TL;DR:
- Attackers are using Microsoft Teams to contact your staff directly, posing as IT support or colleagues — and your email security filters can’t stop them because Teams messages bypass email entirely
- In H1 2026, 42% of phishing alerts triggered by collaboration tools — up from 30% just six months earlier — and attacks on Teams specifically take only 12 minutes from first message to getting into a victim’s system
- Two simple settings in your Microsoft 365 admin panel can block the most common attack method before it reaches your staff
If your business uses Microsoft Teams, your staff are likely getting better at spotting phishing emails. Attackers have noticed. They’ve switched to Teams.
This matters because everything you’ve done to harden email — spam filters, anti-phishing training, DMARC records — doesn’t protect Teams at all. Teams messages land directly in your employee’s chat window with no filtering layer in between.
Why Teams Has Become a Phishing Channel
Microsoft Teams allows users from outside your organisation to message your staff directly. By default, anyone with a Microsoft account can send a message to anyone in your company — they just see a small banner saying the sender is “external.”
Attackers exploit this in a straightforward way:
- They create a free Microsoft 365 account with a name like “IT Support” or “Help Desk” or something that looks like your company name
- They search for employees (LinkedIn is the usual source) and send Teams chat messages posing as IT support
- The message asks the employee to click a link, install something (Microsoft Quick Assist is commonly used), or call a number
- If the employee complies, the attacker has remote access to their computer — and from there, often to your network
The reason this works is trust. Teams feels like an internal tool. When a “Help Desk” account messages you on Teams saying your password is expiring, it feels more legitimate than a cold email saying the same thing. The “external” banner is easy to miss.
Security researchers have documented attacks where the entire process — from first Teams message to malware installed — takes under 12 minutes. That’s faster than your IT support could even be notified there’s a problem.
The Most Common Scenarios
IT support impersonation. The most frequent pattern. An attacker contacts a member of staff claiming to be from IT, saying there’s a problem with their account, a security alert, or a required password reset. They ask the employee to share their screen using Microsoft Quick Assist (a legitimate Microsoft remote assistance tool) so “IT” can fix the problem. Once they have screen access, they move fast — capturing credentials, installing persistent malware, or mapping the network.
Executive impersonation. The attacker poses as a senior person in the company — the CEO, finance director, or HR manager. The message typically requests something urgent that requires bypassing normal processes: a bank transfer, a supplier payment, sharing a sensitive document. Because it comes through Teams rather than email, the usual “check the sender address” advice doesn’t help.
File sharing with malware. Teams allows external users to share files in chat. Attackers send documents or archives that appear to contain legitimate business content — contracts, invoices, proposals — but contain malicious macros or executables.
Two Settings to Change Right Now
Microsoft 365 gives you control over external Teams access, and most small businesses haven’t changed the defaults. Two settings make the biggest difference:
Block external chat from unknown organisations. In your Microsoft 365 admin centre, go to Teams → External access. You can configure Teams to only accept messages from specific domains (your suppliers, partners) and block everyone else. If you don’t regularly get Teams messages from strangers, blocking unknown external tenants removes the main attack surface.
The setting is at: Microsoft 365 Admin Centre → Teams Admin Centre → Users → External access
Require explicit approval for external chats. Even if you keep external access open, you can require that staff explicitly accept a chat before it’s delivered. This adds friction that discourages opportunistic attackers and gives staff a moment to question whether they recognise the sender.
How to Train Your Staff (Without a Training Budget)
You don’t need a formal training programme to address this. A short message to your team covering three points is enough to significantly reduce risk:
Point 1: IT will never contact you first through Teams asking for your password, to install something, or to share your screen.
If someone contacts an employee claiming to be IT support, the employee should end the chat and phone or message the actual IT person through a known contact method — not reply to the request. Real IT support knows this is the right policy.
Point 2: The “External” label on a Teams chat means this is NOT someone from your company.
Show your team what the external user banner looks like. It’s easy to miss when you’re busy. Anyone with “External” next to their name is not a colleague, even if their display name looks familiar.
Point 3: Never approve a Teams file from someone you weren’t expecting to receive one from.
Treat unsolicited files in Teams the same as unsolicited email attachments. If you weren’t expecting a file from that person, verify via a separate channel before opening it.
What if Someone Has Already Clicked or Shared Access?
If one of your staff has given a Teams “IT support” caller remote access to their computer via Quick Assist or a similar tool, treat it as a serious incident:
-
Disconnect the computer from the network immediately. Pull the ethernet cable or turn off Wi-Fi. This limits what the attacker can do while connected.
-
Change all passwords from a different, unaffected device. Start with email, Microsoft 365, and any banking or financial accounts. Assume everything accessible from that computer may be compromised.
-
Contact your bank if financial systems were accessible. If the compromised computer had access to online banking or payment platforms, notify your bank immediately — most UK banks have fraud teams available 24/7 for business accounts.
-
Report it. In the UK, report the incident to Action Fraud (0300 123 2040 or actionfraud.police.uk). If financial loss has occurred, also contact your bank’s fraud team and your cyber insurance provider if you have one.
-
Get the computer professionally examined before reconnecting it. Remote access gives attackers enough time to install persistent malware that survives a password change. A clean reinstall of the operating system is often the safest option.
The Wider Lesson
Teams phishing is a specific example of a broader shift: attackers go where the defences aren’t. Email security has improved considerably, so attacks are moving to collaboration tools, text messages, and phone calls.
The same scepticism your staff apply to suspicious emails needs to extend to all their communication channels. If something comes in unexpectedly and asks for urgent action — regardless of whether it arrives via email, Teams, WhatsApp, or phone — that’s a trigger to pause and verify through a separate, known-good contact method before acting.