Hackers Using Teams to Deliver Malicious Content Posing as Microsoft Services
ID: 4c93b1d1-4294-5907-9d8e-65d98910ca41
STIX ID: report--4c93b1d1-4294-5907-9d8e-65d98910ca41
Feed Name: cybersecurityNews.com
A large-scale phishing campaign abuses Microsoft Teams' native "Invite a Guest" functionality to send fraudulent billing notifications from legitimate Microsoft email addresses, evading standard email authentication and content filters; messages contain obfuscated team names and phone numbers to induce victims to call fraudulent support lines (vishing). Telemetry observed 12,866 phishing messages affecting ~6,135 customers globally, predominantly in the U.S. and impacting sectors like manufacturing, technology, and education; defenders are advised to educate users and scrutinize unexpected Teams invitations containing urgent financial language or phone numbers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
