AWSMTECH

Microsoft Teams Is Becoming a New Playground for Social Engineering

CybersecurityBy Editorial Team5 min read
An employee’s hands on a laptop in a dark office, with a messaging window showing an incoming message highlighted in lime green and a screen-sharing request

01From the Inbox to Collaborative Messaging

For years, most phishing campaigns went through email.

Businesses gradually strengthened their defences: advanced filtering, behavioural detection, stronger authentication and employee awareness training.

At the same time, working habits changed.

Internal communication now largely takes place on platforms such as Microsoft Teams. Informal discussions, support requests, document sharing and virtual meetings have all become routine there.

For attackers, this shift opens up a new field of opportunity.

Why try to get around email filters when you can contact a user directly in an environment they regard as legitimate?

02When Fake IT Support Contacts the Employee

According to several analyses published in summer 2026, cybercriminal groups used Teams accounts to pose as members of IT support or the helpdesk. They would start a conversation with an employee by referring to a technical incident, a security update or an email problem requiring intervention. [cybersecur...tydive.com], [cyberpress.org]

The aim was not to exploit a vulnerability in Microsoft Teams.

The aim was to persuade the user to carry out an action themselves: launch a remote assistance tool, approve a remote-control session or install a component presented as legitimate. [cybersecur...tydive.com], [windowsreport.com]

Sophos researchers observed, in particular, campaigns targeting several dozen North American companies between February and June 2026. In some cases, the access obtained subsequently enabled the deployment of Chaos ransomware. [cybersecur...tydive.com], [cyberpress.org]

03An Attack That Exploits Trust More Than Technology

What makes these campaigns noteworthy is not so much their technical sophistication as their understanding of professional working habits.

The user receives a request in a tool they use all day long.

The request appears consistent with how the business normally operates.

The tone is often professional.

The context is credible.

Under these conditions, it can sometimes be difficult for an employee to tell a legitimate intervention from an impersonation attempt straight away.

Microsoft Security researchers also point out that these operations rely on direct interaction with the user before any technical compromise phase.

This development illustrates a trend observed for several years: cyberattacks are increasingly targeting human processes rather than software vulnerabilities alone.

04SMEs Are Not Immune to the Phenomenon

The issue also affects Swiss SMEs.

The adoption of Microsoft 365 has greatly standardised the digital tools used by businesses, whatever their size. Today, an SME with twenty employees often uses the same collaboration platforms as a large international group.

This democratisation of technology clearly brings productivity benefits.

It also means that certain attack methods are becoming cross-cutting.

In many SMEs, employees regularly deal with an external IT provider or a shared support service. In this context, receiving an unsolicited support message may seem less unusual than in an organisation with a formal in-house service desk.

The issue is therefore not purely technical.

It also concerns operational governance and the way support requests are handled and authenticated.

05Verification Is Becoming a Governance Issue

Experts consulted on these campaigns often make the same observation: organisations generally have procedures in place to manage sensitive access, but more rarely simple rules for verifying the identity of someone requesting an exceptional action.

Yet a Teams message, a phone call or a screen share do not constitute proof of identity.

This reality is leading many businesses to formalise simple validation mechanisms:

  • confirmation via a separate channel;
  • a support ticket opened beforehand;
  • an identified point of contact within the organisation;
  • a procedure requiring approval before any software installation.

The aim is not to multiply controls, but to create an easily remembered reflex when a request falls outside the usual framework.

06A Trend That Goes Beyond Microsoft Teams

Reducing the phenomenon to Teams would probably be a mistake.

The campaigns observed reflect a broader trend: cybercriminals are gradually moving into the collaboration platforms businesses use every day.

Yesterday, email was the main vector for manipulation.

Today, attackers exploit collaborative messaging, remote support tools and cloud platforms.

Tomorrow, they could use other digital working environments with the same logic.

The real issue, therefore, is not Microsoft Teams itself.

The question is how an organisation verifies the identity of a contact when they request a sensitive action.

07Trust Remains an Asset to Protect

Organisations are investing heavily in cybersecurity tools.

  • Firewalls.
  • Email protection.
  • Detection of abnormal behaviour.
  • Identity security.

The campaigns observed in 2026 are a reminder, however, that a significant part of security still relies on trust mechanisms.

When a message appears to come from IT support within a familiar professional environment, the risk is not necessarily that an employee lacks vigilance.

The risk is that they have too little information to quickly verify that the person they are dealing with is who they claim to be.

For SMEs and large enterprises alike, this verification capability is gradually becoming a digital governance issue in its own right.

Box | Three Questions to Ask Yourself

  • Does your IT support sometimes contact users without a prior request?
  • Do employees know how to verify the identity of a contact who asks for an installation or remote control of their device?
  • Is there a single procedure, known to everyone, for validating an unusual request?

In many organisations, the answer to these questions will probably matter more than adding a new security tool.

08Sources

  • Hackers abuse Microsoft Teams in ransomware campaign through fake IT support [cybersecur...tydive.com]
  • Microsoft Teams Vishing Campaign Deploys Chaos Ransomware Through Fake IT Support Calls [cyberpress.org]
  • Microsoft Teams IT Support Scams Lead to Chaos Ransomware Attacks [windowsreport.com]
  • Impersonating IT support: how threat actors turn a remote session into enterprise-wide access [microsoft.com]

Would your employees recognise fake IT support?

AWSMTECH helps you define simple procedures for verifying support requests and secure your collaboration tools.

Talk to an expert