Latest Article -

Brand Protection Alert: Critical Chrome Flaws You Must Fix

Security Awareness Platform: Microsoft Teams IT Support Scam

Security Awareness Platform: Microsoft Teams IT Support Scam

Security Awareness Platform programs are facing a broader social-engineering challenge as attackers increasingly move beyond email and use trusted workplace collaboration tools to reach employees. A campaign tracked by Palo Alto Networks Unit 42 as “Spring Ring” used external Microsoft Teams accounts to impersonate IT help desk personnel and target more than 150 employees across at least 10 organizations between January and April 2026.

The campaign reportedly used voice phishing, or vishing, to persuade employees to grant remote access or execute software. In a more advanced attack path, researchers observed an attempted NTLM relay attack against a domain controller. The incident is a useful case study in why security awareness must address trusted communication channels, authority-based manipulation, and real-time social engineering rather than focusing exclusively on suspicious email.

What Happened in the Microsoft Teams IT Support Scam?

Unit 42 discovered a coordinated operation in which external Microsoft Teams identities posed as internal IT or help desk employees. Researchers identified more than 26 distinct identities approaching targets and observed activity against more than 10 organizations and more than 150 individual employees.

The attackers used professional-looking names and external Microsoft 365 tenants designed to make the contacts appear legitimate. After establishing contact through Teams, they initiated voice calls and attempted to persuade employees to follow technical instructions.

The campaign did not rely on a Microsoft Teams vulnerability, according to Unit 42. Instead, it abused legitimate collaboration functionality and the trust employees place in familiar workplace tools.

This distinction matters. A trusted application can be used as a delivery channel without the application itself being compromised.

How the Attackers Used Vishing and IT Impersonation

The central technique was vishing, where attackers use a voice conversation to manipulate a target into taking an action that benefits the attacker.

In Spring Ring, the supposed IT technician created a sense of legitimacy through a combination of:

  • A familiar enterprise communication platform.
  • An IT or help desk identity.
  • A professional-sounding display name.
  • A technical explanation for why assistance was supposedly required.
  • A direct voice conversation rather than a static message.
  • Pressure to perform an action during the call.

Unit 42 reported that successful calls often lasted between 10 and 15 minutes, while some attempts were much shorter or resulted in missed calls and voicemails. Attackers could therefore adapt their approach according to how employees responded.

This creates a different human-risk environment from conventional email phishing. During a live call, an employee may feel pressure to respond immediately, particularly when the person on the other end claims to be responsible for account security, system maintenance, or an urgent technical problem.

The objective of effective security awareness is not to make employees distrust every IT interaction. It is to give them a reliable verification process when a request falls outside normal procedures.

Why the Teams Environment Made the Social Engineering More Convincing

Attackers benefit when their communication appears to originate inside an organization’s normal workflow.

Employees routinely use Teams for meetings, technical support, project coordination, and internal communication. A message or call arriving through that environment can therefore feel more credible than an unexpected external email.

Unit 42 described this as a “trust gap,” where attackers exploit confidence in SaaS collaboration platforms and human interaction. Researchers also noted that voice conversations may receive less monitoring and documentation than email or file activity, creating another challenge for defenders.

Microsoft has separately documented an identity-focused intrusion involving attackers who impersonated IT support through Teams and convinced a user to grant remote access. Microsoft emphasized that the campaign abused legitimate collaboration and remote-support functionality rather than exploiting a Teams software vulnerability.

For security leaders, the lesson is straightforward: security awareness policies should cover where employees communicate, not only what messages look suspicious.

What Employees Should Recognize During a Fake IT Support Call

Employees do not need to identify a specific threat actor or understand the underlying attack infrastructure. They need to recognize behavioral warning signs.

A supposed IT support representative should trigger additional verification when the interaction includes:

  • An unexpected external Teams account claiming to be internal support.
  • A request to approve remote control of a computer.
  • Instructions to install remote-management software without normal IT procedures.
  • Pressure to act immediately because an account is supposedly at risk.
  • Requests to disclose passwords, authentication codes, or other sensitive information.
  • A request to bypass established help desk processes.
  • A caller who discourages independent verification.
  • A technical request that seems inconsistent with the employee’s normal role.

The strongest employee behavior is often simple: stop, verify, and report.

Employees should use a known internal contact method to confirm unusual IT requests rather than relying on contact details supplied by the caller. They should also report suspicious interactions even when they did not provide information or complete the requested action.

Why Security Awareness Training Must Include Vishing

Traditional security awareness programs frequently concentrate on email phishing. That remains useful, but the Spring Ring campaign demonstrates why phishing awareness needs to expand into other channels.

A modern Cybersecurity Training Platform should help employees understand that social engineering can arrive through:

  • Microsoft Teams and other collaboration platforms.
  • Phone calls and vishing.
  • SMS and smishing.
  • QR codes and quishing.
  • Fake document-sharing notifications.
  • Impersonated managers or vendors.
  • Deepfake audio or video when such techniques are relevant to the organization’s risk profile.

The goal is not to overwhelm employees with every possible attack technique. Training should focus on the scenarios most relevant to their roles and working environment.

Cyberfrog’s current platform positioning centers on AI-powered security awareness training and realistic simulations across multiple attack channels, including phishing, voice calls, SMS, QR codes, deepfakes, and multi-step social engineering.

Its security awareness training guidance also emphasizes continuous learning, realistic decisions, role-based training, safe simulations, and measuring behavior rather than relying solely on completion records.

How a Security Awareness Platform Can Prepare Employees

A Security Awareness Platform can turn an incident such as Spring Ring into a practical learning scenario.

Cyberfrog platform

Train people for the attacks they actually face.

Build stronger habits with phishing, vishing, smishing, deepfake and immersive simulations employees remember.

Book a demoExplore features

Instead of simply telling employees, “Never trust unexpected IT calls,” organizations can teach a repeatable decision process:

  1. Pause the interaction. Avoid allowing urgency to dictate the decision.
  2. Check the identity. Confirm whether the supposed IT representative is using an approved support channel.
  3. Verify independently. Contact the organization’s help desk using a trusted method.
  4. Protect credentials. Never disclose passwords, MFA codes, or authentication information during an unsolicited support interaction.
  5. Question remote access. Confirm that remote assistance is expected and authorized before granting control.
  6. Report the attempt. Reporting helps security teams identify patterns affecting other employees.

These behaviors are particularly useful because they remain relevant even when attackers change their names, scripts, platforms, or technical tooling.

Why Phishing Simulations Should Go Beyond Email

A phishing simulation does not need to be limited to an inbox.

For a campaign such as Spring Ring, organizations could use an authorized social-engineering exercise to test whether employees recognize an unexpected support request and follow verification procedures. The simulation should be controlled, safe, clearly governed, and followed by appropriate education.

Cyberfrog’s current platform describes a full attack simulation suite covering email, SMS, QR codes, malicious attachments, voice calls, video deepfakes, and multi-step social-engineering scenarios.

That approach is particularly relevant to human-risk management because an employee may perform well in an email simulation while responding differently to a convincing voice interaction.

Cyberfrog also discusses why realistic security awareness training should recreate the context in which employees actually make decisions, rather than relying exclusively on passive learning.

A simulated interaction should never be interpreted as proof that an employee would have been compromised in a real attack. It is an observation from a controlled exercise and should be evaluated alongside reporting behavior, repeated outcomes, role, training response, and improvement over time.

Human Risk Management Should Measure More Than Click Rates

Spring Ring also highlights why human risk cannot be reduced to one number.

For an awareness program, useful indicators may include:

  • Simulation interaction rates.
  • Reporting rates.
  • Reporting speed.
  • Repeat outcomes across different scenarios.
  • Training completion.
  • Knowledge-check performance.
  • Role-specific trends.
  • Improvement after targeted training.
  • Response to multiple attack channels.

NIST has cautioned against treating phishing click rates as the sole measure of employee proficiency. Its Phish Scale work discusses the need for security awareness programs to use additional measures when evaluating phishing training and the human element.

A person who interacts with one simulated message should not automatically be labeled permanently high risk. Human Risk Management works better when results identify learning opportunities and help security teams adapt training.

What Organizations Should Do About Teams-Based Social Engineering

Security teams can address this class of attack through a combination of technical controls, clear procedures, and continuous education.

For IT and security teams

Review external collaboration policies and determine whether unexpected Teams contacts should be restricted, flagged, or routed through additional controls. Monitor for unusual remote-support activity and investigate unexpected combinations of collaboration activity, remote-access tools, scripting activity, and authentication anomalies.

For managers

Reinforce that legitimate IT support should follow established processes. Employees should never feel pressured to comply with a technical request simply because the caller appears authoritative.

For awareness teams

Convert real incidents into scenario-based lessons. A fake IT support call is more useful as a training scenario when employees must decide what to do rather than simply memorize a list of warning signs.

For compliance and GRC teams

Document awareness activities, simulation governance, learning outcomes, and program improvements where relevant. Training records can support broader governance activities, but completing training alone does not demonstrate that human risk has been eliminated.

Security Awareness Checklist for Fake IT Support Scams

Organizations can use this checklist to strengthen employee resilience against collaboration-platform impersonation:

  • Teach employees that Teams can be abused for social engineering.
  • Establish a trusted process for verifying IT support requests.
  • Train employees never to disclose passwords or authentication codes.
  • Explain why unsolicited remote-control requests require verification.
  • Include vishing alongside traditional email phishing awareness.
  • Run authorized, realistic social-engineering simulations.
  • Provide immediate educational feedback after simulations.
  • Make suspicious-activity reporting simple and psychologically safe.
  • Measure reporting and behavioral improvement, not only training completion.
  • Review emerging incidents and update awareness scenarios accordingly.
  • Coordinate awareness initiatives with identity, endpoint, collaboration, and access controls.

Frequently Asked Questions

What is the Microsoft Teams IT support scam?

The Microsoft Teams IT support scam refers to social-engineering activity in which attackers impersonate IT or help desk personnel through Teams. In the Spring Ring campaign identified by Unit 42, attackers used external Teams identities and voice calls to persuade employees to take actions that could provide remote access or enable further attack activity.

Was Microsoft Teams itself hacked?

Unit 42 reported that the Spring Ring operation did not exploit a Microsoft Teams vulnerability. Instead, attackers abused legitimate external collaboration functionality and social engineering to impersonate IT personnel. This distinction is important because disabling or replacing a legitimate business application does not by itself solve the underlying human-risk problem.

How can employees verify an IT support request?

Employees should avoid relying on the contact information supplied by an unexpected caller. Instead, they should pause the interaction and contact the organization’s IT or help desk through a known, trusted channel. Requests involving remote access, credentials, authentication codes, or unusual software should receive additional verification before any action is taken.

Can phishing simulations prepare employees for Teams scams?

Yes, if the simulations reflect the organization’s actual threat environment. Email-only exercises may not test how employees respond to real-time voice manipulation or collaboration-platform impersonation. Authorized social-engineering simulations can give employees a safe opportunity to practise verification, refusal, and reporting behaviors before encountering similar pressure during a real attack.

Turn Real-World Incidents Into Practical Security Behavior

The Spring Ring campaign demonstrates that human risk increasingly extends into the collaboration platforms employees use every day. Security Awareness Software can help organizations move beyond annual compliance lessons by combining relevant education with controlled simulations and behavioral measurement.

Cyberfrog is currently positioning its AI-powered platform around security awareness training, realistic phishing and social-engineering simulations, and measurable human-risk education. Organizations interested in exploring the platform can join the Cyberfrog waitlist for launch updates and early-access information.

Disclaimer: Cyberfrogsecurity reports on publicly available threat-intelligence sources. Inclusion of an organization in an article does not imply confirmed compromise. All claims are attributed to external sources unless explicitly verified.

Cyberfrog platform

Make awareness training feel real.

Phishing, vishing, smishing, deepfake and 3D simulations with AI content and unified reporting.

Book a demo Explore features