https://www.bleepingcomputer.com/news/security/microsoft-teams-increasingly-abused-in-helpdesk-impersonation-attacks

Cybercriminals are increasingly exploiting Microsoft Teams to conduct sophisticated helpdesk impersonation attacks, using the trusted business communication platform to trick employees into compromising their organisations’ security. Attackers are leveraging Teams’ external communication features to contact victims directly, posing as IT support staff or helpdesk technicians to request credentials, remote access, or sensitive information. The attacks have surged as more organisations rely on Teams for daily operations, making unsolicited messages from supposed technical support appear more legitimate within the familiar workplace environment.

The scams typically begin with attackers sending Teams messages claiming there are urgent security issues, password expiration problems, or account verification requirements that need immediate attention. Victims are often pressured to act quickly, clicking malicious links, downloading remote access tools, or sharing login credentials with the impersonators. The attacks are particularly effective because Teams messages bypass traditional email security filters and appear within a platform employees trust for legitimate internal communications, making it harder for users to distinguish genuine IT support from fraudulent contacts.

Microsoft has acknowledged the growing threat and is working to enhance Teams security features, but user awareness remains the most critical defense. Organisations are being advised to implement strict policies regarding external Teams communications, educate employees about verifying support requests through official channels, and establish clear protocols for IT helpdesk interactions. Users should treat unexpected Teams messages requesting credentials or system access with the same skepticism they would apply to suspicious emails, and always verify the identity of anyone claiming to be from IT support through independent communication channels.