Microsoft Teams Phishing Scam Steals Credentials with Fake Login Page
Key Takeaways A newly registered domain, teams-online[.]com, is actively impersonating the Microsoft Teams login page and user interface to conduct phishing attacks. The fake site aims to trick users...
Key Takeaways
- A newly registered domain, teams-online[.]com, is actively impersonating the Microsoft Teams login page and user interface to conduct phishing attacks.
- The fake site aims to trick users into entering their work account credentials, which attackers can then steal.
- At the time of its discovery, the phishing domain reportedly showed zero detections by Microsoft Defender.
- Organizations are advised to proactively block the malicious domain and implement robust web filtering policies.
- The attack highlights the ongoing threat of credential phishing targeting widely used collaboration platforms.
Cybersecurity researchers have uncovered a sophisticated phishing operation leveraging a newly registered domain designed to perfectly mimic the Microsoft Teams login portal and its full user interface. This deceptive website, identified as teams-online[.]com, poses a significant threat to organizations by attempting to harvest employee work account credentials.
Table Of Content
The domain’s name is strategically chosen to exploit the ubiquitous nature of Microsoft Teams, making the fraudulent site appear as a legitimate access point for the popular communication and collaboration platform. An initial analysis indicated that the domain was only four days old at the time of examination, and notably, Microsoft Defender registered zero detections. It is important to note that this detection status reflects a specific point in time and does not guarantee that all Microsoft security services failed to identify the threat, nor does it confirm the current detection status.
The suspicious domain was brought to light by security researcher Steven Lim, known on X as @0x534c, who issued a threat alert on October 8, 2026. Lim emphasized that the website meticulously replicated both the login page and the entire user interface of Microsoft Teams. He strongly advised organizations to implement blocks for this domain within their tenant block lists and web filtering policies, cautioning against sole reliance on endpoint protection solutions.
Understanding the Phishing Mechanism
The current information available describes a phishing website designed to steal credentials, not a confirmed malware distribution site. The report does not specify a particular malware family, show evidence of a downloaded payload, or detail the method used to collect submitted login information. Furthermore, there is no disclosed victim count, identified attacker, or proof that the threat actors have successfully breached Microsoft’s internal systems. These limitations are crucial for accurately assessing the overall scope and impact of this particular threat.
By replicating the familiar Microsoft Teams environment, attackers aim to exploit the trust users place in their daily tools. The cloned login page and interface are designed to appear legitimate, while the underlying domain belongs to malicious actors. In a credential phishing attack, the objective is to persuade users to input their email addresses and passwords into this fake interface, thereby compromising their sensitive login details meant for the authentic service.
The exact delivery mechanism used to direct users to this specific phishing site remains unconfirmed. While email links, chat messages, manipulated search results, or even fake meeting invitations are common vectors for such attacks, the current report does not establish these as confirmed routes. Nevertheless, Microsoft has previously documented instances of phishing campaigns conducted through Teams meetings, chats, and calls. This underscores the necessity for users to exercise the same vigilance with familiar collaboration platforms as they would with unexpected emails requesting account access.
Past incidents involving Teams impersonation and unauthorized access have included fake meeting recordings designed to trick users into downloading remote access tools. Similarly, passkey-themed phishing schemes have utilized lookalike sign-in pages to steal cloud session tokens. While these examples illustrate how similar branding can facilitate various attack methodologies, there is no current evidence directly linking these prior operations to the domain flagged by Lim, nor does it confirm that the newly reported website deploys software or steals session tokens.
Microsoft’s guidance on identity attacks details adversary-in-the-middle phishing, a technique where a malicious site acts as a proxy between a user and a legitimate login service. This advanced method can compromise both passwords and active session tokens. However, Lim’s alert does not confirm whether this specific technique is employed by the teams-online[.]com domain. A mere replication of an interface does not, by itself, indicate an attacker’s ability to bypass multi-factor authentication (MFA) or hijack an authenticated session.
The reported “zero detections” by Microsoft Defender requires careful interpretation. The initial alert does not specify the exact Defender product used, the scan configurations, or the methodology behind this finding. Therefore, this observation cannot be definitively interpreted as a complete security bypass. The immediate concern for defenders is that this newly identified phishing domain may require explicit blocking while further investigations are conducted. Given that Teams chat restrictions and web filtering operate on different attack surfaces, administrators should deploy appropriate controls to effectively prevent access to the reported malicious website.
What You Should Do
- Block the Malicious Domain: Immediately add
teams-online[.]comto your organization’s tenant block lists and web filtering policies to prevent access. - Educate Users: Reinforce training on identifying phishing attempts, emphasizing the importance of verifying URLs, especially for login pages, and being suspicious of unexpected login prompts.
- Implement Phishing-Resistant MFA: Deploy and enforce multi-factor authentication (MFA), particularly phishing-resistant methods like FIDO2 security keys and passkeys, across all accounts.
- Monitor for Suspicious Activity: Regularly review web access logs for any attempts to reach the blocked domain. Investigate unusual sign-in patterns, newly registered authentication methods, or unexpected cloud data access.
- Verify Login Requests: Instruct employees to verify any unexpected login requests through a trusted, out-of-band channel and to always use known, official entry points for Microsoft Teams and other corporate services.
- Review Microsoft Guidance: Consult Microsoft’s guidance on identity attacks and incident response for comprehensive strategies on defending against and responding to credential compromise.
- Incident Response Plan: For confirmed account compromises, follow Microsoft’s recommended response steps: reset credentials, revoke active sessions and refresh tokens, and remove any attacker-added authentication methods or mailbox rules.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



Threat Alert: A newly registered domain, 𝘁𝗲𝗮𝗺𝘀-𝗼𝗻𝗹𝗶𝗻𝗲[.]𝗰𝗼𝗺, created just 𝟰 𝗱𝗮𝘆𝘀 𝗮𝗴𝗼, is actively mimicking the full Microsoft Teams login and user interface.
No Comment! Be the first one.