Microsoft Teams Exploited by Scammers in High-Profile Enterprise Phishing Surge
A security advisory released by threat intelligence researchers reveals that threat actors are systematically exploiting default external tenant federation settings in Microsoft Teams. Attackers impersonate corporate IT support personnel or executive leadership to deliver malicious payload links and execute authorization fraud.
Join 45,000+ engineers, founders, and tech leaders receiving our 5-minute daily breakdown of AI, hardware, and tech policy.
Microsoft Teams Exploited by Scammers: what actually changed
Start from exposure, not from the headline. What software, cloud service, or configuration is actually in the blast radius of Microsoft Teams Exploited by Scammers in High-Profile Enterprise Phishing Surge? Write that list down before you open a war room. Most wasted hours on stories like this are spent debating severity before anyone knows whether they run the thing.
A security advisory released by threat intelligence researchers reveals that threat actors are systematically exploiting default external tenant federation settings in Microsoft Teams. Attackers impersonate corporate IT support personnel or executive leadership to deliver malicious payload links and execute authorization fraud.
Microsoft Teams Exploited by Scammers: how it works
Anyone running the affected component in production, CI, or a laptop fleet is in scope until proven otherwise. Inventory first. Include forgotten staging clusters and contractor laptops — those are where 'we don't run that' turns out to be false.
Join 45,000+ engineers, founders, and tech leaders receiving our 5-minute daily breakdown of AI, hardware, and tech policy. CommentLoaderSave StorySave this storyCommentLoaderSave StorySave this storyZhao, a 30-something woman living in Beijing, says she lost over $100,000 in May to a romance scammer who claimed to be a researcher working for Microsoft.
Microsoft Teams Exploited by Scammers: why it matters now
Patch, rotate credentials, and confirm the vendor's fixed version from their advisory — not from a social recap. If you cannot patch today, isolate the service and raise the logging floor. Record the decision and the residual risk so the next person does not re-litigate it.
After initially chatting Zhao up on the Chinese social media platform Xiaohongshu, he asked to move their conversation to Microsoft Teams, where he was happy to provide her with an account and password she could use.“I didn’t think much because I had used this app before. Zhao says that at first, she was excited about the opportunity, and even took out loans from several banks so she could invest more.Then the scammer disappeared with all of her money.
Microsoft Teams Exploited by Scammers: who is affected
Most incidents in this class are either an input-handling bug or a trust-boundary miss. Reconstruct the path with the advisory's affected-versions list in hand. If you cannot explain the path in three sentences, you do not understand it well enough to declare yourself safe.
Because she can no longer log into the Teams account he told her to use, she can’t share the chat logs with police.After Zhao began talking about her experience on social media, she says she started hearing from dozens of other people in China who have fallen prey to the same scheme. They claim to have lost anywhere from $1,500 to $300,000, and only one reported that they were able to recover some of the funds—by tracking down the recipient’s bank account.The victims all describe the same pattern.
Microsoft Teams Exploited by Scammers: what to watch
What is still unknown is as important as what shipped. Track whether exploitation is confirmed, whether a CVE is assigned, and whether your WAF or EDR signatures have caught up. Revisit the ticket when any of those three flip.
At some point, they were instructed to download Microsoft Teams and log in using credentials provided by the scammers. WIRED analyzed the past 18 months of reviews of Teams on Apple’s Chinese app store, and found that out of 500, 30 percent included explicit complaints about scammers.
A 3–5 minute news post is a briefing, not a runbook. Keep Wired and the vendor's primary page in another tab, quote only what they printed, and write down the single decision this story forces (upgrade, wait, or ignore) before you Slack it to the rest of the team. If you need more than that decision, you want the primary docs or a later engineering deep-dive — not another recap of Microsoft Teams Exploited by Scammers in High-Profile Enterprise Phishing Surge.
Enterprise IT departments are urged to audit external communication policies, restrict guest tenant messaging rights, and enforce multi-factor authentication (MFA) step-up challenges for any financial transaction authorization requested over internal chat platforms.
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
Deep Dive: AI Data Center Power Demands vs Environmental Air Quality Limits
Read →
Open-weight AI companies are the Valley’s hottest acquisition targets
Read →
Global AI Infrastructure Debt Exceeds $400 Billion as Lambda Secures $1 Billion Credit Facility
Read →
Steve Jobs’ Hand-Built 1968 Science Fair Project Fetches $34,375 at Auction
Read →
Free Tools
- ✉️ Vintage Letter Generator
Free handwritten-style vintage letter maker — love notes, parchment, download
- 🎨 Past Forward
AI vintage photo editor — travel a portrait through decades
- ✈️ CareerPilot
AI job-search copilot: live job matching, fit scores & resume optimization
- ⚡ Code Formatter
Clean and format any code snippet instantly
- 🔒 Data Masking Tool
Mask sensitive data in logs and test fixtures
- 🖼️ Base64 Decoder
Decode and preview base64 image strings