A cyberattack via Microsoft Teams is any attempt to extort login credentials, take over an account or persuade an employee to perform a dangerous action, in which the criminal uses trust in this platform as an everyday work tool. There are two main variants:
- Phishing impersonating Teams – a classic message imitating the Teams system notification (“you have a new message”, “verify access”), which leads to a fake Microsoft login page. The victim does not open the application itself – the attack takes place in the email box.
- Attack conducted directly inside the Teams platform – a message, file or voice call sent from within the application itself, often from a compromised internal account or with abuse of the Teams federation (access from an account outside the organization), e.g. impersonating the IT department in a voice call or sharing a malicious file in a team chat.
The first variant is partially caught by anti-spam filters at the mailbox level, the second one takes place inside a trusted work environment and often bypasses these protections completely. In both cases, effective human manipulation may result in a serious security incident that will disrupt the continuity of the organization.
That’s why at SECAWA we build security awareness against this type of attack. See how we did it for one of our real estate clients.
Why are phishing attacks via Microsoft Teams so effective?
Employees trust Teams notifications more than emails because they associate them with internal communication and not with an external threat. Attackers take advantage of this automatic trust reflex, combining it with social engineering techniques tailored to the professional context – a request for urgent document approval, notification of a message from a superior or an alert about an alleged access problem.
A few examples of attacks using Microsoft Teams:
- The Cloaked Ursa group (also known as APT29 / Cozy Bear), linked to Russian intelligence, used compromised Microsoft 365 accounts to send Teams messages with malicious links that redirected victims to fake Microsoft login pages (Unit 42, Palo Alto Networks). In December 2025, a group tracked by Mandiant as UNC6692 impersonated an IT helpdesk in Teams, tricking employees into accepting a chat request from an account outside the organization (Unit 42, Palo Alto Networks).
- ReliaQuest researchers described an automated campaign attributed to former affiliates of the group ransomware Black Basta: attack combines mass “email bombing” with impersonating the IT department in a Teams chat or telephone conversation, and sometimes only 12 minutes pass from the first contact to the launch of a malicious script. In March 2026, 77% of such attacks targeted management staff – an increase from 59% at the beginning of the year (ReliaQuest).
- There was also a phishing campaign impersonating Teams notifications – over 9,000 cases in two months, mainly in the financial, professional services, manufacturing and healthcare sectors (Mimecast).
These examples show the scale of a phenomenon that cannot be ignored if your organization uses Teams for teamwork every day.
What does phishing via MS Teams look like step by step?
The most common scenario starts with a message in Teams that looks like a standard system notification – information about a new message from a colleague, an alert about an access problem, or a request to verify your account. The link leads to a credential harvesting page, confusingly similar to a real Microsoft login screen.
In more advanced variants, attackers do not stop at the password – they use the theft token as part of an adversary-in-the-middle (AiTM) attack, capturing the session token in real time and thereby bypassing MFA, even though the victim has successfully authenticated.
This technique was documented by Microsoft, among others: in a campaign that in April 2026 took over the login data and session tokens of 35,000 users in over 13,000 organizations in 26 countries – this shows how easily the same mechanism can also be adapted to messages impersonating Teams (Microsoft Security Blog). A similar effect – taking over access to Microsoft 365 without capturing the password itself – is possible through Kali365, a Phishing-as-a-Service platform, which the FBI warned about in May 2026, pointing out, among other things, to the use of phishing content generated by AI, which makes them more difficult to distinguish from authentic communication (Internet Crime Complaint Center, FBI).
A separate category of threat is the abuse of Teams federation and access to external accounts – the attacker, acting from an account outside the organization, impersonates the IT department and initiates a voice connection (vishing) to build trust and trick the victim into installing a remote access tool.
Microsoft secures Teams with many mechanisms – TLS encryption, Entra ID, conditional access policies, audit logs and an architecture similar to Zero Trust. However, none of these mechanisms will work if the employee himself knowingly provides login details on a fake website. That’s why an organization’s resilience to this type of attack ultimately depends on people’s vigilance, not just the system’s configuration.
At Practical Anti-Phishing Training we have been checking teams’ resistance to this type of impersonation for a long time using classic phishing simulations – a fake email or SMS message impersonates a Teams notification and leads to a fake Microsoft login page.
Below we show what such a test looked like in practice for one of our clients – and why, in response to the growing number of attacks carried out directly inside the platform itself, we are expanding the functionalities of our platform with native simulations in Teams.
How to protect your organization against phishing via MS Teams? Case study
The first attack simulation revealed the scale of human risk
An organization from the real estate industry that manages office space decided to verify its resistance to social engineering attacks as part of a Practical Anti-Phishing Training. One of the first simulations recreated the scenario of a fake new message notification in Teamsleading to a fake Microsoft login page. And the result revealed real human risk:
- 41% of employees clicked on a link leading to a fake login page,
- every fifth employee (approx. 19.5%) entered their login details there – on average within 45 seconds of opening the message,
- no one reported the suspicious message.
About one in five employees provided login details to the fake site within 45 seconds of opening the message. This means that in a real attack, a cybercriminal would need less than a minute to gain access to the account and start moving around the organization’s resources.
What have we done to measurably reduce human risk?
After this first, highly diagnostic campaign, SECAWA team planned systematic security awareness training based on tailored cyberattack simulations and micro-trainingwhen taking a risky action, which taught how to recognize the threat next time and protect against it react. The simulations deliberately differed in social engineering techniques, building resilience on three fronts simultaneously:
- Digital identity and work tools – fake emails (phishing) impersonating Teams notifications and smishing impersonating access systems (e.g. VPN), teaching how to recognize account takeover attempts.
- Emotions and interpersonal relationships – scenarios using curiosity, compassion, social proof and flattery, embedded in HR topics and everyday office situations.
- Authority and time pressure – messages impersonating the IT department, forcing a quick response without verification.
We wanted employees to regularly practice vigilance against various types of attacks. We prepared a variety of phishing campaigns – from impersonating Teams to a false alert from the IT department, which showed us the true picture of vulnerabilities. And the results of subsequent simulations turned out to be truly impressive.
Click-through rate dropped from the initial 41% to less than 2%
41% of clicks, including 19.5% of entered passwords – this is a scale of the problem that could not be ignored. Therefore, in the following months, we carried out further phishing campaigns, and although the overall trend showed a clear decline, those based on highly engaging topics, such as information about holidays or wishes on Women’s Day, temporarily increased the click rate even above the starting result.
This didn’t mean that Practical Anti-Phishing Training didn’t work – just that some phishing methods still require attention. This is how we approached subsequent campaigns, adjusting the scenarios on an ongoing basis, until after a few months the click-through rate dropped to approximately 13%, and in the final phase of the program it stabilized below 2%.
What is also worth paying attention to is that training resulted in a real change in approach: active office managers very quickly began towarn other employees about suspicious messages.
The platform also made it possible to precisely locate the risk –approx. 6% of the team required additional educational support due to a recurring vulnerabilitywhich ensured that subsequent actions went exactly where they were needed most.
We are extending the Practical Anti-Phishing Training with simulations in Microsoft Teams
The growing number of real attacks described above, carried out directly inside the Teams platform itself, not only through messages imitating it, influenced the development of our proprietary security awareness training platform (Security Awareness Training).
So far, we have checked the vulnerability to MS Teams Phishing using a classic simulation – a fake email or SMS imitating a messenger notification. This was enough to reveal the real risk for the client described above, but it does not reproduce the full spectrum of the threat, because an increasing number of attacks now take place directly inside the platform. That is why we are expanding the Practical Anti-Phishing Training with native simulations of attacks conducted directly in Microsoft Teams.
Cybercriminals are shifting their activity to where people spend most of their time at work today – to company messengers. That’s why we are expanding the SECAWA platform with attack simulations directly in work messengers. We will teach teams how to recognize and respond to phishing in MS Teams.
We have been developing our own platform for simulating cyberattacks for seven years – we are not a reseller of a ready-made tool from a foreign supplier, we design, implement and constantly expand the technology with our own team of specialists. This makes adding new functionalities to the SECAWA platform a natural step – one of our goals is to constantly develop the tool to keep up with modern cybercriminals’ methods.
If you want to learn more about Practical Anti-Phishing Training, schedule a free demo during which you will see our Polish training platform in action, real simulations of cyberattacks and a dashboard that allows you to measure the organization’s resilience and, with one click, generate a report that helps demonstrate compliance with DORA, NIS2, KSC 2.0, ISO 27001 and GDPR.

