Managed IT Services

Microsoft Teams phishing: your inbox isn't the only frontline anymore

I want to be direct with you: we are seeing a sharp and sustained rise in Microsoft Teams phishing attacks, and we are seeing it across our own client base right now. This is not a future risk to plan for. It is happening today, and I want to make sure you know what to look for before it reaches your team. 

Email phishing has not gone away. Your people have got better at spotting suspicious messages, and attackers know it. So rather than replace email, they have added a second front: your collaboration platform. A channel most of us treat as inherently safe, because the messages there feel like they come from colleagues. That assumption is exactly what attackers are exploiting. 

Compliance Microsoft 365
5 min

by Ollie Hayward

Security & Compliance Lead for Access Managed Services

Posted 20/08/2026

Employee reviewing a potentially suspicious Microsoft Teams message on a laptop in an office, representing a Teams phishing threat

The scale of the problem 

  • 41% increase in Teams-based phishing attacks between October 2025 and March 2026 (Source: IT Pro, May 2026)
  • 10x rise in malicious Teams call attempts compared to the mid-2025 baseline (Source: Microsoft Security Blog, July 2026)
  • 77% of Teams-based attacks in Q1 2026 targeted executives, managers, or directors (Source: KnowBe4, May 2026)

 

Why Teams has become the channel of choice for attackers 

Teams is built for speed and informality. A message lands there and most people assume it is from a colleague. They reply quickly, without the pause they would give an email from an unfamiliar address. That instinct is exactly what attackers are counting on.1 

There is also a structural problem. Depending on configuration, teams can allow external users to contact people inside your organisation. So a message that looks like it is coming from your IT team, your finance director, or your CEO can, in reality, come from an account with no connection to your business whatsoever. The name looks right. The platform feels safe. And that combination is enough to catch people out. 

What these attacks actually look like 

We are seeing two patterns consistently across our client base. 

The impersonation message 

A threat actor creates or takes over a Teams account and uses it to contact someone inside your organisation, posing as a senior colleague, a manager, or someone from IT or finance. The message creates urgency: an account that needs securing, a payment that needs authorising, a compliance issue that cannot wait. Because it arrives in Teams rather than email, people are less likely to stop and question it. The platform itself lends the message credibility it has not earned.

The impersonation call 

This is the one that concerns me most right now. Attackers are not just sending messages. They are calling. Posing as IT support dealing with a security incident, they walk employees through handing over remote access to their machine. Once that access is granted, the damage moves fast. In documented cases, attackers went from first contact to executing malicious activity in 12 minutes.3 Twelve minutes from a Teams notification to a compromised device. 

The clearest warning sign: Check whether the sender is using a non-organisational Teams account. A genuine colleague will always appear under your company's domain. If the account looks external, or if you do not recognise the organisation it belongs to, treat it as suspicious before you do anything else. 

What to do if something feels wrong 

Trust that feeling. Here is exactly what to do. 

  1. Do not reply. Even a response that says you are not interested confirms the account is live and can invite further contact. 
  2. Block the sender. Hover over their profile picture, click the three dots, select "Block contact." It takes ten seconds and closes the door. 
  3. Verify through a different channel. If the message claims to be from a colleague, call them on their known number or send a separate email. Do not use any contact details the suspicious message itself provides. 
  4. Tell your security team. Every report helps us build a clearer picture of how these attacks are presenting. What you flag today could protect someone else tomorrow. 

How to block a contact in Teams: Hover over the sender's profile picture in the chat window, click the three dots (...) that appear, then select "Block contact" from the menu. The sender will no longer be able to reach you. 

When in doubt, just ask us 

I would far rather you send us a message that turns out to be nothing than stay quiet about something that turns out to be an attack. If a Teams communication does not feel right, reach out to the security and compliance team before you engage with it. That is exactly what we are here for, and there is no such thing as a question that is too small. 

Attackers succeed when people feel uncertain about whether something is suspicious enough to report. Do not give them that gap. If it feels off, it probably is. 

Want to make your organisation harder to attack?

Our managed security services cover the tools, monitoring, and training your team needs to stay ahead of threats like this one, without the overhead of building it all in-house. Talk to our security team to find out more.


Sources 

  • IT Pro (May 2026) - "The inbox is no longer the only frontline": itpro.com 
  • Microsoft Security Blog (July 2026) - "Email threat landscape: Q2 2026 trends and insights": microsoft.com 
  • KnowBe4 (May 2026) - "Much Faster Phishing Attacks Target Your Senior Execs via Microsoft Teams": knowbe4.com 

By Ollie Hayward

Security & Compliance Lead for Access Managed Services

Ollie Hayward is the Security & Compliance Lead for Access Managed Services. His role at Access includes helping customers strengthen their security posture, meet compliance requirements, and navigate the evolving cyber threat landscape. He works closely with organisations to identify risks, implement effective security controls, and ensure they remain aligned with industry standards and regulatory expectations.
Ollie is passionate about making security practical, understandable and effective for all customers, regardless of size.