Skip to content

Hackers Exploiting Microsoft Teams Notifications to Deliver CallBack Phishing Attack

Cybersecuritynews • December 5, 2025

Cybersecurity researchers have identified a sophisticated phishing campaign that exploits Microsoft Teams notifications to deceive users into calling fraudulent support numbers.

The attack demonstrates how legitimate communication platforms can be weaponized to bypass security defenses and email filters.

According to SpiderLabs, threat actors are abusing Microsoft Teams to add users to groups with deceptive team names containing fake financial content.

These team names impersonate urgent payment issues, including counterfeit invoices, auto-renewal notices, or unauthorized PayPal charges.

Once added to these groups, victims receive notification emails that appear to come from legitimate Microsoft Teams infrastructure, sent to no- @teams.mail.microsoft.

The notifications contain a critical detail prompting users to a fake support number if they did not authorize the charge.

Because the emails originate from an official Microsoft domain, they often bypass email filter detection and appear trustworthy to recipients.

Users, believing they are contacting legitimate support, call the provided fraudulent numbers and provide sensitive information to cybercriminals.

This campaign represents a mature evolution in callback phishing techniques. Rather than attempting to compromise victims through email links or attachments, attackers rely on voice-based social engineering .

Once victims call the fake support numbers, trained operators can manipulate them into revealing payment card details, account credentials, or other personally identifiable information.

Using Microsoft Teams as the delivery mechanism is particularly effective because many organizations trust internal collaboration platforms.

Grant them liberal email delivery permissions; this trust becomes a liability when attackers exploit it. According to SpiderLabs, researchers have identified the following fraudulent phone numbers associated with this campaign.

Organizations should educate employees this specific attack pattern. Users should verify urgent payment requests through official company channels rather than responding to Team notifications.

Email security teams should implement additional scrutiny on Teams notifications or adjust delivery policies to require manual approval for Team invitations from unknown groups.

Microsoft Teams users should regularly review their group memberships and be suspicious of groups with financial-themed names, particularly those that use urgency language.

Implementing multi-factor authentication and maintaining robust email gateway security remain essential defenses against such campaigns.

This attack underscores how cyber criminals continuously adapt their techniques to exploit trusted platforms and human psychology rather than technical vulnerabilities.

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Cybercriminals are actively spreading CoinMiner malware through USB drives, targeting workstations across South Korea to…

A sophisticated cyber threat has emerged targeting Windows systems across multiple countries in the Middle…

Cloudflare's global network suffered a brief but widespread disruption this morning, lasting approximately 25 minutes,…

A persistent privilege escalation technique in AWS that allows attackers with limited permissions to execute…

A new Remote Access Trojan known as CastleRAT has emerged as a growing threat to…

Russian threat actors are running a new wave of phishing campaigns that spoof major European…

Extracted Entities

Attack Types (1)

Countries (1)

Malware (2)

Tools (1)