A wide-scale phishing operation is weaponizing Microsoft Teams to circumvent traditional email security defenses, according to new research from Check Point.
The campaign has already delivered more than 12,000 malicious emails targeting over 6,000 users across multiple industries. Unlike conventional phishing attempts that rely on malicious links or suspicious attachments, these attackers are exploiting legitimate Microsoft Teams features, specifically the platform's guest invitation system, to impersonate billing alerts and deceive victims into contacting fraudulent support lines.
The sophistication of this operation is significant. By abusing built-in collaboration tools rather than external threats, attackers are effectively turning trusted business infrastructure against itself.
The attack methodology signals a broader shift in how cybercriminals approach corporate environments in an era where collaboration platforms have become essential business tools.
Exploiting Email Trust Through Teams
The attack unfolds through a carefully orchestrated sequence that leverages Microsoft Teams' native functionality.
Attackers begin by creating a new team within the platform, assigning it a finance-themed name crafted to trigger urgency and concern.
Check Point researchers documented one example that read: "Subscription Auto-Pay Notice (Invoice ID: 2025_614632PPOT_SAG Amount at least 629.98 USD). If you did not authorize or complete this monthly payment, please contact our support team urgently."
The sophistication lies in the obfuscation techniques embedded within these team names. Attackers deploy character substitutions (replacing "o" with "0" and "e" with "3") alongside mixed Unicode characters and visually similar glyphs designed to evade automated detection systems. These subtle manipulations allow malicious content to slip past security filters that might otherwise flag suspicious patterns yet still appear normal to human users.
Once the team is established, attackers exploit the "Invite a Guest" feature, which triggers official-looking Microsoft emails sent directly to targets' inboxes. This mechanism allows the attack to reach users without traditional phishing techniques like malware-loaded attachments or links. The invitation emails originate from legitimate Microsoft servers, carrying authentic Microsoft branding and headers that would pass most email authentication checks.
The final stage directs victims to call a fraudulent support number to resolve the fabricated billing issue. During these calls, attackers attempt to extract login credentials, multi-factor authentication codes, or other sensitive information that can be used to access corporate email accounts and internal systems.
The combination of official Microsoft messaging, urgent finance-related language, and the absence of links creates a heightened level of trust, making standard firewall protections less effective and leaving user vigilance as the main line of defense.
The Growing Threat Landscape: Teams as an Attack Vector
Microsoft Teams and similar collaboration platforms have increasingly become preferred targets for cybercriminals seeking to exploit trusted communication channels.




