Microsoft: Hackers Registered New Domain with Exact Microsoft Teams Interface to Steal Logins

Microsoft: Hackers Registered New Domain with Exact Microsoft Teams Interface to Steal Logins

New Phishing Site Mimics Microsoft Teams Login in Credential Theft Attempt

A recently registered domain, teams-online[.]com, is impersonating the Microsoft Teams login page in a suspected phishing campaign aimed at stealing corporate credentials. The site, discovered by security researcher Steven Lim (@0x534c) on October 8, 2026, replicates the full Teams interface to deceive users into entering their work account details.

The domain was just four days old at the time of analysis, and initial scans reportedly showed zero detections in Microsoft Defender though this does not confirm a persistent security gap. The phishing page appears designed to exploit trust in Microsoft’s collaboration platform, a tactic consistent with credential-harvesting attacks.

While the site mimics the Teams login, there is no evidence of malware delivery, session token theft, or adversary-in-the-middle (AiTM) techniques. The attack vector remains unconfirmed, though Microsoft has previously documented phishing attempts via Teams chats, meetings, and calls. The domain’s operators, victim count, and method of credential exfiltration are also unknown.

Lim advised organizations to block the domain via tenant restrictions and web filtering rather than relying solely on endpoint protection. Microsoft’s broader guidance for suspected account compromise includes resetting credentials, revoking active sessions, and removing unauthorized authentication methods.

The only confirmed indicator of compromise (IoC) is the domain itself no additional hashes, IPs, or malicious URLs were provided. Security teams are urged to investigate access logs for visits to the site while treating potential exposure as part of a broader identity theft review.

Source: https://cybersecuritynews.com/domain-with-exact-microsoft-teams-interface/

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-security

"id": "mic1791448086",
"linkid": "microsoft-security",
"type": "Cyber Attack",
"date": "10/2026",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'name': 'Microsoft Teams Users',
                        'type': 'Corporate Users'}],
 'attack_vector': 'Phishing Website',
 'customer_advisories': 'Treat potential exposure as part of a broader '
                        'identity theft review.',
 'data_breach': {'sensitivity_of_data': 'High',
                 'type_of_data_compromised': 'Corporate credentials'},
 'date_detected': '2026-10-08',
 'date_publicly_disclosed': '2026-10-08',
 'description': 'A recently registered domain, *teams-online[.]com*, is '
                'impersonating the Microsoft Teams login page in a suspected '
                'phishing campaign aimed at stealing corporate credentials. '
                'The site replicates the full Teams interface to deceive users '
                'into entering their work account details.',
 'impact': {'data_compromised': 'Corporate credentials',
            'identity_theft_risk': 'High'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Organizations should not rely solely on endpoint '
                    'protection and should implement domain blocking and web '
                    'filtering.',
 'motivation': 'Credential Theft',
 'recommendations': 'Block the domain via tenant restrictions and web '
                    'filtering, reset credentials, revoke active sessions, '
                    'remove unauthorized authentication methods, and '
                    'investigate access logs for visits to the site.',
 'references': [{'date_accessed': '2026-10-08',
                 'source': 'Steven Lim (@0x534c)'}],
 'response': {'containment_measures': 'Block the domain via tenant '
                                      'restrictions and web filtering',
              'enhanced_monitoring': 'Investigate access logs for visits to '
                                     'the site',
              'remediation_measures': 'Reset credentials, revoke active '
                                      'sessions, remove unauthorized '
                                      'authentication methods'},
 'title': 'New Phishing Site Mimics Microsoft Teams Login in Credential Theft '
          'Attempt',
 'type': 'Phishing'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.