TfL cyber attack forced 28000 staff to reset passwords
Discover how the TfL cyber attack exposed human vulnerabilities and why cyber security training for businesses is essential for reducing risk.
Microsoft Teams has become part of everyday working life. Employees use it to discuss projects, share documents, speak to colleagues and exchange information that may never appear in a formal email.
That familiarity can create a dangerous assumption: if a message appears in Teams, it must be safe.
But is Microsoft Teams secure for confidential information?
Microsoft Teams includes multiple security controls, including external-user labels, suspicious-message warnings, malicious-link protection and administrative security settings. However, attackers can still target the people using the platform. They exploit trust, urgency, authority and normal workplace routines to persuade employees to reveal information or grant access.
The platform itself may be legitimate while the person using it is not.
Here are the main phishing and scamming methods businesses and employees need to recognise.
Microsoft Teams allows organisations to communicate with people outside their own business. This is useful when working with clients, suppliers, consultants and other partners, but it also creates an opportunity for attackers.
An external account may contact an employee while pretending to represent:
The company’s IT department
Microsoft support
A senior manager
A supplier
A customer
A recruitment agency
A finance or payroll team
Teams may label the person as external and display an accept-or-block prompt. It may also warn users when a message shows signs of impersonation or phishing. However, these protections still depend on the employee noticing and respecting the warning.
An attacker does not necessarily need to break into the organisation’s Teams environment. They may simply create or compromise an account in another Microsoft 365 tenant and contact employees across organisational boundaries.
An attacker sends a direct message containing a believable reason for making contact. The message could refer to a delivery, complaint, payment, shared document or technical issue.
The objective may be to convince the employee to:
Open a malicious link
Download a file
provide login information
Reveal internal details
Continue the conversation on another platform
Accept a voice or video call
The message feels more trustworthy because it appears inside a familiar workplace application rather than in an unexpected email.
Some attacks come from genuine accounts that have already been compromised.
A message from a real colleague, supplier or business partner can be much more convincing than a newly created external account. The attacker may study previous conversations before sending a message that matches the relationship, writing style or current project.
This can turn an ordinary Teams conversation into a targeted spear-phishing attack.
Teams phishing is not limited to written messages. Attackers can use voice calls, video meetings and screen-sharing features to make their story more believable.
Microsoft has documented attacks in which criminals impersonated support staff through Teams and used conversation, screen sharing and legitimate remote-support tools as part of the compromise.
A common method begins with the victim receiving a large number of spam emails. Shortly afterwards, someone calls through Teams claiming to be from IT support.
The caller may say:
“We have detected a problem with your mailbox.”
“We are calling to stop the spam.”
“Your computer is causing a security alert.”
“We need to run a quick health check.”
“Your Microsoft account needs to be repaired.”
Because the employee has just experienced a genuine problem, the explanation appears believable.
The fake technician then guides the employee through steps that give the attacker access.
The attacker may ask the employee to open Microsoft Quick Assist or another legitimate remote-management tool.
The employee is given a session code and told that this will allow the IT team to inspect the device. In reality, it can give the attacker remote access to the computer.
Security researchers and Microsoft have observed campaigns in which fake support staff used remote-access tools to install malware, steal information and move further through the organisation’s network.
The danger is that the software itself may be genuine. The scam relies on deceiving the employee about who is requesting access.
An attacker may initially ask only to view the employee’s screen. They may later request control of the device, claiming it is necessary to solve the problem.
Once control is granted, they may:
Download malicious software
Change security settings
Access files and browser sessions
Collect saved credentials
Open internal systems
Steal confidential information
Employees should never approve a remote-control request simply because the person claims to work in IT.
Attackers can also send unexpected meeting invitations that appear to involve:
An urgent client complaint
A job interview
A confidential management meeting
A supplier review
A legal problem
A security investigation
The invitation may direct the employee to a fake Teams page, ask them to download supposed meeting software or present a fraudulent Microsoft login screen.
Microsoft has reported campaigns using workplace meeting themes, PDF attachments and malicious downloads disguised as legitimate applications.
When asking is Microsoft Teams secure for confidential information, businesses must consider what employees click, download and share through the platform.
Teams can scan links and display warnings when a URL is considered potentially harmful. Microsoft Defender for Office 365 can also provide Safe Links protection for Teams conversations, group chats and channels. These controls reduce risk, but no technical filter should be treated as perfect.
At Optimise Cyber, we provide businesses with cyber security training for businesses to use workplace software safely, recognise phishing attempts and avoid the scams that target everyday office systems.
A message may claim that the employee needs to sign in to:
View a shared document
Join a private meeting
Restore access to an account
Complete a security check
Open a voicemail
Review an invoice
Accept a new company policy
The link can lead to a page designed to look like Microsoft 365. The victim enters their username, password and possibly an authentication code.
The attacker may then use the stolen information to access email, Teams, files and other connected services.
In a device-code attack, the victim may be directed to a genuine Microsoft login page and asked to enter a code supplied by the attacker.
Because the page is real, the process may not look like ordinary phishing. However, entering a code that the employee did not personally request may authorise access for the attacker.
Staff should never enter a Microsoft device code unless they initiated the sign-in process themselves.
Attackers can place links in:
Private messages
Group chats
Channel posts
Meeting conversations
Replies to existing discussions
Messages sent from compromised accounts
A link might lead to credential theft, malware, a fraudulent payment page or a false document-sharing service.
Employees should check where a link actually leads rather than trusting its displayed text.
A QR code may be shared as an image, document or meeting instruction. The message may say that scanning it is required to authenticate, access a file or verify an account.
Scanning the code moves the activity from the protected work device to a personal phone, where employees may be less likely to notice the destination or receive a company security warning.
A Teams message may contain or link to:
A false invoice
A PDF with a malicious link
A fake security tool
A fraudulent meeting application
A compressed file
A script or executable file
A document requesting macros or additional permissions
Attackers may disguise malware as familiar workplace software to make the download appear safe. Microsoft has reported campaigns in which signed malicious software impersonated legitimate workplace applications and installed remote-management tools.
Through our funded cybersecurity training, your staff will learn how to recognise suspicious activity in the workplace, respond appropriately and avoid phishing attempts and scams.
Role-based scams are designed around the authority, responsibilities or access associated with a particular job.
Instead of sending the same message to everyone, the attacker creates a scenario that makes sense for the victim’s position.
An attacker pretends to be a chief executive, director or senior manager and asks an employee to:
Make an urgent payment
Purchase gift cards
Send a confidential document
Share customer information
Keep the request secret
Change bank details
Join an unexpected private call
The message may refer to a real project, employee or business event gathered from LinkedIn, the company website or a previous account compromise.
Finance employees may receive messages requesting:
A change to supplier payment details
Approval of an invoice
A copy of payroll information
Confirmation of a bank transfer
An urgent payment outside normal procedures
The attacker may impersonate a supplier, manager or colleague. They may also move between email and Teams to make the conversation appear more convincing.
Someone posing as an employee or manager may request:
A change to salary payment details
Copies of employment records
Personal employee information
Access to benefits documents
Updates to contact information
These requests can expose both company data and employees’ personal information.
IT support is particularly effective for role-based scamming because employees expect technical staff to ask questions, request access or provide instructions.
The attacker may ask the victim to:
Reset a password
Approve an authentication request
Share a verification code
Disable a security control
Install software
Open a command prompt
Run a PowerShell command
Start a remote-support session
Microsoft has observed targeted Teams campaigns involving credential-theft messages and support impersonation.
Attackers may pose as an external organisation that the employee recognises.
They can use copied logos, realistic names and information gathered from public sources. A compromised supplier account can make the approach even harder to identify.
The request may involve a contract, quotation, file, invoice, complaint or payment change.
Security researchers have also identified and disclosed Teams vulnerabilities involving executive impersonation, manipulated notifications, altered messages and forged identities during audio or video calls. This demonstrates why a familiar display name, notification or profile image should not be treated as proof of identity.
The answer is not simply yes or no.
Microsoft Teams can support secure business communication when it is configured properly, protected with suitable security controls and used by employees who understand social engineering.
However, confidential information can still be exposed when someone is persuaded to trust the wrong person, approve the wrong request or share information without verification.
Microsoft recommends reducing the Teams attack surface through appropriate external-access policies, threat protection, reporting processes and security monitoring.
Employees should verify unusual requests through a separate, trusted method.
For example:
Call the colleague using a number already held by the company
Contact IT through the official support process
Check payment changes with the supplier’s known contact
Ask a manager to confirm an unusual instruction
Start a new conversation using a verified directory entry
Do not rely on contact details supplied in the suspicious message.
An external label does not mean that a message is malicious, but it does mean the sender is outside the organisation.
Employees should pause before accepting an unexpected external conversation, particularly when the sender claims to be an internal employee or IT technician.
Passwords, multifactor authentication codes, recovery codes and device codes should not be shared through Teams.
Employees should also reject unexpected authentication prompts rather than approving them to make the notification disappear.
Businesses need a clear policy explaining:
Which tools IT support is allowed to use
How employees can verify support staff
When remote access may be requested
What the approval process looks like
How suspicious requests should be reported
A real support process should be recognisable and verifiable.
Organisations should review who can contact employees from external Teams environments. External access may be necessary, but it should be configured according to the company’s actual business requirements and risk profile.
Employees should know exactly how to report:
Suspicious chats
Unexpected calls
False meeting invitations
Malicious links
Unusual file-sharing requests
Impersonation attempts
Accidental clicks or information disclosure
Microsoft Teams and Defender for Office 365 include capabilities for reporting and investigating suspicious Teams messages, but employees must know when and how to use them.
Traditional phishing training often concentrates heavily on email. That leaves employees less prepared for attacks arriving through chat, calls, screen sharing and collaboration tools.
At Optimise Cyber Solutions, we train staff to stay away from these dangers by helping them recognise realistic workplace scenarios, including phishing, scamming, role-based scams, impersonation and unsafe information-sharing requests.
The aim is not to make employees afraid of Microsoft Teams. It is to help them pause when a familiar platform is being used to create false trust.
So, is Microsoft Teams secure for confidential information?
It can be, but the security of a conversation depends on more than the platform. It also depends on who has access, how the organisation configures Teams, what information employees share and whether unusual requests are independently verified.
Attackers are using Teams because it feels familiar. A message from “IT Support”, a call from a manager or a link shared by a colleague can appear safer than an unexpected email.
That is exactly why employees must remain careful. The message may be inside Microsoft Teams. The person behind it may not be who they claim to be.
Discover how the TfL cyber attack exposed human vulnerabilities and why cyber security training for businesses is essential for reducing risk.
If you are unsure how to use AI safely, this guide will help you evaluate any AI service. It outlines what to check when using AI tools and what to do if you are at risk or experience a cyberattack.
Artificial intelligence is reshaping cybersecurity for UK businesses, creating new risks and making cyber resilience more important than ever. This blog from Optimise Cyber Solutions explains why staff awareness, secure processes and practical training are essential in a changing threat landscape.