All client systems monitored 24/7
Sheffield, UK  //  Est. 2006
01433 377 977

Microsoft Teams Phishing: A Real Attack We Just Stopped

Microsoft Teams Phishing: A Real Attack We Just Stopped

This week we saw our first customer hit by a significant, genuinely sophisticated phishing attempt on Microsoft Teams. Not email, Teams. It very nearly worked, it was stopped by one person trusting their instincts, and it is exactly the kind of attack every practice and business should now expect. Here is what happened and what to take from it.

What happened

External accounts created a Teams group chat and added the finance director of one of our customers. The accounts had been made to look convincingly like the business owner and another member of staff, using very similar names and email addresses. At a glance, the chat looked like an ordinary internal conversation.

The conversation began as an innocuous, entirely plausible business discussion, so the finance director understandably joined in. Then the questions became increasingly detailed and unusual, and alarm bells started to ring. They stopped, and we were contacted. We investigated the conversation and blocked the malicious external accounts.

To be completely clear: the customer's systems had not been hacked, and their Microsoft 365 accounts had not been compromised. This was a social-engineering attack. The criminals used external Teams accounts and convincing impersonation to establish trust, then tried to use that trust to obtain information. It is the same con that has run over email for decades, moved into a channel where most people's guard is still down.

Why Teams phishing works

We have all learned, slowly and sometimes painfully, to be suspicious of email. Odd sender addresses, unexpected invoices, urgent requests from "the boss": most teams now treat these with appropriate caution, which is exactly why criminals are moving somewhere else.

A Teams message does not feel like email. It feels internal. It arrives in the same window as genuine chats from colleagues, with a name and a profile picture, and the conversational back-and-forth builds trust in a way a single email cannot. Notice the craft in this attack: no dodgy link in message one, no urgent payment demand up front. Just a plausible business conversation that earned trust first and only then started digging. That patience is what makes it dangerous.

The specific targeting matters too. They picked the finance director, impersonated the business owner, and constructed a scenario that made sense for that business. This was not a scattergun blast; someone did their homework, most likely from nothing more exotic than the company website and LinkedIn. As we have written before, practices and small businesses are probed constantly, and the attacks that get through are increasingly the well-researched ones.

The person was the defence, and that is the point

The member of staff handled this exactly as we would hope. They stopped when something did not feel right, and they checked independently before going any further.

That instinct is worth more than any single piece of software. Filters, policies and monitoring all matter, and we run plenty of them, but a conversation that contains no malware and no malicious links can sail past technical controls. What stopped this attack was a human noticing that the questions had drifted from normal to odd, and refusing to carry on until they had verified who they were really talking to.

That is not luck. It is culture, and you can build it.

What your team should do about Teams phishing

The advice is simple enough to share at your next team meeting:

  • Treat unexpected Teams chats like unexpected emails. The same caution you apply to a surprise email applies to a surprise chat, even when the name and photo look familiar.
  • Check the exact email address and domain. Impersonators rely on near-miss names and lookalike addresses. Click the profile and read the actual address carefully, not just the display name.
  • Pay attention to Teams' external-user warnings. Teams labels people from outside your organisation. If a chat with "your boss" is flagged as external, that is the whole story right there.
  • Verify unusual requests through a separate channel. Anything involving payments, credentials or sensitive business information gets checked on a known telephone number, or in person, before you act. Never verify through the same chat that made the request.
  • Make it safe to stop and ask. The finance director in this story paused and escalated rather than pushing on. Praise that behaviour loudly; nobody should ever feel silly for double-checking.

The same "verify independently" habit protects you across every channel. We have seen it defeat phone-based contract scams too, and it costs nothing but a two-minute phone call.

What we do behind the scenes

Technical controls still matter alongside the human ones. Sensible Microsoft 365 tenant configuration, multi-factor authentication everywhere, restrictions and warnings around external Teams access, and a layered security setup that assumes some attacks will always be conversations rather than code. And when something odd does surface, being able to contact your IT provider, have the conversation investigated and the accounts blocked the same day is precisely what managed support is for.

We will say it plainly rather than dramatically: this was our first Teams phishing case in the wild against a customer, and we do not expect it to be the last. Phishing is no longer confined to email, and the sooner your whole team internalises that, the safer you are.

Talk to your team, then talk to us

The single most useful thing you can do today is free: tell your team this story. Five minutes at a huddle covering "check the address, watch for the external tag, verify odd requests by phone" is genuinely effective security training, because it is a real event, not a hypothetical.

And if you would like us to review how your Microsoft 365 tenant handles external Teams access, or to help build this kind of awareness in your practice, get in touch. We would much rather help you rehearse this before the criminals pick your number.

Book your free IT health check.

We'll examine your network, tell you exactly where you stand, and what we'd fix. No commitment, no sales patter.

WhatsApp us any time on 01433 377 977or text 07488 890826