- Microsoft warns of Teams‑based campaign where attackers impersonate IT staff
- Victims tricked into granting remote access, leading to malware, lateral movement, and ransomware
- Defenses: verify support contacts, train staff, harden Teams, and use Defender Safe Links/ZAP
Microsoft is warning about an ongoing hacking campaign that starts with a Teams message and ends with a ransomware infection and data theft.