Teams Imposters, Fake Microsoft Scans, and M365 Under Siege

by The Creator | Aug 25, 2026

Phishing attack response starts with verification: if someone contacts you via Teams claiming to be IT support, confirm their identity through a separate channel before following instructions. Four active threats are hitting small businesses right now, from fake Microsoft security scans to a campaign that has compromised 48% of targeted M365 accounts.

How are phishing attacks bypassing M365 two-factor authentication?

The Mirage2FA campaign has compromised over 4,500 US and EU companies by defeating Microsoft 365 two-factor authentication, with 48% of targeted accounts potentially exposed. Attackers impersonate IT support through Microsoft Teams, distributing SynkLoader malware. Fake Microsoft security scan websites trick users into removing antivirus software and granting remote access. Your immediate action: verify all IT requests through a second communication channel, require staff to refuse any request to uninstall security tools, and patch TeamCity servers immediately (Australia and US warn of active exploitation of a critical flaw). CISA tracks these incidents; check your M365 audit logs for suspicious sign-in attempts.

Key takeaways

  • Verify all IT support requests via Teams through a second channel before acting. Microsoft will never ask you to remove antivirus software.
  • Mirage2FA has hit 4,500 companies; check M365 audit logs for suspicious sign-ins and consider hardware security keys to strengthen two-factor authentication.
  • If your business uses TeamCity, patch immediately. Australia and US authorities report active exploitation of a critical server flaw.
  • Train staff to recognize fake Microsoft security scan websites that pressure users to grant remote access or disable protections.

Frequently asked questions

How do I verify if a Teams message from IT support is real?

Call your IT department or manager directly using a known phone number. Do not use contact information from the Teams message itself. Legitimate IT support will never ask you to install software, grant remote access, or remove security tools via chat.

What should I do if I clicked a link in a fake Microsoft security scan?

Disconnect the device from the network immediately and contact your IT team or a cybersecurity professional. Change your Microsoft 365 password from a different device and review your account login history in M365 security settings for suspicious activity.

Does WhatsApp passkey support affect business security?

WhatsApp's adoption of passkeys by 1 billion users strengthens security for communications using that platform. If your business uses WhatsApp for client contact, this upgrade reduces phishing risk on that channel specifically.

How critical is the TeamCity patch?

Very critical. Both Australia and US authorities warn of active exploitation of a critical TeamCity server flaw. If your business or development team uses TeamCity, apply the patch immediately and review server logs for unauthorized access.

Sources

Keep reading