For years, cybersecurity professionals have trained employees to watch for suspicious emails, fake websites and unexpected text messages. Now, security experts are warning that some cybercriminals are taking a far more direct approach: showing up in person.
Recent warnings from federal authorities and cybersecurity researchers highlight a growing tactic in which attackers impersonate IT workers and use face-to-face interactions to gain access to company systems and sensitive information, Tech Radar recently reported. The activity has been linked to a cybercrime group that has targeted organizations across the United States, particularly in legal, financial and professional services industries.
When Social Engineering Leaves the Screen
Most cyberattacks begin online. Criminals send phishing emails, make fraudulent phone calls or create fake login pages designed to steal credentials.
What makes these recent incidents different is that attackers are combining traditional social engineering with physical access. In some reported cases, criminals first contacted employees while posing as technical support personnel. When those efforts were unsuccessful, individuals associated with the operation allegedly visited offices and attempted to gain direct access to computers and company data.
The incidents serve as a reminder that cybersecurity is no longer limited to firewalls and antivirus software. Physical security and employee awareness play an equally important role.
Why Businesses Should Pay Attention
Many organizations have procedures for verifying emails and handling suspicious links. Fewer have clear processes for verifying someone who arrives at the office claiming to be from IT support, a software vendor or a technology contractor.
Attackers understand that employees are often conditioned to help solve technical problems quickly. A convincing story, professional appearance and sense of urgency can sometimes be enough to bypass normal caution.
Once access is granted, criminals may be able to copy files, collect credentials or gather information that can be used in future attacks. Federal authorities say these incidents have been tied to data theft and extortion efforts rather than traditional ransomware deployment alone.
How Organizations Can Reduce the Risk
Businesses should consider reviewing both cybersecurity and physical access policies to address this evolving threat.
Key safeguards include:
- Requiring identification and verification for all technology support personnel.
- Establishing procedures for confirming service visits before granting access.
- Training employees to report unexpected requests for computer access.
- Restricting the use of unauthorized USB drives and external storage devices.
- Limiting access to sensitive systems based on job responsibilities.
Organizations should also remind employees that legitimate IT teams typically follow established support procedures and can be verified through internal channels.
Cybersecurity Is No Longer Just a Digital Issue
The latest warnings illustrate how cybercriminals continue to adapt their tactics. As companies strengthen their defenses against online attacks, some threat actors are looking for opportunities that exist in the real world.
For businesses, the lesson is that security awareness should extend beyond inboxes and login screens. The person asking for access to a computer may be just as important to verify as the email asking for a password.



