Phishing is no longer confined to the inbox.
We’re seeing phishing move beyond email and into the tools people use throughout the working day. Microsoft Teams is part of that shift, with attackers impersonating IT support, sending malicious links and calling employees directly.
The approach works because Teams feels different from email. It’s where employees speak with colleagues, receive files and respond to everyday requests. A message arriving there can feel internal and trustworthy, even when it comes from outside the business.
That’s the opening Microsoft Teams phishing attacks are designed to exploit.
What is Microsoft Teams phishing?
Microsoft Teams phishing is a social engineering attack delivered through a Teams chat, call, meeting invitation or shared link.
The person making contact may pretend to be:
- A member of your IT team
- A Microsoft support technician
- A senior employee
- A supplier or business partner
- Someone from another trusted organisation
The attacker usually wants the recipient to click a link, enter their login details, approve an authentication request, open a file or provide remote access to their device.
The first message may look harmless. Once the recipient responds, the attacker can move the conversation to a call, direct them to a fake sign-in page or ask them to open a legitimate remote support tool.
Microsoft investigated one attack where a caller posed as IT support through Teams. After 2 failed attempts, the attacker convinced a third employee to open Quick Assist and grant remote access. The employee was then directed to a fake login page, and malicious software was installed on the device.
Why phishing is moving into Teams
What we’ve seen is that people still approach Teams differently from email. The platform is built around quick messages, calls and file sharing, which can make an unexpected request feel like part of a normal working conversation.
Microsoft reported continued growth in Teams-based social engineering during the second quarter of 2026. By the end of the quarter, weekly malicious call attempts were nearly 10 times the mid-2025 baseline.
External communication is a normal part of Teams. Depending on how it’s configured, your employees may be able to chat and meet with people from other Microsoft 365 organisations or unmanaged Microsoft accounts.
That access is useful for working with clients, suppliers and partners. It also gives attackers a way to contact staff from outside the business.
What a Teams phishing attack can look like
There’s no single version of a Microsoft Teams phishing attack. The message changes depending on what the attacker wants the employee to do.
Fake IT support
An employee receives an unexpected message or call from someone claiming to be from IT.
They may say:
- A security issue has been detected
- The employee’s account needs to be updated
- A software installation has failed
- The device is sending suspicious traffic
- Access will be suspended unless the issue is fixed
The requests we’d treat most seriously are the ones involving remote access. An employee may be told to open Quick Assist or another remote access tool, share a code or install a support tool under the impression that someone is fixing a genuine problem.
Fake login links
The attacker sends a link to what looks like a Microsoft sign-in page, shared document or internal portal.
The page captures the employee’s username, password or authentication details. Because the link arrived through Teams, the recipient may be less cautious than they would be with an unexpected email.
Employee impersonation
An external account is set up to look like someone inside the business.
The attacker may copy a name, job title and profile image from the company website or LinkedIn. They then ask for information, request a payment or try to move the conversation to another channel.
We see the same problem with email impersonation: people recognise the name and move on without checking the account behind it. A copied name, job title and profile photo can make an external Teams account look convincing at a glance.
Malicious files and meeting requests
The recipient may be asked to open a file, join a meeting or review a shared document.
The request can lead to a fake sign-in page, a malicious download or a call where the attacker continues the deception.
How to spot Microsoft Teams phishing
Some attempts are obvious. Others use correct names, branding and business language.
Look at the request as a whole rather than waiting for one clear giveaway.
The contact is unexpected
Treat messages from new external contacts carefully, especially when the person claims to work inside your business.
Teams may display a warning when it detects possible spam, phishing or impersonation in an external chat request. Check the sender’s name and email address before accepting it.
The person creates urgency
Be cautious when someone says the issue must be fixed immediately, especially when the request involves login details, authentication codes or remote access.
Urgency gives the recipient less time to stop and verify the request through another channel.
The request doesn’t follow your usual IT process
The businesses best placed to catch these requests have a clear IT support process. Their staff know how support normally makes contact, which remote access tool is used and how to verify a technician before granting access.
From what we’ve seen, confusion creates the opening. If employees don’t know what legitimate support looks like, a convincing Teams call can fill that gap.
The account is marked as external
The external label means the person is contacting you from outside your organisation.
That may be perfectly legitimate. If they claim to be an employee or your IT provider, check their identity before continuing.
They ask for information IT shouldn’t need
Passwords and authentication codes shouldn’t be shared through a Teams chat or call.
End the conversation and contact your IT team directly using a known number or your existing support channel.
What to do with a suspicious Teams message
Don’t respond to the request or follow its instructions.
Instead:
- Stop the conversation. Don’t click links, open files or provide information.
- Check the account details. Look at the sender’s address and whether Teams marks them as external.
- Verify the request separately. Contact the person or your IT provider using a known phone number or support channel.
- Report the message. If reporting is enabled, select More options, then Report this message and choose the security concern option.
- Tell your IT team. The same message may have reached other employees.
- Act quickly if you followed the instructions. Contact IT immediately if you entered login details, opened a file or provided remote access
Keep the message until your IT or security team has reviewed it. The account details, links and conversation history may help them work out what happened and who else was contacted.
How your businesses can reduce Teams phishing risk
Staff awareness helps, but the Teams settings and support process matter too.
Start with external access. Some businesses need to communicate with a broad mix of clients and partners. Others can limit access to a smaller list of approved organisations.
Microsoft lets administrators allow all external domains, block selected domains or restrict communication to approved domains. The right setting depends on how your business uses Teams.
Practical controls include:
- Restricting external Teams access where it isn’t needed
- Blocking suspicious domains and sender addresses
- Reviewing unusual external contact activity
- Enabling message reporting
- Configuring Safe Links for Teams where licensing supports it
- Limiting who can use remote support tools
- Setting a clear process for IT support and identity checks
- Monitoring unusual sign-ins and account activity
- Teaching staff to verify unexpected requests through another channel
The Teams external domain anomalies report can help administrators find unusual increases in first-time contact from outside domains. Those patterns can then be checked against normal business activity.
Administrators can also block domains and individual sender addresses. New Teams chats, calls, meetings and channel communication from a blocked source are then stopped.
Businesses using Microsoft Defender for Office 365 can apply Safe Links checks to links clicked in Teams and enable user reporting for suspicious messages. Feature availability depends on the Microsoft 365 licence in place.
Make the IT support process clear
Technical controls won’t catch every convincing message. Staff also need to know how genuine IT support works.
Make these points clear:
- How IT normally contacts employees
- Which remote support tool your provider uses
- What information IT will never ask for
- How an employee can verify a support request
- Who to contact when something feels wrong
- What to do after clicking a link or granting access
A genuine technician should be comfortable with an employee ending the conversation and calling back through the official support number.
Review Microsoft Teams before the next message arrives
Microsoft Teams phishing relies on familiarity. The platform is part of the working day, so requests can feel routine before anyone has checked the account behind them.
When we review Microsoft 365 environments, Teams external access and remote support processes are areas we want to understand. Who can contact your employees? Can staff report a suspicious message? And do they know how to verify someone claiming to be from IT?
Those checks won’t stop every attempt. But they will give your employees a much better chance of recognising when a request doesn’t fit the way your business normally works.
Windstil helps Australian businesses manage Microsoft 365 and cyber security, including Microsoft Teams access, identity controls, threat protection and incident response processes.
