A message from “IT Support” lands in an employee’s Teams chat asking them to approve a security prompt. It looks routine. It isn’t. Here’s why attackers have moved into the one place your team never learned to be suspicious of — and what to do about it
It’s 9:40 on a Tuesday. A message lands in your office manager’s Microsoft Teams chat.
“Hi — IT here. We’re pushing a security update this morning. Can you approve the prompt on your phone?”
She approves it. Of course she does. It arrived in the same window where real IT questions show up every day, it used the right words, and it asked for something that happens all the time.
It wasn’t IT. And in the time it took to tap “approve,” an attacker was inside her account — and inside everything that account could reach.
This is one of the fastest-growing attack patterns of 2026, and most businesses have no idea the door is even open. The reassuring part is that closing it is straightforward once you know where to look.
The Door Everyone Stopped Watching
For two decades, the dangerous message was the email, so that’s where the defenses went. Spam filters, link scanning, external-sender banners, and years of training staff to slow down and look twice before clicking. That work paid off. For most businesses, the email inbox became a well-guarded front door.
But the way we work quietly has moved somewhere else. Microsoft Teams — along with tools like Slack — became where the real-time work happens: quick questions, file drops, “can you approve this?” And because chat feels internal, it feels safe.
That assumption is exactly what attackers are now exploiting. Your team has spent years learning to be suspicious of email, but nobody ever taught them to distrust a Teams message. A chat doesn’t feel like a threat; it feels like a coworker. Worse, those conversations happen outside the reach of the email security filters most businesses rely on — so the safeguards you’ve paid for never even get a chance to catch the attack.
According to security firm KnowBe4, Microsoft Teams is fast becoming a favorite target for this kind of social engineering. Microsoft itself has warned over the past year about attackers posing as internal support staff inside Teams, including attackers reaching in from outside an organization entirely.
What a Microsoft Teams Impersonation Attack Looks Like
The most common version is a fake IT helpdesk. An attacker messages an employee in Teams, posing as internal tech support or a familiar vendor:
- “We’re pushing a security update — can you approve the prompt on your phone?”
- “Quick verification needed — what’s the code you just received?”
- “We’re seeing a problem with your account. Can you confirm your password so we can unlock it?”
It works because it’s plausible. It arrives in the same window where real IT requests appear, it uses the right language, and it asks for something that feels routine. One approved multi-factor prompt or one shared verification code, and the attacker is into that account — and from there, into email, files, and whatever else that person can access.
The goal is almost always the same: capture a login session or trick the employee into approving access, then move deeper into the business.
The Teams Setting Most Businesses Don’t Know Is Open
Here’s the part worth pausing on. Most organizations have never changed the default setting that allows outside users to message their staff in Teams. In KnowBe4’s research, 74% of surveyed organizations had external Teams access enabled with no domain restrictions in place — meaning someone outside the company can start a chat with an employee, and nothing stops them.
(It’s worth knowing that the figure comes from a security vendor’s own survey rather than independent research, so treat the exact percentage loosely. But the direction is well supported by Microsoft’s own warnings and by independent reporting.)
This setting is rarely revisited after a tenant is first set up. The default was chosen years ago by someone who wasn’t thinking about impersonation, and it has quietly stayed that way ever since. For most businesses, “external access” is simply a door nobody remembers is unlocked.
The good news: this is a configuration, not a rebuild. External Teams access can be restricted, limited to the specific partner domains you actually work with, or switched off entirely — depending on how your business genuinely operates.
It’s Not Only Teams: The “Paste This to Continue” Trick
The bigger pattern here is attackers deliberately going around your email defenses. Teams is one route. Another that surged in 2026 is worth knowing by name: ClickFix.
According to threat researchers at ReliaQuest, ClickFix became one of the most common ways attackers deliver malware this year. The trick is disarmingly simple: a web page — often a fake “verify you’re human” check — instructs the visitor to copy a bit of text and paste it into their computer to “continue.” When they do, they’ve quietly run the attacker’s command themselves. No attachment to scan, no obvious link to block.
The common thread with the Teams scam is the same: the attacker never breaks through your security tools, because they convince a person to open the door from the inside. That’s why awareness matters as much as any filter.
How to Protect Your Business
You don’t need to be technical to close most of this gap. A few practical steps make a real difference:
Lock down external Teams access. Review who can message your staff from outside the organization, and restrict it to the partner domains you actually work with. For many businesses, this single change removes the most common entry point.
Teach one simple rule: real IT never asks for your password or approval code. Legitimate support will not message someone in chat asking them to hand over a password or approve an unexpected multi-factor prompt. If a message does, that’s the signal to stop and verify.
Build a verify-first habit. Encourage staff to confirm any unexpected “IT” or “vendor” request through a known channel — a quick call or a message to a person they know — before acting. A ten-second check defeats the entire attack.
Extend security awareness beyond email. Most training still assumes the threat arrives in the inbox. Make sure yours covers chat platforms and browser-based tricks, so your team recognizes a suspicious message wherever it lands.
Strengthen multi-factor authentication. Where possible, use phishing-resistant methods and make sure staff know never to approve a prompt they didn’t personally trigger.
The Bottom Line
“Secure email” no longer means “secure communication.” The work you’ve done to protect the inbox still matters — but the conversation has moved, and your protection needs to move with it. The businesses staying ahead of this are simply the ones that stopped treating internal chat as automatically trustworthy and gave it the same basic guardrails they already give email.
At Circle Twice, reviewing settings like external Teams access, hardening Microsoft 365, and training teams to spot these newer attacks is part of the managed IT and security work we do every day. If you’re not sure who can message your team inside Teams right now — or whether your people would recognize a fake helpdesk message before approving one — that’s exactly the kind of gap we can close quickly.
Contact us, and we’ll review your Teams and Microsoft 365 setup and make sure the door isn’t sitting open.