Voice phishing via a Teams support call gave attackers access
Microsoft's incident response team has detailed a real-world intrusion in which a threat actor used voice phishing through a Microsoft Teams support call. The actor persuaded an employee to grant remote access via the Quick Assist tool. The user was then directed to a malicious website, credentials were harvested through a spoofed form, and several malicious files were deployed that enabled continued remote access, command execution and credential theft within the environment.
What this means for your organisation
The attack required no vulnerability. It exploited an ordinary work situation where an employee receives help from someone who appears to be IT, and where granting remote access is a normal, helpful act. Norwegian organisations that accept external calls in Teams effectively have a door where a stranger can speak directly to an employee with no prior contact. The result is an identity compromise that must be handled broadly, not just on one machine.
Berigo recommends
- Assess whether external parties should be able to call or message employees directly in Teams, and restrict it where unnecessary.
- State and communicate that IT never requests remote access through an unannounced call, and how employees can verify a request.
- Limit remote control tooling to approved solutions and block those not in use.
- Treat such incidents as credential theft: revoke sessions, rotate passwords and review access for affected users.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch