
Cybercriminals are increasingly abusing collaboration platforms such as Microsoft Teams to impersonate IT support, send phishing messages and convince employees to give them access to business devices and accounts. In some attacks, what starts as an unexpected Teams message or call can eventually lead to stolen credentials, malware, data theft or ransomware.
For small businesses, these scams can be harder to spot when there’s no dedicated IT team to check with.
Microsoft Teams scams rely heavily on social engineering. Instead of hacking Teams itself, attackers use legitimate communication features such as chats, calls and screen sharing to convince someone to trust them and take an unsafe action.
For example, a scammer may contact an employee from an external Teams account and pretend to be someone from IT, Microsoft support, a supplier or another trusted organization. The message might claim there is a problem with the employee's account, a security update that needs to be installed or suspicious activity that needs immediate attention. From there, the scammer tries to persuade the employee to do something that gives them greater access. That could mean clicking a phishing link, sharing login information, opening a file, approving a remote connection or following instructions during a Teams call.
Because the conversation is happening inside a familiar workplace platform rather than through an obviously suspicious email, the request may feel easier to trust.
Attackers can contact employees through external Teams accounts and pose as IT or technical support. They may say your account needs to be verified, a security update must be installed or there's a problem that needs to be fixed urgently.
The next step is often a request to access your computer remotely.
Someone posing as IT support may ask you to open Microsoft Quick Assist or another remote-access tool, enter a code and allow them to view or control your computer.
The tool itself is legitimate, the scam is getting you to hand over access.
Microsoft has documented attacks where scammers used Teams to pose as support staff and then persuaded employees to grant remote access. From there, they could steal credentials, install malware or gain access to other parts of the business network.
Phishing links don't only arrive by email. Scammers can send them through Teams, too.
A link may take you to a fake Microsoft 365 login page designed to steal your username and password, or to another fraudulent website asking for payment or sensitive business information.
Be especially careful with unexpected messages asking you to click a link, open an attachment or sign in to an account.
“Your account will be suspended.” “Your password has expired.” “Suspicious activity was detected.”
Messages like these are meant to get you to act quickly. Microsoft has documented attacks using lures such as “Microsoft Security Update,” “Spam Filter Update” and “Account Verification,” as well as warnings that an account could be deactivated.
A scammer may also pretend to be your boss, a coworker, supplier or another person you regularly deal with.
They might ask you to review a document, join a meeting, make a payment or share business information. If the request is unusual, verify it with the person directly before doing anything.
An unexpected message doesn't automatically mean someone is trying to scam you. Small businesses routinely communicate with clients, contractors and other people outside their organization through Teams.
But you should be more cautious when a message:
Microsoft Teams can also display warnings when it detects possible spam, phishing or impersonation from someone outside your organization. Don't ignore them. Microsoft recommends checking the sender's name and email address and accepting the conversation only when you're confident the sender is trustworthy.
Many Teams scams work because an employee believes they're dealing with someone they can trust. One way to prevent this is to make sure everyone knows how your business provides IT support and what an IT provider would never ask them to do.
For example, if your IT provider would never contact employees unexpectedly through Teams and ask for remote access, make that clear to everyone.
You can also limit who can contact employees through Teams. Microsoft recommends restricting messages from unmanaged Teams accounts or, when possible, allowing external communication only with trusted domains.
You should also:
If someone clicked a suspicious link, entered credentials, installed software or gave a stranger remote access to their device:
Bitdefender Ultimate Small Business Security helps protect your business against scams with technology built specifically with small businesses in mind. Its scam detection is trained to recognize threats targeting small businesses, including the language, tactics and social engineering techniques scammers use against owners and employees.
Beyond scam protection, it helps protect your business devices, accounts and employees against phishing, malware, ransomware and other online threats, while giving you visibility over security from one easy-to-use dashboard.
Try Bitdefender Ultimate Small Business Security free for 30 days. No credit card required.
You may also want to read:
Yes. Scammers can use Microsoft Teams to impersonate IT support, coworkers or other trusted contacts. They may send phishing links, fake security alerts or try to convince you to share information or give them remote access to your device.
Watch for unexpected messages, urgent requests, unfamiliar external accounts, suspicious links and requests for passwords, MFA codes, screen sharing or remote access. If you're unsure, verify the request through another trusted communication channel.
Yes, if you follow the scammer's instructions. For example, fake IT support may ask you to use Quick Assist, install remote-access software, share your screen or give them control of your device.
Stop interacting with the message and report it. If you entered a password, change it immediately and check the account for suspicious activity. If you downloaded something or granted remote access, contact whoever manages your business's IT or cybersecurity as soon as possible.
tags
Cristina Popov is a Denmark-based content creator and small business owner who has been writing for Bitdefender since 2017, making cybersecurity feel more human and less overwhelming.
View all posts