Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
voice-social-engineeringidentity-impersonation-fraudphishing-campaign-intelligencewidely-deployed-product-advisory

Microsoft Teams and Azure Tenant Abuse for Social Engineering Attacks

Updated 3mo agoFirst seen Dec 25, 20252 sources

Microsoft is introducing a new feature that allows security administrators to block external users from sending messages, calls, or meeting invitations to their organization via Teams, managed through the Microsoft Defender portal. This integration with Defender for Office 365 enables admins to centrally manage blocked external contacts, supporting up to 4,000 domains and 200 email addresses, and is designed to counteract cybercrime groups, including ransomware actors, who exploit Teams for social engineering. The update will also enhance default security by enabling malicious URL detection and warning admins about suspicious external traffic, aiming to strengthen organizational defenses against external threats.

Simultaneously, cybercriminals are exploiting legitimate Microsoft infrastructure, specifically .onmicrosoft.com domains assigned to Azure tenants, to launch Telephone-Oriented Attack Delivery (TOAD) scams. Attackers create controlled tenants and send malicious invites that appear to originate from trusted Microsoft addresses, bypassing standard email security filters. These invites contain social engineering lures in the message field, urging recipients to call fraudulent support numbers. Security teams are advised to implement targeted Exchange Transport Rules using Regex to mitigate this threat, as blocking the entire domain would disrupt legitimate operations.

Share:
Microsoft Teams and Azure Tenant Abuse for Social Engineering Attacks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jan 1, 20266mo ago

Microsoft schedules Teams security features to roll out in January 2026

Microsoft said the new Teams external user blocking feature would begin rolling out in January 2026 for customers with Defender for Office 365 Plan 1 or Plan 2. The company also said enhanced protections such as malicious URL detection and blocking of weaponizable file types would be enabled by default in the same timeframe.

Dec 24, 20256mo ago

Microsoft announces Teams external user blocking via Defender

Microsoft announced a new Teams security capability that will let administrators block external users, domains, messages, calls, and meeting invitations through the Defender for Office 365 Tenant Allow/Block List. The feature is intended to reduce social engineering and ransomware-related abuse of Teams.

Dec 22, 20256mo ago

Attackers abuse Azure .onmicrosoft.com domains for TOAD scam emails

Cybercriminals began using default .onmicrosoft.com domains tied to attacker-created Azure tenants to send Microsoft Invite notifications containing phone numbers for Telephone-Oriented Attack Delivery scams. The technique abuses trusted Microsoft infrastructure to evade many email security controls because the social engineering content appears in the email body.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

2 LINKEDOpen in app
Affected products
1 linked
Exchange
Organizations
1 linked
Microsoft Corporation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.