There's finally a fix to this serious Microsoft Teams problem

Microsoft Teams
(Image credit: Shutterstock / monticello)

The team behind Microsoft Teams has moved to address one of the most pressing security issues affecting the service in a new update.

Users of the video conferencing platform will soon be able to report suspicious Microsoft Teams messages as a security threat using Office 365's built-in safety protections.

The service will be available to Office 365 users via its Microsoft Defender service, and will work much the same way as the current process for reporting suspect emails.

Microsoft Teams phishing

In its entry on the official Microsoft 365 roadmap, the company notes that the new tool will help an organization "protect itself from attacks via Microsoft Teams".

Given the similarities to existing systems, this should be as simple as clicking on a Defender pop-up message alerting to possible threats, which should block the malicious message immediately.

The feature is still listed as in development for now, with a scheduled general availability launch set for January 2023. When released, the company says it will be available to all web and desktop users across the world using Teams and Microsoft Defender for Office 365.

The news is the latest in a series of upgrades to Microsoft Teams in order to help protect users from possible security threats.

Back in July 2021, the platform gained the ability to automatically block phishing attempts thanks to an expansion of Defender for Office 365 Safe Links. This tool automatically scans URLs sent in Microsoft Teams to determine if they direct to a malicious destination.

Microsoft said at the time that every month its detection systems discover close to two million distinct URL-based payloads used by cybercriminals to conduct credential phishing campaigns.

Microsoft Teams has long been an attractive target for hackers, offering a straightforward route into a business via its employees. A report in February 2022 found attackers are using Teams chats and channels to spread malicious executable (.exe) files throughout organizations, which once activated can deliver malicious files to any member of the organization, either via one-on-one chats or group channels.

Another recent Microsoft 365 phishing campaign looked to impersonate several departments of the United States government, including the Department of Labor and the Department of Transport.

The emails, targeted at government contractors, claim to request bids for government projects but lead victims to credential phishing pages instead. 

Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Read more
Microsoft Teams
Microsoft Teams is finally introducing a spam and phishing alert - here’s what you need to know
Phishing
Russian cyberattackers spotted hitting Microsoft Teams with new phishing campaign
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Microsoft Teams
Microsoft Teams is getting one of Facebook's worst features, and I can't see why you'd ever use it
Hacker Typing
This devious two-step phishing campaign uses Microsoft tools to bypass email security
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft authentication system spoofed via phishing attack
Latest in Security
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedlyleft users exposed for months
DeepSeek
Fake DeepSeek installers are infecting your device with dangerous malware
AI tools.
Not even fairy tales are safe - researchers weaponise bedtime stories to jailbreak AI chatbots and create malware
Data leak
Top California sperm bank suffers embarrassing leak
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
ransomware avast
Billions of credentials were stolen from businesses around the world in 2024
Latest in News
Stability AI 3D Video
Stability AI’s new virtual camera turns any image into a cool 3D video and I’m blown away by how good it is
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedlyleft users exposed for months
Google Pixel 9a
Google is delaying the Pixel 9a to fix a mystery “component quality issue”
The bottom left corner of an Android phone, showing the Phone, Messages, Google icons and Google Search bar
Google Messages remote delete will soon save you from texting embarrassment – and here's how it works
ExpressVPN mobile app and Aircove
ExpressVPN ‘reduces workforce’ for the second time in two years
The Nanoleaf PC Screen Mirror Lightstrip being used on a desktop computer.
Mac gaming could get an intriguing boost – but not in the way you'd expect