How to recognise and safely handle a suspicious email or impersonation attempt on Microsoft Teams or Teams chat
Summary
This guide helps you troubleshoot and resolve: How to recognise and safely handle a suspicious email or impersonation attempt on Microsoft Teams or Teams chat. Follow the steps below to fix the issue.
Common Causes
Cyber criminals increasingly use Microsoft Teams and Teams chat to impersonate colleagues, IT staff, or external organisations. These messages often arrive as a direct chat from someone you do not know, a sudden "external tenant" warning, or a request to click a link, sign in, or share a code. Because Teams is trusted as an internal communication tool, these impersonation attempts can be particularly convincing. This guide explains how to spot a suspicious Teams message, what to do before you click anything, and how to report the incident to 220 Internet Services so we can investigate and protect your environment.
Common signs of a suspicious Teams message
- An unexpected direct message from someone outside your organisation, often with an external tenant warning banner.
- Impersonation of a manager, the ATO, Australia Post, Microsoft, or an IT support technician.
- Urgency or pressure, such as "act in the next 10 minutes" or "your account will be locked".
- Requests for passwords, multi-factor authentication (MFA) codes, payment details, or remote access.
- Links that look slightly wrong, use unusual domains, or take you to a sign-in page that is not
login.microsoftonline.com. - Files or attachments you were not expecting, including OneDrive or SharePoint links.
- A display name that matches a colleague but uses a different account or email address.
Quick Fix Steps
- Do not click any links, open any attachments, or reply to the message.
- Do not approve any MFA prompts or share verification codes.
- Use the Teams Report option to flag the message to Microsoft and your organisation.
- Take a screenshot of the chat, including the sender's email address and any external tenant warning.
- Open a support ticket with 220 Internet Services so we can review and contain any risk.
Detailed Instructions
Step 1: Stop and assess the message
Before you do anything, read the message carefully and look for the red flags listed above. Pay particular attention to:
- The sender's full email address, not just their display name. In Teams, hover over the profile picture or name to reveal the underlying email.
- The presence of an "External" or "From an external organisation" banner above the chat.
- The tone, grammar, and any unusual requests that do not match normal workplace behaviour.
If anything feels rushed, unusual, or too good to be true, assume it is suspicious and proceed without clicking.
Step 2: Verify the sender through a separate channel
If the message appears to come from a colleague, manager, or known organisation, confirm it through a different channel before acting. For example:
- Call the person on a phone number you already have saved.
- Speak to them in person or via a previously confirmed Teams thread.
- For organisations like the ATO or Australia Post, visit their official website directly by typing the address into your browser, never by using the link in the message.
Never use the contact details provided inside the suspicious message itself.
Step 3: Report the message in Microsoft Teams
Microsoft Teams includes a built-in reporting option that notifies your security team and Microsoft.
- Open the suspicious chat in Teams.
- Hover over the message or click the More actions (
...) menu in the top-right corner of the chat. - Select Report this message (in some tenants this appears as Security then Report).
- Choose the most appropriate category, such as Phishing or Impersonation.
- Click Report to submit. The message will be sent to your organisation's security team for review.
Step 4: Capture evidence before deleting
Before you block or delete the sender, take a screenshot of:
- The full chat, including the sender's name and email address.
- Any external tenant warning banner.
- Any links, attachments, or QR codes contained in the message.
- The exact date and time the message was received.
This evidence is essential if 220 Internet Services needs to investigate, block the sender at the tenant level, or report the incident to authorities.
Step 5: Block the sender and leave the chat
- In the chat, click the sender's name or profile picture at the top of the window.
- Select Block, then confirm by clicking Block again.
- Optionally, click Leave to remove yourself from the chat if it is a group or external conversation.
Blocking prevents further direct messages from that account, although the user may still appear in shared channels or meetings.
Step 6: Secure your account
If you have already clicked a link, entered credentials, or approved an MFA prompt, act immediately.
- Change your Microsoft 365 password from a device you trust. See our guide: Password reset (Windows login).
- Review and remove any unfamiliar sign-in sessions by going to
account.microsoft.comthen Security then Sign-in activity. - Remove any suspicious App registrations or Multi-factor authentication methods from your account.
- Sign out of all sessions by selecting Sign out everywhere.
- Run a full antivirus scan on the device you used.
Step 7: Report the incident to 220 Internet Services
Once you have secured your account and captured evidence, lodge a ticket so our security team can investigate and take protective action across your tenant.
- Go to the 220 support portal at app.220.com.au.
- Click Open a Ticket and choose the Security category.
- Include the screenshots, the sender's email address, the time of the message, and a summary of any actions you took (for example, "I clicked the link but did not enter my password").
- Submit the ticket and watch for a response from our team.
Troubleshooting
I cannot find the "Report this message" option
The option may be disabled by your organisation's Teams policy, or it may appear under a slightly different menu. Try the following:
- Click the More actions (
...) menu at the top-right of the chat window. - Look for Report, Report a concern, or Report this chat.
- If the option is not available, take screenshots and report the incident directly to 220 Internet Services through the support portal.
The message came from inside my organisation but still looks suspicious
Internal accounts can also be compromised. Treat the message with the same caution and verify the request through a separate channel such as a phone call. If you cannot confirm the request, report it to our security team.
I approved an MFA prompt by mistake
An approved MFA prompt means the attacker may now have access to your account. Act immediately:
- Change your Microsoft 365 password straight away.
- Remove the compromised MFA method from your account at
account.microsoft.comunder Security then Advanced options. - Sign out of all sessions using Sign out everywhere.
- Review recent sign-in activity for any unfamiliar locations or devices.
- Notify 220 Internet Services through the support portal so we can audit your tenant for further suspicious activity.
I clicked the link but did not enter any details
You may still be at risk if the link triggered a silent download or credential capture. Run a full antivirus scan, clear your browser cache and cookies, and report the incident to 220 Internet Services so we can monitor your account for unusual behaviour.
The sender is already blocked but the messages keep coming
Attackers often create new accounts. Continue to report each new message using the Teams Report option and notify 220 Internet Services. We can apply tenant-level blocks and conditional access policies to reduce further attempts.
Still Having Issues?
💻 Open a Ticket