Categories: Digital LifeNews

This “Microsoft Teams” scam aims to steal your login credentials

There has been a report that a new phishing campaign has been aimed to steal the login credentials of employees by sending fake Microsoft Teams notifications. As many individuals move to full-time remote work due to the COVID-19 pandemic, they could be more likely to succumb to the scam online.

Attackers use crafted emails that appear to be emails of automated notifications coming from Microsoft Teams. Once the user clicks a malicious link in the email, it takes them to the fake landing page that impersonates the webpages of Microsoft Teams.

More and more victims are likely to fall for the scam as more people switch from Zoom to Microsoft Teams in light of Zoom’s safety and privacy issues. Here are two different attacks that try to steal employee login credentials, according to researchers:

  • The email includes a link to a document that contains an image that urges recipients to login with Microsoft team, upon clicking the image it takes to the fake Microsoft Office login page.
  • A YouTube link, redirected multiple times, and reaches a final webpage that impersonates Microsoft login page.
Image source: gbhackers.com

If a victim falls for any of the scams, their login details get compromised, and attackers may even gain access to Microsoft Office 365 services. The attack targets more than 50,000 employees in more than 150 companies, as reported by the Group-IB Threat Intelligence group.

However, in the case of the attacks, neither security configurations nor vulnerabilities in Microsoft Teams were at fault. Instead, they note that the scam emails were “convincingly-crafted” impersonating the automated notification emails from Microsoft Teams. 

“Recipients would be hard-pressed to understand that these sites were set up to misdirect and deceive them to steal their credentials. Given the current situation, people have become accustomed to notifications and invitations from collaboration software providers,” said Abnormal Security.

As a general rule, do not log into suspicious links, and always make sure you’re on the official site by checking the URL before entering your credentials. Spam phishing emails will often ask you to go to a fraudulent or spoofed website to re-enter your credit card number or verify your password. Scammers will also try to have you call them on the phone to provide your personal information. Keep in mind that reputable businesses would not make such requests by email.

[ SOURCE, 2 ]

Recent Posts

ASUS ExpertBook Ultra: Flagship Business Laptop with Premium Looks, Military-Grade Toughness, and Serious Power

This post is brought to you by ASUS. If you are looking for a flagship…

13 hours ago

Countdown to Kickoff: Unifi TV Brings All 104 FIFA World Cup 2026 Matches Live in HD

This post is brought to you by Unifi. The wait is almost over. On June…

16 hours ago

Over 100 EVs take over Sepang for SoyaCincau x Dongfeng Pop-Up EV Clinic: Track Edition 2026

More than 100 electric vehicles (EV) gathered at Sepang International Circuit on the 6th June…

1 day ago

Gentari deploys four DC Chargers at Publika Shopping Gallery

If you're heading to Publika Shopping Gallery at Solaris Dutamas in Kuala Lumpur, there are…

1 day ago

Gentari turns on 180kW DC Charger at Petronas Batu Ferringhi

Gentari continues to deploy more EV chargers on Penang Island and the latest location is…

1 day ago

KLIMS 2026: Malaysia’s premier mobility extravaganza promises more than just car showcase

This post is brought to you by KLIMS. Making a return for the 11th time,…

2 days ago

This website uses cookies.