What to look out for today
Be on guard for unexpected Microsoft Teams chats (especially from unknown people or external contacts) that try to rush staff into clicking links, opening files, or “signing back in”. A newly reported malware campaign is being distributed via Teams phishing and aims to steal credentials using a fake lock screen.
Why this matters to smaller businesses
For many SMEs, Teams is a primary channel for day-to-day work and quick approvals. If an attacker steals a user’s Microsoft 365 credentials, they may be able to access email, files, chat history, and potentially use the account to target customers and suppliers. This can quickly turn into payment fraud, data exposure, and operational disruption.
Warning signs
- A Teams message from an unfamiliar person or an unusual external address, especially with urgent language (“account locked”, “new policy”, “invoice overdue”, “IT needs you to verify”).
- Requests to open an attachment or click a link to “view a document” or “confirm access”.
- A sudden “lock screen” or sign-in prompt that appears after clicking something in Teams, particularly if it doesn’t look like your normal Microsoft sign-in flow.
- Colleagues reporting strange Teams messages “from you” that you didn’t send.
- Unexpected MFA prompts (approve/deny notifications) following a Teams interaction.
How attackers may exploit the situation
- Credential theft: tricking staff into entering Microsoft 365 usernames/passwords into a fake prompt or lock screen.
- Account takeover: using stolen credentials to access mailboxes and Teams, then impersonate staff internally and with customers/suppliers.
- Malware foothold: using compromised accounts to distribute further malicious links/files to other staff.
- Payment and invoice fraud: once inside email/Teams, attackers may watch invoice conversations and attempt to change bank details or intercept payments.
What to do today
- Remind staff: treat unexpected Teams messages like emails—don’t click, don’t open, verify via another channel (phone call using a known number).
- Review external access: check whether your Teams settings allow external chats and whether it’s needed for your organisation.
- Harden sign-in: ensure MFA is enabled for Microsoft 365 and that staff know to report unexpected MFA prompts immediately.
- Set a simple reporting route: “If you get a suspicious Teams message, forward/screenshot to IT (or your MSP) and do not engage.”
- Finance control: reinforce that bank detail changes must be verified out-of-band (call-back) even if the request comes via Teams.
Ask your IT provider
- Do we allow external Teams chats? If yes, can we limit them to approved domains/partners?
- Do we have alerting for suspicious Microsoft 365 sign-ins (impossible travel, unfamiliar locations, repeated failures)?
- Are we logging and monitoring Teams messages/links enough to investigate suspected phishing quickly?
- What’s the process if a user reports a fake sign-in prompt or suspected credential entry—how fast can we reset sessions, revoke tokens, and check mailbox rules?
- Do we have conditional access policies (where appropriate) to reduce risky sign-ins?
Patch watch - only one short paragraph, and only if relevant
This Teams-based campaign is primarily a social engineering and credential theft risk rather than a “patch it and it goes away” issue. Keep standard device and Microsoft 365 security updates moving, but focus today on blocking risky sign-in paths, tightening Teams external access, and staff reporting.
One action today
Send a same-day staff note: “Treat unexpected Microsoft Teams messages like phishing—don’t click links or open files from unknown/external contacts; verify by phone using a known number; report immediately to IT/MSP.”
Related Actions On Cyber resource
Actions On Cyber CTA: Microsoft 365 / Teams phishing mini-checklist (staff guidance + reporting steps + finance verification)
Sources
- New SynkLoader malware pushed in Microsoft Teams phishing campaign (BleepingComputer)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.