Growing use of Microsoft Teams in internal impersonation scams
- rrelentless

- Aug 6
- 2 min read

Attackers are increasingly using Microsoft Teams to pose as internal IT support staff and trick employees into giving away access to company systems. In these incidents, criminals send messages or make calls through Teams pretending to be from helpdesk, often asking the user to approve a login request, share a one-time security code or install software so the “issue” can be fixed.
Why these attacks are so convincing
Because Teams is already used for day-to-day communication, these messages can appear genuine and may not raise the same suspicion as an unexpected email. Once access it granted, attackers can move through the organisation, contact other employees and expand the breach.
This approach is part of a wider shift towards real-time scams that rely on trust and urgency rather than technical exploits.
What should businesses do?
Staff should be made aware that legitimate IT teams will not ask for passwords, security codes or approval of unexpected login requests through Teams or similar platforms. Organisations should also review who is allowed to contact employees externally and monitor for unusual behaviour, such as new accounts messaging multiple people and where possible, additional checks should be applied to risky logins so that access is not granted based on a single user action.
Encouraging employees to verify unexpected requests through known contact methods can significantly reduce the likelihood of these attacks succeeding.
Prevention is essential, but so is protection
While employee awareness, strong security controls and effective monitoring can reduce the risk of attacks, no organisation is immune to cyber incidents. Having a clear response plan and access to specialist support can be just as important as preventing an attack in the first place.
A robust and comprehensive cyber insurance policy can make all the difference in protecting businesses effectively against cyber and data threats.
To find out how rrelentless cyber insurance can help clients strengthen their cyber resilience and respond effectively to cyber incidents, brokers can visit our Cyber Insurance policy page.
Businesses interested in learning more about rrelentless insurance should contact their insurance broker for tailored advice.
rrelentless is one of many providers of cyber insurance, and that like most commercial insurance products, getting advice from an independent insurance intermediary is a great way to make setting up your insurance needs straightforward.


