Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Law Firm Cybersecurity2026-10-01By Securing Your Law Firm

How Threat Actors Use ScreenConnect Against Law Firms

Fake IT support can misuse ScreenConnect or Quick Assist to reach a law firm computer. Learn what staff should verify before allowing remote access.

Blog post - By Securing Your Law Firm

Get your free Zero-Access Exposure Review™ | See cybersecurity awareness training

An office manager gets an unexpected call from someone claiming to be IT. There is an email problem, the caller says. Could they connect using a remote-support app?

The tool may be legitimate. The caller may not be. If staff approve the session, the caller could see or control the computer, depending on the tool and permissions.

ScreenConnect and Quick Assist are legitimate support tools. Finding either on a computer does not, by itself, mean the computer is compromised. The risk is granting access to someone the firm has not verified.

How the scam works

Remote-support software lets an authorized technician help without being in the office. Depending on its settings, the technician may be able to view or control the screen, transfer files, or keep access for future support.

An impostor may persuade an employee to start a session or install a fake update. Attackers have also used one remote-management tool to install another. Microsoft has reported:

  • A May 2024 campaign used fake support requests and Quick Assist, followed by other tools including ScreenConnect.
  • In September 2026, Microsoft described attackers impersonating IT in Teams and using a remote session to gain further access.
  • Another September 2026 report described a deceptive installer that deployed ScreenConnect as a second access route. Microsoft said it did not observe exploitation of ScreenConnect itself in that campaign.

These reports describe activity across industries, not campaigns specifically targeting law firms. They show how attackers can misuse trusted tools; they do not show that ScreenConnect itself was exploited.

What could be at risk

An employee's computer may already be signed in to email, case-management software, shared files, or a client portal. What a caller could reach depends on the employee's access and what the remote session allows.

That may include client correspondence, drafts, discovery material, or payment discussions. An attacker with access to an email session could also use real conversations to make a fraudulent payment request more convincing. The risk varies; not every session exposes every system.

Make verification routine

If someone unexpectedly asks you to install a support tool, enter a code, approve screen control, or sign in while they watch:

  1. End the call or chat. Do not use a number or link the caller gives you.
  2. Contact IT using a saved number or the firm's support portal.
  3. Confirm the technician, the reason for the request, and the tool they plan to use.
  4. Tell a supervisor or IT about pressure, an unexpected Teams message, or an update prompt.

Make the approved support contact easy to find, including when email is unavailable. A familiar product name or ticket number is not enough to verify who is calling.

Questions for your IT provider

  • Which remote-support tools are approved, and who manages them?
  • Can any tool connect when no employee is present? If so, who reviews those sessions?
  • Do technicians use individual accounts with MFA and only the access they need?
  • How does the firm spot or restrict unapproved remote-access tools?
  • How are payment changes verified outside an email thread or support session?

Ask the provider to explain the answers in terms staff can follow. Your firm and IT provider should agree on a simple process for reporting unexpected access requests.

If someone already allowed a connection

End the session. If you cannot confirm it has stopped, disconnect the computer from Wi-Fi and Ethernet, then call your verified IT or security contact from another device. Do not change passwords or try to remove software from the affected computer.

Note the time, caller details, tool name, messages, and what happened. Keep the messages. Ask IT or your security responder to check active sessions, other remote-access tools, account activity, and possible access to files. Closing the support window does not confirm the computer is safe.

Give staff a clear rule. Give leadership evidence.

Our Cybersecurity Awareness Training for Law Firms uses practical scenarios to help staff recognize and report suspicious requests. The Law Firm Security Baseline helps leadership assess core safeguards and identify evidence to request from its IT provider. Priority Security Improvements can help address agreed gaps or coordinate work with that provider.

The Free Zero-Access Exposure Review™ checks public-facing information. It does not inspect firm computers or determine whether someone gained access. Ask your authorized IT or security provider to investigate those concerns.

Contact us to discuss staff training or an evidence-based review of your firm's safeguards.

This article is for informational purposes only and does not constitute legal, compliance, or insurance advice.