What happened
Sophos disclosed on May 21, 2025 that a 3AM ransomware affiliate had attacked one of its clients earlier in 2025 using a combination of email bombing and phone-based impersonation of the victim's own IT department. Sophos observed at least 55 attacks using this technique between November 2024 and January 2025. In the documented case the attackers stole 868 GB of data but were stopped before encryption.
How the deception worked
The affiliate first buried a target employee under 24 unsolicited emails in three minutes, manufacturing an apparent IT emergency. While the inbox was still filling, an operator phoned the employee using a spoofed caller ID that matched the company's real IT department number, offered to fix the flood, and asked the employee to start a Microsoft Quick Assist remote session. The employee granted control, giving the attacker hands-on-keyboard access. The attackers then exfiltrated 868 GB to Backblaze cloud storage over nine days before attempting ransomware deployment.
AI involvement · No AI reported
Sophos did not report AI-generated audio; the caller spoofed the victim's real IT department number.
The control that would have caught it· our reading, not a claim from the sources
A rule that IT never initiates remote-control sessions by inbound call, paired with blocking or alerting on Quick Assist use, breaks the email-bombing-plus-callback pattern.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.