrives by text.

For the most sensitive accounts, the sturdiest defence remains a physical one: a **[FIDO2 security key](https://www.amazon.co.uk/s?k=cl%C3%A9+de+s%C3%A9curit%C3%A9+FIDO2+USB+NFC&tag=ds0608-21)** plugged in via USB or tapped via NFC cannot be phished, because it cryptographically verifies the site's address before responding. A fake login page, however flawless, gets nothing.

![Bearded man with a shaved head looking suspiciously at his smartphone screen in the dark](/images/blog/2026-09-09-arnaques-sms-teletravail-materiel-informatique-entreprise/body-2.jpg)

## Remote work: the ideal playing field

Three factors stack up when you work from home.

**Social isolation.** In the office, checking is instant and free: you turn to a colleague. At home, checking means opening Teams, finding the right person, waiting for a reply. The cognitive cost goes up, vigilance goes down.

**Blurred boundaries.** The same smartphone receives the text from the paediatrician, the notification from the sports group and the "IT security" alert. The brain doesn't switch into work mode; it processes everything at the same level of attention — which is to say, distractedly.

**Personal devices.** Many employees check their work email on a phone they own, with no security configuration imposed by their employer. A [recent Android smartphone](https://www.amazon.co.uk/s?k=smartphone+Android+mises+%C3%A0+jour+s%C3%A9curit%C3%A9+longue+dur%C3%A9e&tag=ds0608-21) with security updates guaranteed for several years makes a real difference here: a device that no longer receives patches becomes a sieve, however careful its owner may be.

Add a timing factor: professional smishing campaigns are sent en masse **on Monday mornings, late on Friday afternoons, and during school holidays**. These are the moments when IT departments are overloaded or short-staffed, and when an urgent message seems most plausible.

## Five questions to ask yourself before touching the screen

None of them requires any technical skill.

1. **Has my IT department ever texted me before?** In the vast majority of organisations, the answer is no. Communications go through internal email, the intranet or the phone.
2. **Is the message asking me to *do* something urgently?** Genuine security information informs. A scam commands.
3. **Does the link lead somewhere other than my company's usual domain?** If you can't read the full address, assume the answer is yes.
4. **Did I trigger the action mentioned myself?** No reset request from me = no legitimate reset.
5. **What happens if I ignore this message for two hours?** Almost always: nothing. That question alone defuses the urgency.

## What to do when you've already clicked

The worst reflex is silence out of embarrassment. Getting caught is not professional misconduct: it's the predictable outcome of attacks designed by professionals. Reporting within ten minutes limits the damage; reporting after three days arrives long after the theft.

**In order:**

- **Change the affected password immediately**, from another device if possible, and above all from the official address typed in by hand — never from the link in the text.
- **Alert your IT department or your manager**, even if you're unsure, even if you didn't enter anything. Only they can invalidate open sessions.
- **Check your mailbox rules**: attackers often create an invisible auto-forwarding rule so they can keep reading your emails after the password change.
- **Report the text to 33700** by forwarding the message, then sending the sender's number. The service, run by the Fédération française des télécoms, enables sending numbers to be blocked.
- **File a police report if data has been misappropriated**, and report the incident on cybermalveillance.gouv.fr, which will direct you to ExpertCyber-certified providers.

If the company suffers a personal data breach, it also has a legal obligation: to notify the CNIL within 72 hours, in accordance with Article 33 of the GDPR. Your prompt reporting is part of that chain.

![Young woman in a hijab and pink coat looking at her smartphone in the street, next to a railing](/images/blog/2026-09-09-arnaques-sms-teletravail-materiel-informatique-entreprise/body-3.jpg)

## Reducing your exposure, as an employee

You don't control your employer's security policy, but you do control several things.

**Separate your uses.** The cleanest solution remains a second line: a [prepaid SIM card](https://www.amazon.co.uk/s?k=carte+SIM+pr%C3%A9pay%C3%A9e+sans+engagement&tag=ds0608-21) dedicated to sign-ups, deliveries and online services, with the other reserved for trusted contacts. On eSIM-compatible smartphones, this separation costs nothing in bulk. The less your work number circulates, the less likely it is to end up in resold databases.

**Don't leave your number lying around.** The WeLiveSecurity article on how scammers collect phone numbers made the point this spring: data breaches at online retailers, prize draws and sign-up forms feed most of the lists used for smishing. Every form you fill in is one more exposure.

**Protect the device itself.** A phone used to approve work logins is a critical object. A reinforced protective case and tempered glass aren't vanity purchases: a cracked screen you put off repairing means a device replaced in a hurry, with rushed account transfers and forgotten sessions left on the old hardware. Likewise, a [compact power bank](https://www.amazon.co.uk/s?k=batterie+externe+compacte+smartphone&tag=ds0608-21) avoids the classic scenario of a dead phone at the very moment you need to approve — or decline — a login.

**Manage your passwords properly.** Reusing a password between a hobby forum and a work account is the number one cause of these attacks. A password manager, free or paid, eliminates the problem in a single evening of setup. For those who prefer analogue, a [password notebook](https://www.amazon.co.uk/s?k=carnet+de+mots+de+passe+papier&tag=ds0608-21) kept in a locked drawer is still infinitely safer than one master key used everywhere — provided it never leaves the house.

## What your employer should do (and what you can ask for)

If you're in a position to suggest it, three measures change everything, and none of them is expensive:

- **Publish a single verification channel that everyone knows**: an internal number, an address, a standard phrase. "IT will never text you" should be displayed as clearly as the fire drill instructions.
- **Switch two-factor authentication to number matching** rather than a simple approval button, and deploy physical keys for privileged accounts.
- **Establish a blame-free reporting culture.** An organisation that scolds the employee who got caught guarantees it will only find out once the ransomware is installed.

The free guides from ANSSI and cybermalveillance.gouv.fr — notably the *Guide des bonnes pratiques de l'informatique* and the awareness kits aimed at small businesses — provide materials that can be reused directly, with no budget.

## The bottom line in one sentence

A legitimate IT department never puts you in a position where you have to act in a panic from your personal phone. Whenever a message combines **urgency, a link and a work account**, the only right response is to close the text and dial a number you already knew before receiving it.

And if doubt lingers, keep this asymmetry in mind: the scammer needs you to respond within five minutes. You, on the other hand, are entitled to wait until tomorrow.

{/* image-sources: https://images.pexels.com/photos/15697340/pexels-photo-15697340.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/7534799/pexels-photo-7534799.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/6406709/pexels-photo-6406709.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/6084425/pexels-photo-6084425.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 */}
