When “Hi, This Is IT” Comes Through Microsoft Teams
This report details a tactic employed by threat actors, primarily Cloaked Ursa (APT29), to compromise organizations by impersonating IT departments within Microsoft Teams. The attackers leverage trusted communication channels to trick employees into approving MFA prompts, gaining access to accounts. This trend is increasing, with collaboration tools now representing a significant portion of phishing alerts, highlighting the need for enhanced security measures beyond traditional email defenses.
The incident involves threat actors, such as Cloaked Ursa and UNC6692, utilizing Microsoft Teams to mimic legitimate IT support. These actors initiate conversations with employees, often presenting themselves as the IT department and requesting MFA approvals to verify identities. This approach capitalizes on the trust users place in internal communication tools, bypassing traditional email security measures. Recent data shows a surge in phishing alerts originating from collaboration tools, specifically Microsoft Teams, accounting for 42% of all alerts in the first four months of 2026, compared to 30% in the preceding period. This shift underscores the vulnerability of organizations relying heavily on these platforms for internal communication.
To further enhance their deception, threat actors employ tactics like typosquatted domains resembling trusted vendors and leveraging Microsoft 365 tenants mimicking IT support functions. Teams federation, enabled by default in many organizations, allows external communication, creating an opportunity for attackers to exploit existing trust relationships. While Microsoft Teams offers an impersonation protection feature, the ultimate responsibility lies with the user to recognize and scrutinize suspicious messages. The report emphasizes a shift in focus from solely educating users to implementing stricter configuration and identity-centric controls to prevent these malicious chat requests from reaching employees in the first place.
