• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
  • X
  • Facebook
  • YouTube
  • LinkedIn
Screen Connect
Support
Customer Portal
Pay Online
SWK logo.

SWK Technologies

Software Solutions & Services

  • Accounting & ERP Software
      • Acumatica Cloud ERP
        • Overview
        • Construction
        • Distribution
        • Field Service
        • Financial Management
        • Manufacturing
        • Professional Services
        • Project Accounting
        • Retail-Commerce
      • Sage Intacct
        • Overview
        • Construction and Real Estate (CRE)
        • Distribution Operations for Sage Intacct
        • Financial Services
        • Healthcare
        • Manufacturing Operations for Sage Intacct
        • Nonprofits
        • Professional Services
        • Sage Intacct Payroll powered by ADP
      • Sage 100
        • Overview
        • Business Intelligence
        • Core Accounting & Financials
        • Distribution
        • Manufacturing
        • Payroll
        • Sage 100 Contractor
      • More Accounting Products
        • QuickBooks
        • Sage 50
        • Sage 300
        • Sage 500
        • Sage BusinessWorks
      • ERP Add-ons
        • ADP Workforce Now
        • Avalara
        • AvidXchange
        • BILL
        • BigCommerce
        • CIMCloud
        • Cloud Hosting
        • DataSelf
        • DocLink
        • Endpoint Automation Solutions
        • Fortis
        • FreightPOP
        • Lumber
        • Microsoft 365
        • Netstock
        • Quadient
        • Sage Fixed Assets
        • Sage HCM
        • Sage Intacct Payroll powered by ADP
        • Sage Supply Chain Intelligence
        • Savant WMS
        • ScanForce
        • Solver
        • SPS Commerce
        • Velixo
        • Workforce Go!
      • More ERP Add-ons
        • Crystal Reports
        • KnowledgeSync
        • Nuvei
        • Nectari
        • Ottimate
        • Pacejet
        • Planning Maestro
        • Sage CRM
        • Sage HRMS
        • Sage Intelligence
        • Service Pro
        • ShipStation
        • Shopify
        • Starship
        • Sugar CRM
        • Traild
      • Industries
        • Construction
        • Distribution
        • Financial Services
        • Healthcare
        • Manufacturing
        • Nonprofit
        • Professional Services
        • Retail
  • Managed Cloud Services
      • Managed IT Services
        • Managed Cloud Services
        • Network Assurance Core
        • Co-Managed IT
        • Email Hosting
        • IT Support
        • Microsoft 365 Services
        • Server Monitoring
        • Virtualization
      • Cybersecurity
          • CyberAssurance CORE™
          • Cybersecurity Solutions
          • Backup & Continuity
          • Compliance
          • Dark Web Monitoring
          • EDR
          • Encryption
          • MDR
          • MFA
          • Penetration Testing
          • Security Training
          • SOC
          • Spam & Virus Filtering
          • vCIO
          • Vulnerability Assessment
      • Cloud Services
        • Secure Cloud Hosting
        • Infrastructure-as-a-Service
        • Acumatica IaaS
      • Industries
        • Financial Services
        • Healthcare
        • Construction
      • Locations
          • Nationwide
          • Austin
          • California
          • Chicago
          • Minneapolis
          • New Jersey
          • New York
          • North Carolina
          • Philadelphia
          • Phoenix
          • San Diego
          • Seattle
  • Consulting & Implementation
    • Business Technology Consulting
    • eCommerce
    • Financing
    • Human Capital Management
    • Managed Cloud & IT Services
    • Partner Program
    • Software Development
    • Software Implementation
  • Resources
    • Help Desk
    • Blog Posts
    • Payments Portal
    • Webinars
    • YouTube Channels
    • Acumatica Resources
    • Sage Intacct Resources
    • Sage 100 Resources
    • IT Resource Pages
  • About
    • About SWK
    • Awards & Recognition
    • Life@SWK
    • Careers
    • Success Stories
    • SWK Gives
  • Contact
    • Contact Us
    • Support
    • Our Locations

Microsoft Teams Phishing Threats – What to Watch For

August 7, 2026 by Hector Bonilla

Home » Microsoft » Microsoft Teams Phishing Threats – What to Watch For

Microsoft Teams logo, 3D rendering on a white background: a translucent white speech bubble outline on the left containing a solid blue capital letter T, overlapping a larger purple figure with a rounded body and a separate purple spherical head, next to a smaller blue figure with a rounded body and a separate blue spherical head on the right.

Cybercriminals have been increasingly using Microsoft Teams as a channel for phishing individual employees using commercial Microsoft 365 accounts, often posing as a trusted party, such as someone from your internal IT department. These attacks leverage in-house chats being seen as more trustworthy than email, catching end users off-guard with what seems like an innocuous request for access, though often also promoting a sense of urgency to grant the other party permission quickly.

Below is a breakdown of why this shift happened, the different types of Teams phishing that have emerged over the past year, what your team should do when a request feels wrong and which controls reduce your risk at the account and device level:

Why Your Microsoft Teams Account is a Phishing Target

Microsoft 365 is one of the most popular business communication and productivity software suites for midmarket and enterprise businesses in the world, with Teams alone featuring hundreds of active users every month. This means that hackers have a large target base to work with from the start, although the chat application is still far from the top phishing vector, yet. There were millions of email compromise attempts versus thousands through Teams in the first half of 2026 – so, why worry about the latter at all?

Which would you be more likely to trust: a message from an account claiming to be your IT support on Outlook, or one popping up in what should be your internal company chat? Cybercriminals know that spoofed emails are a well-known and oversaturated method that most of their would-be victims are increasingly being trained to spot, but Teams phishing relies on most people unaware that chats and calls can be spoofed as well as an email. It is one of the fastest growing techniques of 2026 for this reason, with few immediate controls that could automatically block these sorts of attempts without also cutting off legitimate connectors.

Cost and effort on the attacker’s side are close to nothing, which also explains much of the growth in volume. A consumer email address is enough to register a Teams account and from there a threat actor can reach anyone whose organization allows outside accounts to open conversations without restriction. No exploit is involved and no inherent software flaw is being abused, so there is no quick patch to fix this gap.

Microsoft’s own Q2 2026 threat report shows how quickly this has scaled through 2026:

  • Teams-based phishing detections rose 19% from March to April, held roughly flat into May, then increased another 10% into June
  • Average weekly malicious call attempts rose 31% from April to May and another 27% into June, with the final two weeks of June recording the two highest weekly volumes on record
  • Weekly voice phishing attempts have increased roughly 80% since the beginning of 2026 and now run at nearly ten times the mid-2025 baseline, the steepest growth of any threat category in the report
  • Attackers concentrate the calls between 10:00am and 4:00pm Eastern on weekdays, with near-zero weekend activity, as that is when the person they are calling is most likely sitting at their desk

Types of Phishing Threats Seen in Teams Recently

Specific phishing threats for Microsoft Teams are continuously evolving and the exact methods that hackers use change fairly often. However, there are a few particular methods that make up the majority of those that have been observed increasing since last summer:

Impersonation of IT Support

Attackers posing as IT helpdesk support make up the dominant share of these attempts, typically warning of an account lockout that needs attention immediately. The conversation then moves to a request for approval, which across nearly every documented case takes one of three shapes: a multifactor prompt the employee accepts, a one-time passcode the employee reads aloud or a remote support session the employee opens themselves. While chats from outside accounts may display a warning banner, calls frequently do not, which means a call can feel more legitimate than the same approach delivered as a message. Attackers have also figured out how to avoid easy red flags on their account names, with generic names used climbing from 42 percent of these attempts in April to 52 percent by June, explicit IT support branding falling from 32 percent down to 16 percent and Helpdesk branding growing from 22 percent to 31 percent.

Compromise of a Trusted Account

A more concerning and more direct phishing attempt in Teams leverages an external account that has already been compromised but that would appear more trustworthy, typically one belonging to a partner or customer. The attacker would take advantage of this party having both access to and history with your chat communications, so a request or file attachment will not seem out of the ordinary. This technique essentially relies on the same social engineering practices hackers use with email or social media scams, but with the added benefit that many users are still unused to the same approach being used in a channel such as Microsoft Teams.

Voicemail Phishing (Vishing)

Beyond sending their requests via chat message, some threat actors are also directly calling users via Teams to impersonate IT personnel, taking advantage of the warning banner gap with calls to more successfully imitate a legitimate request. One ransomware group launched a campaign across the US and Canada using this technique, successfully infecting three confirmed victim organizations, with at least one of these attacks successfully encrypting the company’s files in under 17 hours.

Credential and Session Theft

A separate category bypasses the conversation entirely and goes after the sign-in itself, as with the subscription Kali365 phishing kit the FBI warned about in May 2026 that captures Microsoft 365 access and refresh tokens without ever touching the user’s password or triggering a multifactor challenge. Delivery in the documented cases came by email and not through Teams. At the same time, those tokens grant persistent access to Outlook, Teams and OneDrive together.

Email and Teams Phishing Simultaneously

Some threat actors are actively bombarding victims with attempts at phishing through email channels and Microsoft Teams to reinforce the legitimacy and urgency of their requests. This method still relies on impersonating IT helpdesk support in execution, but also targets the user with a sizable volume of spam emails, evidently to convince the victim to agree to the support request out of desperation. At least one cybercriminal group tracked by Google and Mandiant used this technique to infect several organizations with malware.

Fake Microsoft Store Updates

A more complex and multi-step campaign by one threat actor directed a victim towards a fraudulent Microsoft Store webpage that prompted them to update their Teams application, via a malicious attachment that was initially sent by email and ensured that the user was sent to the page of the attacker’s choosing. Once there, they downloaded what they assumed were legitimate updates after being prompted to – in actuality, the attacker installed remote monitoring and management (RMM) software on their computer.

What a Teams Impersonation Attempt Looks Like

Nearly every documented version of the impersonation attacks on Teams observed over the past year includes several of the following:

  • An external tag on the chat or call, indicating the account sits outside your organization, which internal support will never carry
  • Someone identifying themselves as IT for a ticket nobody at your company opened, which is backwards from how legitimate support engagements begin
  • Pressure to act immediately, framed as an account lockout, a security alert or a compliance deadline
  • A request to approve a multifactor prompt or read back a one-time code, neither of which any real support process requires
  • A request to open a remote support session or install remote-control software during a first conversation
  • A link or file nobody was expecting, particularly one presented as an update that has to be installed before something else will work

One of the easiest ways to catch these attempts, however, is in the method itself. Real IT support requests should originate from a case ticket you actually opened, and legitimate helpdesk engagements generally afford time to verify who is on the other end. A first-contact request that arrives with pressure attached is worth pausing on regardless of what it appears to ask for.

What You Should Do When an IT Support Request Feels Off

Here are three steps you should take immediately if you receive a sudden request from anyone claiming to be your IT support on Microsoft Teams:

  1. Stop – Approve nothing and install nothing until you have confirmed who is actually making the request
  2. Verify – Reach your support team through a channel you already use, such as a saved number or your ticket system
  3. Report – Tell your IT or helpdesk team right away, because the sooner they know the sooner an account can be locked

Adopting two additional practices also make it easier to verify legitimate requests if and when a hacker attempts to phish one of your employees via Teams:

  1. Publishing in advance how your support team contacts people and what they will never ask for removes the ambiguity these attempts leverage
  2. Setting a verbal verification word internally then gives your staff something concrete to request that a scammer would be able to produce

Reducing Phishing Risk at the Account and Device Level

No configuration change removes this category of risk on its own, because the attack turns on a person making a decision and not on a system being defeated. What these controls do is reduce how often an attempt reaches someone, limit what a single approval can accomplish and shorten the time an intrusion goes unnoticed. The goal is risk reduction rather than prevention, and the framing worth adopting is one that pairs proactive controls with the monitoring layer that catches what those controls do not:

Restricting Access at the Entry Point

Limiting Teams contact to an allowlist of trusted domains removes the entry point that these attempts rely on. The same logic applies to turning off the ability for outside accounts to open conversations, and to locking down guest access and anonymous meeting join at the tenant level. Remote support utilities are the other half of this. Quick Assist and comparable tools should be disabled or restricted to the roles that genuinely need them, with no legitimate session beginning without a ticket number attached to it.

Limiting What a Single Approval Reaches

Phishing-resistant multifactor authentication methods such as security keys and passkeys are considerably harder to socially engineer than an approval prompt somebody can be talked into accepting. Access policies requiring a compliant device before any administrative action or remote management session then contain what a single mistake is able to reach. Blocking device code authentication through policy closes an alternate path that a captured one-time code would otherwise open.

Catching an Intrusion Sooner

Identity, device and Teams activity need to be evaluated together so that a first-contact external chat followed by a remote session registers as one event and not as three unrelated log entries, with unusual approval patterns reviewed as a matter of course. Link checking at the moment of click, retroactive removal of messages later found malicious and active spoof detection all apply to Teams content and not only to email. Attack simulation tooling now covers simulated phishing delivered through Teams, which means your cybersecurity training can test people on the channel they are actually being approached through.

What Your Licensing Covers

Which of these settings you can apply depends partly on your M365 licensing, as several of the filtering and access policy controls sit in the higher plan tiers rather than in the base subscription. Putting them in place is generally a configuration project rather than an ongoing service, so it is worth confirming what your current subscription already entitles you to before purchasing anything additional.

What Happens After Someone Approves the Request

The controls above determine how often an attempt gets through, and what happens in the days afterward determines what it costs. Most of the financial and reputational damage in these incidents accumulates during that second interval, which is also the part businesses tend to plan for least. Even if a compromise does not get that, your business will still be exposed to significant financial risk, to say nothing of the reputational risk if and when data is exposed.

An attacker with access to an active mailbox can read through inbound and outbound messages for a wire transfer conversation with a vendor or client, alter the payment instructions on the outbound side and then step back while the funds move to an account they control. The same access becomes a distribution point for further phishing sent from a legitimate address to that person’s contacts, which quite a few recipients open because they recognize the sender.  These are only two examples of methods that have been executed in the real world repeatedly – once a hacker gets into your network or systems, there are multiple ways they could capitalize on the intrusion, at your (figurative and literal) expense.

How CyberAssurance CORE™ Helps

CyberAssurance CORE™ is SWK Technologies’ managed cybersecurity program for small, mid-sized and small enterprise businesses, structured around the six functions of the NIST Cybersecurity Framework 2.0. Where the Microsoft 365 configuration work discussed above addresses this threat by tightening the environment itself, CyberAssurance CORE™ approaches it from a different direction, layering continuous monitoring, response and training on top of whatever controls are already in place.

The program is built to function as one system, so the analysts, tools and procedures inside of it operate as a coordinated ecosystem rather than as a collection of separate products your team has to manage on its own. Three core components of CyberAssurance CORE™ provide effective solutions to combating Teams phishing attacks:

  • SIEM-backed monitoring captures the disparate activity generated across your network and flags the pattern of a compromised account, whether the compromise originated in email or in Teams.
  • Security awareness training provides staff with the knowledge to spot these attempts, along with periodic testing to identify who is most likely to click through.
  • Managed detection and response flags the follow-on activity of a threat actor attempting to install additional software on a compromised device.

A 24/7 security operations center sits behind all three, with the trained analysts who investigate what the monitoring layer surfaces and act on it when the situation calls for a response.

Reduce Your Microsoft Teams Risk with SWK Technologies

Attackers are working through the tools your staff already trust, and a Teams message asking for a quick approval does not look like a security event while it is happening. Reducing that risk means addressing both the moment of first contact and everything that follows it, which is what CyberAssurance CORE™ is built to do, pairing solutions and managed support that allow you to strengthen the human layer of your network security as well as shorten the window between compromise and containment.

Contact SWK here to learn how CyberAssurance CORE™ can help your business improve threat visibility and meet compliance requirements.

Contact SWK for More Microsoft Security Tips

Category: Microsoft, Blog, Cybersecurity, News and Events, Tips and Tricks

Sidebar

Recent Posts

  • Microsoft Teams Phishing Threats – What to Watch For
  • Sage 100 2026 Upgrade Planning: How to Reduce Disruption
  • Data Center MEP Contractors Face the Same WIP Problem as GCs
  • SWK Delivers a New Financial and Payroll Platform for National Pizza Franchise
  • User Security in Acumatica – Roles, Access and Login Options
  • SWK Cybersecurity News Recap July 2026
  • How to Set Up Microsoft 365 Copilot for Your Business

Categories

Ready to take the next step?

Contact SWK today to get in touch with one of our experts. We’ll go over your business challenges and unique needs, and see where you can unlock new value from your technology and make your operations run easier.

Get in touch!

Our Latest Posts

Microsoft Teams logo, 3D rendering on a white background: a translucent white speech bubble outline on the left containing a solid blue capital letter T, overlapping a larger purple figure with a rounded body and a separate purple spherical head, next to a smaller blue figure with a rounded body and a separate blue spherical head on the right.

Microsoft Teams Phishing Threats – What to Watch For

Read moreMicrosoft Teams Phishing Threats – What to Watch For
Business team reviewing Sage 100 2026 upgrade planning at computers

Sage 100 2026 Upgrade Planning: How to Reduce Disruption

Read moreSage 100 2026 Upgrade Planning: How to Reduce Disruption
MEP contractors installing large HVAC cooling equipment and piping outside a data center

Data Center MEP Contractors Face the Same WIP Problem as GCs

Read moreData Center MEP Contractors Face the Same WIP Problem as GCs

Awards and Accreditations

Top work places in NJ 2020.
Acumatica the Cloud ERP gold certified partner.
The Gold Microsoft partner logo on a black background.
Sage business partner diamond logo.
Dell Technologies Gold Partner
Sage tech partner logo.

Stay in the know!

Subscribe for exclusive ERP, process automation, IT and cybersecurity news.

Twitter
  • Facebook
  • YouTube
  • LinkedIn

Home
About
Contact

Support
Screen Connect
Pay Online
Downloads

SWK logo.

Headquarters:
120 Eagle Rock Ave, Suite 330
East Hanover, NJ 07936

Contact:
info@swktech.com
(877) 979-5462

Copyright © 2026 · SWK Technologies, Inc. · All Rights Reserved · Terms of Use · Privacy Policy

This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. By continuing to browse this site you agree to the use of cookies. Visit our privacy policy to learn more.