Home › Knowledgebase › KB-492

How to recognise and safely handle a suspicious email or impersonation attempt on Microsoft Teams or Teams chat

Summary

This guide helps you troubleshoot and resolve: How to recognise and safely handle a suspicious email or impersonation attempt on Microsoft Teams or Teams chat. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Cyber criminals increasingly use Microsoft Teams and Teams chat to impersonate colleagues, IT staff, or external organisations. These messages often arrive as a direct chat from someone you do not know, a sudden "external tenant" warning, or a request to click a link, sign in, or share a code. Because Teams is trusted as an internal communication tool, these impersonation attempts can be particularly convincing. This guide explains how to spot a suspicious Teams message, what to do before you click anything, and how to report the incident to 220 Internet Services so we can investigate and protect your environment.

Common signs of a suspicious Teams message

If a message asks you to read out an MFA code, approve a sign-in prompt, install software, or hand over remote access, treat it as a scam. No legitimate technician from 220 Internet Services will ever ask for these.

Quick Fix Steps

  1. Do not click any links, open any attachments, or reply to the message.
  2. Do not approve any MFA prompts or share verification codes.
  3. Use the Teams Report option to flag the message to Microsoft and your organisation.
  4. Take a screenshot of the chat, including the sender's email address and any external tenant warning.
  5. Open a support ticket with 220 Internet Services so we can review and contain any risk.

Detailed Instructions

Step 1: Stop and assess the message

Before you do anything, read the message carefully and look for the red flags listed above. Pay particular attention to:

If anything feels rushed, unusual, or too good to be true, assume it is suspicious and proceed without clicking.

Step 2: Verify the sender through a separate channel

If the message appears to come from a colleague, manager, or known organisation, confirm it through a different channel before acting. For example:

Never use the contact details provided inside the suspicious message itself.

Step 3: Report the message in Microsoft Teams

Microsoft Teams includes a built-in reporting option that notifies your security team and Microsoft.

  1. Open the suspicious chat in Teams.
  2. Hover over the message or click the More actions (...) menu in the top-right corner of the chat.
  3. Select Report this message (in some tenants this appears as Security then Report).
  4. Choose the most appropriate category, such as Phishing or Impersonation.
  5. Click Report to submit. The message will be sent to your organisation's security team for review.
If your organisation has the Microsoft Defender for Office 365 Teams protection feature enabled, reported messages are also analysed by Microsoft automatically.

Step 4: Capture evidence before deleting

Before you block or delete the sender, take a screenshot of:

This evidence is essential if 220 Internet Services needs to investigate, block the sender at the tenant level, or report the incident to authorities.

Step 5: Block the sender and leave the chat

  1. In the chat, click the sender's name or profile picture at the top of the window.
  2. Select Block, then confirm by clicking Block again.
  3. Optionally, click Leave to remove yourself from the chat if it is a group or external conversation.

Blocking prevents further direct messages from that account, although the user may still appear in shared channels or meetings.

Step 6: Secure your account

If you have already clicked a link, entered credentials, or approved an MFA prompt, act immediately.

  1. Change your Microsoft 365 password from a device you trust. See our guide: Password reset (Windows login).
  2. Review and remove any unfamiliar sign-in sessions by going to account.microsoft.com then Security then Sign-in activity.
  3. Remove any suspicious App registrations or Multi-factor authentication methods from your account.
  4. Sign out of all sessions by selecting Sign out everywhere.
  5. Run a full antivirus scan on the device you used.

Step 7: Report the incident to 220 Internet Services

Once you have secured your account and captured evidence, lodge a ticket so our security team can investigate and take protective action across your tenant.

  1. Go to the 220 support portal at app.220.com.au.
  2. Click Open a Ticket and choose the Security category.
  3. Include the screenshots, the sender's email address, the time of the message, and a summary of any actions you took (for example, "I clicked the link but did not enter my password").
  4. Submit the ticket and watch for a response from our team.

Troubleshooting

I cannot find the "Report this message" option

The option may be disabled by your organisation's Teams policy, or it may appear under a slightly different menu. Try the following:

The message came from inside my organisation but still looks suspicious

Internal accounts can also be compromised. Treat the message with the same caution and verify the request through a separate channel such as a phone call. If you cannot confirm the request, report it to our security team.

I approved an MFA prompt by mistake

An approved MFA prompt means the attacker may now have access to your account. Act immediately:

  1. Change your Microsoft 365 password straight away.
  2. Remove the compromised MFA method from your account at account.microsoft.com under Security then Advanced options.
  3. Sign out of all sessions using Sign out everywhere.
  4. Review recent sign-in activity for any unfamiliar locations or devices.
  5. Notify 220 Internet Services through the support portal so we can audit your tenant for further suspicious activity.

I clicked the link but did not enter any details

You may still be at risk if the link triggered a silent download or credential capture. Run a full antivirus scan, clear your browser cache and cookies, and report the incident to 220 Internet Services so we can monitor your account for unusual behaviour.

The sender is already blocked but the messages keep coming

Attackers often create new accounts. Continue to report each new message using the Teams Report option and notify 220 Internet Services. We can apply tenant-level blocks and conditional access policies to reduce further attempts.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket