When it's already happened
Someone from IT called asking for my password. Is that normal?
A calm walkthrough of the fake IT support call: why no genuine help desk needs your password or your six-digit code, why the call sounds so convincing, and exactly what to say to end it and check who really called you.
No real IT team needs your password or a code from your phone. Hang up, look up the number yourself, and call them back.
Last reviewed 2026-08-18 by Grayson Dodson. Free, plain-English guidance for everyday work technology.
No. And here is the flat version
No. It is worth saying flatly, because the softer version is what gets people hurt: a genuine IT team does not need your password. Not to verify your identity, not to finish a mailbox migration, not to clear an urgent ticket, not for two minutes, not ever. This is not a rule with a quiet exception your employer forgot to mention. The people who actually run your accounts already have administrator tools, the Microsoft 365 admin center or the Google Admin console, that let them reset your password, unlock your account, or sign a stolen laptop out of everything, all without ever seeing what your password was. Asking you for it would hand them nothing they cannot already do in about ten seconds. If you are on that call right now, and some part of you wants to just say it so this pleasant, busy-sounding person can get on with their day, that pull is not a weakness in you. It is the entire design of the attack. Nothing has broken yet if you have not said it out loud. And if you already did, that is fixable too, and the last section tells you exactly what to do first.
Why the call sounds so convincing
Because somebody did the homework. The caller may open with the real name of your actual IT manager, found in ten seconds on LinkedIn, and mention the branch office you work in, which is on your company's own website. They use internal-sounding language: a tenant migration, a mailbox move, a conditional access policy, an INC ticket number that looks exactly like the ones you normally get. Your phone may even display your company's main switchboard number, because caller ID is trivially faked and has been for years. None of that is evidence of anything. Then there is the choreography. Skilled callers phone first and email second, or send a Teams message a minute later, so the email arrives already expected and therefore already trusted. It quietly reverses the order your instincts were trained for. Look at the actual sending address rather than the display name: in Outlook, click the sender's name to expand it, and on an iPhone tap the name in the header. A Teams message from outside your company carries an External tag next to the sender. A display name that reads IT Service Desk costs nothing at all to set.
The six-digit code is the same attack
The most common version of this call does not ask for your password at all. It asks you to read out the six-digit code that just arrived by text, or to tap Approve on the prompt from Microsoft Authenticator, Duo, Okta Verify, or the Google prompt on your phone. Understand what that request means. They already have your password, bought from a breach list or captured on a fake sign-in page weeks ago, and they are standing at the login screen right now. Your code is the last lock on the door, and they are asking you, very politely, to open it for them. Watch for the version where the prompts come first. Approval requests arrive at eleven at night, then again, then five more, then a call from friendly IT saying they are testing something and could you just approve it so the alerts stop. Deny it instead. Every code message tells you the truth in small print: nobody will ever ask you for this code. Real support cannot see your code and never needs it, because the code exists precisely to prove that you, holding your phone, are the one signing in.
How to end the call without feeling rude
You do not need to win an argument, catch anyone out, or explain your reasoning. You need one sentence and a hang-up. Try this, word for word: "I'm not able to share that over the phone. I'll call the service desk back on the number in our directory." Then stop talking. Silence is allowed. If they push, and pushing is the tell, use: "That's fine, I'll open a ticket myself and reference it there." Then end the call. You can be entirely warm while doing it. "No problem, I'll call you back on the main line" is polite, final, and gives away nothing. Notice what an honest technician does next. They say that is a good instinct, give you their extension, and wait. What they do not do is escalate, get personal, insist a callback will take too long, invoke their manager, or warn that your account locks in five minutes unless you act now. Urgency is the pressure that makes people skip verification, so treat it as confirmation rather than an obstacle. And weigh the two mistakes honestly: being briefly awkward with a real colleague costs you a thirty-second apology tomorrow, while handing your credentials to a stranger costs your employer a security incident and costs you the week that follows it.
Verify it yourself, then report it
Hang up first. Then look up the number yourself, and do not use any number, link, extension, or callback code the caller offered you, because that is the one detail always under their control. Good sources: your intranet staff directory, the sticker on the back of your laptop, the number taped by the printer or printed on your badge, the global address list in Outlook, or the person's contact card in Teams, where an outside account is labeled External. If you can, call from a different phone. When someone answers, say it plainly: "Someone called me claiming to be from IT and asked for my password. Was that one of you?" They will not mind. They would far rather take that call than the other one. Report the email too, if one arrived. In Outlook, use the Report button on the Home ribbon, then Report phishing. In Gmail, open the message, click the three-dot menu at the top right, then Report phishing. Report before you delete anything, and keep the voicemail. Those headers and timestamps are how your security team learns whether anyone else got the same call.
What real IT asks for, and what to do if you already answered
Real support asks for things that identify the problem, not things that unlock you: your name and team, what you were doing when it broke, the exact wording of the error, a screenshot, the device name or asset tag on the sticker, and a ticket number you can look up yourself in ServiceNow, Jira Service Management, or whatever your workplace runs. They may ask you to open Microsoft Quick Assist and type a code they read to you, which is a screen-sharing code rather than a login code, and they should tell you before they take control. They will let you type your own password yourself. If you already gave something away, tell your IT or security team now, today, before you tidy anything up. Speed matters far more than a tidy explanation, and early reporting genuinely produces better outcomes than a quiet fix. Then change your password and sign out everywhere: myaccount.google.com/security and myaccount.google.com/device-activity for Google, myaccount.microsoft.com and mysignins.microsoft.com for Microsoft. You will not be the first person this week. Help desks see this constantly, and the people who call early are the reason nothing worse happened. One caution about remote-control tools specifically: Quick Assist and its equivalents are legitimate when you opened the ticket first and you are expecting the call. They are also among the most abused tools in real intrusions, so a remote-control request that arrives with an unexpected call is a reason to stop, not a reassurance.
Common questions
Is IT ever normal for IT to ask for your password?
No. There is no legitimate situation where your IT team needs your password, including migrations, audits, urgent tickets, or new-starter setup. Administrators can already reset your password, unlock your account, and check your sign-in history from the Microsoft 365 admin center or the Google Admin console without ever seeing it. If someone asks, the request itself is the answer. Say you will call the service desk back on the number in your directory, then hang up and do exactly that.
I already gave someone my password. What do I do now?
Tell your IT or security team immediately, before anything else, and say plainly what you shared and when. That single call is what limits the damage, and help desks handle it every week without drama. Then change your password and sign out of all sessions: myaccount.google.com/security and myaccount.google.com/device-activity for Google, or myaccount.microsoft.com and mysignins.microsoft.com for Microsoft. Do not delete the email, the text, or the voicemail first. Reporting comes before tidying, because those records are what your team needs to see who else was targeted.
The caller ID showed my company's real number. Doesn't that prove IT's real?
No. Caller ID is display text, not proof of origin, and faking it takes a scammer no effort at all. Your phone will happily show the main switchboard, a colleague's extension, or the number printed on your own IT poster. Treat what appears on screen as decoration. The only check that works is the one where you control the connection: hang up, find the help desk number in your staff directory or on your badge yourself, and call in.
They only wanted a six-digit code, not my password. Is that safer?
No, it is the same attack, and it is now the more common one. Asking for the code means they already have your password and are sitting at the login screen waiting for the last lock to open. The same is true of a push notification you did not trigger yourself, including one that arrives after a burst of prompts at an odd hour. Never read a code out and never approve a prompt you did not start. Deny it, then report it, then change your password.
How do I say no to an IT call without sounding paranoid or rude?
Use a short, friendly sentence and let it be the end of it: "I'm not able to do that over the phone, I'll call the service desk back on our internal number." You do not owe an explanation, and you do not have to keep talking. A genuine technician will tell you that is exactly right and give you their extension. Pressure, personal appeals, or warnings that verifying will take too long are the signal that you were right to check.