Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Trellix Source Code Breach: Hackers Access Repository
May 2, 2026
Hackers Exploit cPanel Flaw to Breach Government Military
May 2, 2026
Exim Mail Server Vulnerabilities Lead to Crash via DNS Data
May 2, 2026
Home/CyberSecurity News/Detect Microsoft Teams Attackers via External Domain Anomal
CyberSecurity News

Detect Microsoft Teams Attackers via External Domain Anomal

Microsoft is rolling out the External Domains Anomalies Report, a new security feature for Teams, designed to help IT administrators identify and respond to suspicious external communications before...

David kimber
David kimber
January 21, 2026 2 Min Read
0 0

Microsoft is rolling out the External Domains Anomalies Report, a new security feature for Teams, designed to help IT administrators identify and respond to suspicious external communications before they escalate into data breaches.

This proactive monitoring tool, scheduled for global deployment in February 2026, addresses a critical security gap as threat actors increasingly exploit Teams for social engineering campaigns.

The External Domains Anomalies Report uses pattern analysis to establish baselines of normal communication behavior and flags deviations that could indicate security concerns.

The system monitors three key indicators: sudden spikes in messaging volume with external parties, first-time communications with previously unknown domains, and unusual engagement patterns that deviate from established norms.

When anomalies are detected, administrators receive actionable insights through a dedicated report, enabling security teams to investigate risky interactions before they result in data exfiltration incidents.

External Domain Anomalies (Source: Steven Lim)

This feature arrives as threat actors like Black Basta have intensified social engineering attacks through Microsoft Teams.

Black Basta has been observed flooding victim inboxes with thousands of emails, then using Microsoft Teams chats to pose as IT help desk staff and convince users to install remote desktop support tools like AnyDesk, ultimately gaining remote access to their machines.

In late October 2024, the ransomware group added targeted users to Microsoft Teams chats with external users operating from newly created Entra ID tenants designed to appear as legitimate support staff.

The External Domains Anomalies Report will initially roll out to standard multi-tenant environments on the web platform starting February 2026 under Roadmap ID 536572.

Organizations can enable this feature through the Teams admin center by navigating to Notifications & alerts > Rules, selecting External domain anomalies, changing the status to Active, and choosing a Teams channel to receive alert notifications.

This capability builds on earlier Teams security enhancements, including warnings for malicious URLs and blocking risky file types in chats.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitransomwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Hackers Abuse VS Code to Execute Malicious Payloads

Next Post

Weaponized Shipping Docs Deliver Remcos RAT Malware Threat

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
cPanelSniper PoC Exploit for cPanel Vulner Disclosed Vulnerability
May 2, 2026
EtherRAT Targets Enterprise Admins with SEO Poison
May 1, 2026
New Spyware Platform: Rebrand & Resell Android Lets Buyers
May 1, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Sarah simpson
Sarah simpson
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us