Attackers are posing as IT support inside Microsoft Teams. Two settings decide whether they can reach your staff — and both are wide open by default.
The email looks harmless — an employee survey from HR. Twenty minutes after someone opens it, a Microsoft Teams call comes in from "System Administrator." There's a problem with your account, the caller says. They'll walk you through fixing it.
That's the opening move of a campaign documented by Palo Alto Networks' Unit 42 and reported by BleepingComputer in early July. The "administrator" talks the employee into sharing their screen, then into installing a remote-control tool like AnyDesk. From there the attacker installs malware — this one is called EtherRAT — and has full control of the computer. In one case researchers traced, the fake help desk was messaging from [email protected]: a Microsoft 365 account at a company that doesn't exist, named to look like IT support.
Why the scam moved into Teams
Your team has spent years learning to distrust email. Odd sender address, urgent tone, unexpected attachment — most people now hesitate.
Nobody taught them to hesitate in Teams. A chat message feels internal, pre-vetted, safe. Attackers have noticed: Unit 42 reports that in the first four months of 2026, 42% of the phishing alerts its systems flagged came through collaboration tools like Teams — up from 30% in the four months before.
Teams does label these messages "External." But the label is small, the sender's name says "IT Support," and it's 4:55 on a Friday. The researchers' conclusion, and ours: don't leave this to the label.
The two settings that decide who can message your staff
Here's the part most owners don't know. Out of the box, Microsoft 365 lets two groups of strangers start a chat with your employees:
1. Anyone with a free personal Teams account. There's a checkbox in your settings — the actual name is "External users with Teams accounts not managed by an organization can contact users in my organization." If it's on, anyone who signed up for free Teams with any email address can message your team.
2. Anyone at any other Microsoft 365 organization. The default for external organizations is "Allow all external domains." That means every one of the millions of Microsoft 365 setups in the world — including one an attacker created last week and named like a help desk — can start a chat or a call with your staff.
Neither of these is a flaw Microsoft needs to patch. They're settings, sitting on their most open position, in a corner of the admin center nobody visits — Microsoft's own documentation walks through both.
What to do this week
Tell your team the one rule. Real IT support will never cold-message you asking to approve a sign-in prompt or install remote-control software. If "IT" appears in Teams unannounced, verify through a channel you already trust — your IT provider's known phone number, or the owner. Takes two minutes at your next stand-up.
Ask your IT provider for the two changes by name. Turn off "External users with Teams accounts not managed by an organization can contact users in my organization." And switch "Teams and Skype for Business users in external organizations" from "Allow all external domains" to "Allow only specific external domains," listing just the partners you actually chat with. Both live in the Teams admin center under Users → External access. Fifteen minutes, and this entire scam category can no longer reach your people.
If nobody chats with outsiders, close the door completely. Plenty of small businesses never use Teams externally. If that's you, blocking all external domains costs nothing and ends the conversation.
Settings like these — wide open by default, invisible until someone abuses them — are exactly what Tenant Strike's read-only scan checks for: it grades your Microsoft 365 setup A–F and shows the exact fix, in under five minutes, without changing anything.
The attackers running this campaign are still refining their malware — researchers found nine versions and counting. The fix on your side, though, isn't software. It's two settings and one sentence to your team.
AI-researched from public sources, human-reviewed on July 22, 2026. We label AI-assisted writing — see our trust page.
See your own risk
Want this for your own Microsoft cloud?
Tenant Strike runs 130+ read-only checks across Microsoft 365 and Azure and hands you a plain-English fix for every gap. Start a 7-day Pro trial — no credit card.