Microsoft Teams phishing attack hits 150+ employees
A fake Microsoft Teams help desk scam tricked over 150 employees across 10 companies into handing over their login details. Attackers used real Teams accounts to pose as IT staff and send convincing fake support requests.
- Report priority
- Medium
- Targets
- Microsoft
How it works
Attackers set up fake Microsoft Teams accounts to impersonate real IT help desk staff, then sent fake support requests to employees via Teams messages.
What to do
Check if you got a suspicious Teams message from an unknown or unusual sender asking for your password or account details between January and April 2026.
Never click links in unexpected Teams messages, even if they look like they're from IT. Report suspicious messages to your company's IT team immediately and change your password if you clicked anything.
Technical details
An employee gets a Teams message from what looks like their company's IT help desk. It says their account is locked and asks them to click a link to 'verify their password.' The link goes to a fake Microsoft login page, where the attacker steals their real password.
A coordinated social-engineering campaign dubbed Spring Ring used external Microsoft Teams accounts to impersonate corporate IT help desk staff and target more than 150 employees across at least 10 organizations between January and April 2026.