Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Warden Stealer Spreads Via Malvertising and Cracked Software
October 9, 2026
MATCHBOIL Malware Uses Cloudflare to Hide C2 Servers, Delivers Backdoor Payloads
October 9, 2026
Telegram Desktop Critical Flaw Lets Attackers Take Over Accounts
October 9, 2026
Home/Threats/Microsoft Teams Phishing Scam Steals Credentials with Fake Login Page
Threats

Microsoft Teams Phishing Scam Steals Credentials with Fake Login Page

Key Takeaways A newly registered domain, teams-online[.]com, is actively impersonating the Microsoft Teams login page and user interface to conduct phishing attacks. The fake site aims to trick users...

Emy Elsamnoudy
Emy Elsamnoudy
October 8, 2026 5 Min Read
22 0

Key Takeaways

  • A newly registered domain, teams-online[.]com, is actively impersonating the Microsoft Teams login page and user interface to conduct phishing attacks.
  • The fake site aims to trick users into entering their work account credentials, which attackers can then steal.
  • At the time of its discovery, the phishing domain reportedly showed zero detections by Microsoft Defender.
  • Organizations are advised to proactively block the malicious domain and implement robust web filtering policies.
  • The attack highlights the ongoing threat of credential phishing targeting widely used collaboration platforms.

Cybersecurity researchers have uncovered a sophisticated phishing operation leveraging a newly registered domain designed to perfectly mimic the Microsoft Teams login portal and its full user interface. This deceptive website, identified as teams-online[.]com, poses a significant threat to organizations by attempting to harvest employee work account credentials.

Table Of Content

  • Key Takeaways
  • Understanding the Phishing Mechanism
  • What You Should Do

The domain’s name is strategically chosen to exploit the ubiquitous nature of Microsoft Teams, making the fraudulent site appear as a legitimate access point for the popular communication and collaboration platform. An initial analysis indicated that the domain was only four days old at the time of examination, and notably, Microsoft Defender registered zero detections. It is important to note that this detection status reflects a specific point in time and does not guarantee that all Microsoft security services failed to identify the threat, nor does it confirm the current detection status.

The suspicious domain was brought to light by security researcher Steven Lim, known on X as @0x534c, who issued a threat alert on October 8, 2026. Lim emphasized that the website meticulously replicated both the login page and the entire user interface of Microsoft Teams. He strongly advised organizations to implement blocks for this domain within their tenant block lists and web filtering policies, cautioning against sole reliance on endpoint protection solutions.

Understanding the Phishing Mechanism

The current information available describes a phishing website designed to steal credentials, not a confirmed malware distribution site. The report does not specify a particular malware family, show evidence of a downloaded payload, or detail the method used to collect submitted login information. Furthermore, there is no disclosed victim count, identified attacker, or proof that the threat actors have successfully breached Microsoft’s internal systems. These limitations are crucial for accurately assessing the overall scope and impact of this particular threat.

By replicating the familiar Microsoft Teams environment, attackers aim to exploit the trust users place in their daily tools. The cloned login page and interface are designed to appear legitimate, while the underlying domain belongs to malicious actors. In a credential phishing attack, the objective is to persuade users to input their email addresses and passwords into this fake interface, thereby compromising their sensitive login details meant for the authentic service.

The exact delivery mechanism used to direct users to this specific phishing site remains unconfirmed. While email links, chat messages, manipulated search results, or even fake meeting invitations are common vectors for such attacks, the current report does not establish these as confirmed routes. Nevertheless, Microsoft has previously documented instances of phishing campaigns conducted through Teams meetings, chats, and calls. This underscores the necessity for users to exercise the same vigilance with familiar collaboration platforms as they would with unexpected emails requesting account access.

🚨 Threat Alert: A newly registered domain, 𝘁𝗲𝗮𝗺𝘀-𝗼𝗻𝗹𝗶𝗻𝗲[.]𝗰𝗼𝗺, created just 𝟰 𝗱𝗮𝘆𝘀 𝗮𝗴𝗼, is actively mimicking the full Microsoft Teams login and user interface.
​
At the time of analysis, 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗗𝗲𝗳𝗲𝗻𝗱𝗲𝗿 𝗿𝗲𝗽𝗼𝗿𝘁𝗲𝗱 𝘇𝗲𝗿𝗼… pic.twitter.com/otM577jzbV

— Steven Lim (@0x534c) October 8, 2026

Past incidents involving Teams impersonation and unauthorized access have included fake meeting recordings designed to trick users into downloading remote access tools. Similarly, passkey-themed phishing schemes have utilized lookalike sign-in pages to steal cloud session tokens. While these examples illustrate how similar branding can facilitate various attack methodologies, there is no current evidence directly linking these prior operations to the domain flagged by Lim, nor does it confirm that the newly reported website deploys software or steals session tokens.

Microsoft’s guidance on identity attacks details adversary-in-the-middle phishing, a technique where a malicious site acts as a proxy between a user and a legitimate login service. This advanced method can compromise both passwords and active session tokens. However, Lim’s alert does not confirm whether this specific technique is employed by the teams-online[.]com domain. A mere replication of an interface does not, by itself, indicate an attacker’s ability to bypass multi-factor authentication (MFA) or hijack an authenticated session.

The reported “zero detections” by Microsoft Defender requires careful interpretation. The initial alert does not specify the exact Defender product used, the scan configurations, or the methodology behind this finding. Therefore, this observation cannot be definitively interpreted as a complete security bypass. The immediate concern for defenders is that this newly identified phishing domain may require explicit blocking while further investigations are conducted. Given that Teams chat restrictions and web filtering operate on different attack surfaces, administrators should deploy appropriate controls to effectively prevent access to the reported malicious website.

What You Should Do

  • Block the Malicious Domain: Immediately add teams-online[.]com to your organization’s tenant block lists and web filtering policies to prevent access.
  • Educate Users: Reinforce training on identifying phishing attempts, emphasizing the importance of verifying URLs, especially for login pages, and being suspicious of unexpected login prompts.
  • Implement Phishing-Resistant MFA: Deploy and enforce multi-factor authentication (MFA), particularly phishing-resistant methods like FIDO2 security keys and passkeys, across all accounts.
  • Monitor for Suspicious Activity: Regularly review web access logs for any attempts to reach the blocked domain. Investigate unusual sign-in patterns, newly registered authentication methods, or unexpected cloud data access.
  • Verify Login Requests: Instruct employees to verify any unexpected login requests through a trusted, out-of-band channel and to always use known, official entry points for Microsoft Teams and other corporate services.
  • Review Microsoft Guidance: Consult Microsoft’s guidance on identity attacks and incident response for comprehensive strategies on defending against and responding to credential compromise.
  • Incident Response Plan: For confirmed account compromises, follow Microsoft’s recommended response steps: reset credentials, revoke active sessions and refresh tokens, and remove any attacker-added authentication methods or mailbox rules.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityHackerMalwarephishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical PoeLLM Malware Targets AI Infrastructure Via GitHub Poem

Next Post

Gitea Patches Critical SSH Auth Bypass, SSRF, and 25 Other Flaws

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Top 10 Bug Bounty Platforms of 2026 Ranked and Scored
October 9, 2026
Anthropic’s New OSS Scanner Identifies Open-Source Vulnerabilities
October 9, 2026
Top 10 IaC Security Tools for 2026
October 9, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us