Fake IT Help Desk Messages Are Hitting Microsoft Teams

Attackers are impersonating IT support staff inside Microsoft Teams to trick employees into installing backdoor software. Here is what to watch for and how to stay safe.

Your “IT department” might not be who you think

If your company uses Microsoft Teams for internal communication, there is a new threat you should know about. Attackers are posing as IT helpdesk staff inside Teams, sending messages that look completely routine — telling employees their device is running slow, needs cleaning, or has a security issue that must be fixed right away.

The goal is simple: get you to download and run a piece of software they recommend. That software is not a cleaner. It is a backdoor framework — meaning it opens a hidden channel into your computer that lets the attacker access files, steal credentials, or dig deeper into a company network.

Why Teams makes this easier for attackers

Email scams have been around long enough that most people have learned to be cautious. A suspicious email from “IT support” raises flags. But a Teams message feels different — it arrives inside a tool your employer already trusts, alongside messages from real colleagues. That familiarity lowers your guard.

Attackers exploit this by creating accounts that look like internal IT staff, sometimes using similar display names or profile pictures. In companies where Teams is open to external contacts, the message does not even need to come from inside your organisation.

What to look out for

There are a few signs that a helpdesk message might not be genuine. Real IT teams rarely reach out unprompted asking you to install something immediately. Urgency is a classic manipulation tactic — phrases like “your device is at risk” or “act now to avoid losing access” are designed to short-circuit your judgement.

Before clicking any link or downloading anything sent over Teams, call your IT department through a separate channel — phone or a verified email address — and confirm the request is real. If they did not send it, report it.

Also check the sender’s account carefully. An address ending in an external domain, or a display name that is slightly different from the real IT team’s name, is a strong warning sign.

For anyone running a small business or website

If you manage your own server or run a small team, you may not have a formal IT department at all — which means attackers sometimes impersonate outside support services or hosting providers instead. The same rule applies: never install software because a chat message told you to, no matter how official it looks.

What this means going forward

As more workplace communication moves into collaboration platforms like Teams, Slack, and similar tools, those platforms will attract more social engineering attacks — scams that manipulate people rather than exploit software bugs. Training your team to treat unexpected software requests with scepticism, regardless of where they arrive, is one of the most practical defences available right now.