
Microsoft Teams has become a frequent target for impersonation scams, moving beyond email phishing to exploit trust in workplace communication tools.
How the attacks work
Scammers pretend to be internal employees—often from IT, payroll, or finance—and send urgent messages asking recipients to click links, share screens, or provide login details. The messages look real, sometimes including fake verification marks or familiar names.
Andrea Sivieri, chief product and technology officer at CoreView, explained that these attacks exploit trust by using native Microsoft 365 controls, which weren’t built to block real-time social engineering. A single user approval can give attackers access to Quick Assist, email accounts, and other sensitive data without raising alarms.
Once inside, the threats escalate. Sivieri noted the same access can lead to full tenant ransom scenarios, where hackers encrypt OneDrive and SharePoint files, take over Global Admin accounts, and lock out legitimate users. They can even alter Microsoft’s sensitivity labels to block data access without deploying traditional ransomware.
Recovery from these incidents often takes weeks. Rob Edmondson, principal technologist of Microsoft 365 at CoreView, pointed out that Microsoft doesn’t offer backups for tenant configurations, and security teams frequently miss unauthorized changes because the platform lacks real-time alerts.
Real-world cases show businesses losing access to critical Microsoft 365 services for extended periods, sometimes requiring full tenant rebuilds with direct Microsoft support.
Related: Beware of Three Common Zoom Scams
Attackers use urgency in their messaging to encourage quick action. They’ll often frame messages as IT security alerts or billing issues, sometimes including a fake checkmark to appear legitimate. They may ask users to download fake remote support tools, fraudulent versions of Quick Assist, or direct them to malicious websites or malware-laden files. Voice calls can also be part of the scheme, with scammers impersonating colleagues and instructing victims to run scripts in Command Prompt.
A method called “quishing” involves sending QR codes that redirect to phishing sites mimicking Microsoft’s login pages. Scanning the code hands over credentials, which attackers use to infiltrate systems.
Some scammers send fraudulent links in chat or meeting requests, hoping victims will click without verification.
Red flags to watch for
External senders are usually marked with an “[External]” tag in Teams. Messages with vague language—especially from supposed IT or finance staff—should be treated with caution. Attackers may also insist on “desktop only” meetings, as their malware often only works on PCs.
The scams rely on familiarity. Attackers may impersonate long-time contacts, making requests seem normal—until they ask for something unusual, like running an unknown script.
Companies that work closely with external partners face greater risk. Scammers can mimic clients, vendors, or collaborators, making fraudulent requests harder to detect.
How to protect your team
Turning off external messages can reduce risk for employees who don’t need outside communication. For those who do, training is essential. Staff should learn to spot phishing signs, such as unexpected links, urgent requests, or demands to run unfamiliar commands.
Multi-factor authentication (MFA) should always be enabled. Keeping antivirus software, firewalls, and other security tools updated helps close vulnerabilities in older versions.
Quick Assist, Microsoft’s screen-sharing tool, is a common entry point for attackers. Disabling it unless absolutely necessary removes a major risk. If IT or support teams need it, they should verify requests through another channel—like email or a phone call—before proceeding.
HR, finance, and IT departments should confirm sensitive actions through a second communication method. For example, if payroll asks for a password reset, the employee should call or email to confirm before complying. Payroll mistakes can expose small businesses to similar risks.
Edmondson advised treating Microsoft 365 tenants as critical infrastructure. Segmenting tenants limits damage if an attack succeeds, and maintaining backups of configurations allows faster recovery if settings are changed.
No single measure stops all threats, but layered defenses make attacks harder to execute. The challenge is balancing security with usability—too many restrictions slow work, while too few leave gaps for exploitation.


