Numentis

When “Hi, This Is IT” Comes Through Microsoft Teams: A New Phishing Frontier

Cybercriminals are evolving—and fast. While email phishing has long been the primary attack vector, threat actors are now shifting their focus to collaboration tools like Microsoft Teams. According to recent research from Unit 42, phishing attempts originating from collaboration platforms surged from 30% to 42% in just eight months, signaling a major change in attacker strategy.

For organizations relying heavily on Teams for day-to-day communication, this shift is more than a trend—it’s a wake-up call.


The New Face of Phishing

Imagine this: an employee receives a Teams message that reads:

“Hi, this is IT. We’ve detected a login issue with your account. Please approve the MFA prompt to confirm your identity.”

It looks legitimate. It sounds urgent. And it comes through a trusted platform.

But it’s a trap.

Threat groups like APT29 (Cloaked Ursa / Cozy Bear) and UNC6692 are now using Microsoft Teams to impersonate IT staff or trusted partners. Instead of emails, they initiate chats—often from external tenants or compromised accounts—and guide victims into:

  • Clicking malicious links
  • Sharing credentials
  • Approving fraudulent MFA requests

The end goal remains the same: identity compromise.


Why Microsoft Teams?

Attackers go where defenses are weakest—and right now, that’s collaboration platforms.

Here’s why Teams has become a prime target:

  • Lower user skepticism: Employees are trained to distrust emails, but not internal-looking chats.
  • Default open federation: Many organizations allow external users to message employees by default.
  • Trusted environment: Messages feel immediate, personal, and legitimate.
  • Impersonation opportunities: Attackers use typosquatted domains or fake tenants (e.g., “IT Helpdesk Support”).

Even more concerning, some attackers are compromising legitimate partner accounts, bypassing allowlists entirely and exploiting existing trust relationships.


How the Attack Works

A typical Teams phishing attack follows this sequence:

  1. External contact initiates a chat (often disguised as IT or a vendor).
  2. Victim accepts the request, ignoring the external warning label.
  3. The attacker claims an urgent issue (e.g., account compromise).
  4. The victim is asked to:
    • Click a login link
    • Approve an MFA notification
  5. The attacker gains access—while continuing the chat to maintain credibility.

It’s simple. It’s effective. And it’s working.


The Real Risk: Identity is the New Perimeter

These attacks aren’t about malware—they’re about access.

Once an attacker compromises an identity, they can:

  • Access sensitive data
  • Move laterally across systems
  • Launch additional attacks internally
  • Maintain persistence within your environment

In today’s cloud-first world, identity is your security perimeter. And Teams is now a direct line to it.


How Organizations Can Fight Back

The good news? This isn’t a vulnerability in Teams—it’s a configuration and awareness gap. And it can be addressed.

1. Lock Down External Communication

  • Disable unmanaged external Teams communication
  • Move from open federation to a strict allowlist of trusted domains

2. Strengthen Identity Controls

  • Enforce Conditional Access policies
  • Require compliant devices for authentication
  • Implement step-up verification for sensitive actions

3. Adopt Just-in-Time Privileges

  • Use Microsoft Entra PIM to limit standing administrative access

4. Detect Suspicious Behavior

  • Monitor for:
    • External chat initiation from unknown domains
    • Typosquatted tenant names
    • Chat acceptance followed by login anomalies

5. Empower Users (Without Burdening Them)

  • Educate employees on this exact pretext:

    “IT will never ask you to approve MFA via chat.”

  • Enable easy reporting of suspicious messages

How NUMENTIS Helps You Stay Ahead

At NUMENTIS, we understand that modern threats require modern defenses. This shift to Teams-based phishing reinforces a key reality: security must move closer to identity, behavior, and user interaction.

Here’s how we help:

✅ Managed Microsoft 365 Security

We assess and harden your Teams and Entra configurations, eliminating risky defaults and tightening external access.

✅ Conditional Access & Identity Protection

Our experts design policies that stop unauthorized access—even if credentials are compromised.

✅ 24/7 Security Monitoring

We actively monitor for behavioral anomalies, including suspicious Teams interactions and identity misuse.

✅ Security Awareness Training

We go beyond generic training—educating your users on real-world threats like “fake IT” chats in Teams.

✅ Incident Response & Containment

If an attack happens, we act fast—revoking access, removing malicious chats, and securing affected accounts.


Final Thoughts

The shift from email to collaboration tool phishing isn’t just a trend—it’s a strategic evolution by attackers. As defenders, we must adapt just as quickly.

Microsoft Teams is a powerful productivity tool—but without proper controls, it can also become an open door.

The key? Reduce exposure, detect behavior, and remove the burden from your users.


Take Action Today

Don’t wait until a suspicious “Hi, this is IT” message becomes a breach.

Let NUMENTIS help you secure your Microsoft environment from modern identity-based threats.

👉 Contact us today to schedule a security assessment
👉 Or visit www.numentis.com to learn more about our managed security services

Stay secure. Stay ahead.