Skip to main content
Enterprise chat channels diverted through a deceptive account-control trap

Scammers in China are weaponizing the trust people place in Microsoft Teams

WIRED found a recurring pattern in which scammers move victims into enterprise chat accounts they control, combining familiar software with romance, investment and impersonation tactics.

Published

31 Aug 2026

Reading Time

3 min read

Share this article:

Contents

Trusted software becomes part of the pretext

WIRED reported on August 28, 2026 that scammers in China are using Microsoft Teams, Webex and other workplace communication tools to support romance, investment and impersonation schemes. The recurring pattern is not a software exploit. Attackers first make contact elsewhere, then persuade a target to move into a legitimate enterprise app — sometimes supplying the username and password themselves.

That account control is important. WIRED says scammers can place victims inside an organization they administer and later disable access, leaving the victim unable to retrieve chat history that could help an investigation. The platform's reputation also becomes a social-engineering asset: familiar corporate software can make an unusual request feel more credible.

WIRED analyzed 500 reviews from the previous 18 months on Apple's China App Store and found that 30 percent explicitly complained about scammers. That is the publication's analysis of app-store reviews, not an official estimate of all Teams activity in China. Microsoft told WIRED that it investigates abuse and strengthens protections, and the report says it began showing a general scam-warning banner to Teams users in China in June.

The warning signs are behavioral

A request to use Teams is not evidence of fraud. The stronger warning is the sequence: an unsolicited recruiter, romantic contact, buyer or official asks to change platforms; provides credentials for an account the recipient does not control; discourages independent verification; and then introduces money transfers, cryptocurrency, remote control or sensitive information.

Microsoft's own guidance advises users to inspect the sender's name and address, preview suspicious external messages and accept a chat only when they trust the sender. Its phishing guidance also recommends verifying a claimed organization through contact details obtained independently, rather than through the message itself.

No legitimate investigator, employer or romantic partner needs a target to sign in with credentials that the other party controls. Users should keep ownership of their own account, preserve screenshots and transaction records, and stop before sharing a screen, installing remote-access software or moving funds. If money or credentials were already shared, the next steps are to contact the relevant bank or service through an official channel and report the account to the platform and local authorities.

What administrators can reduce

Organizations should review external chat and cross-tenant settings, train staff to recognize help-desk and authority impersonation, and make reporting paths easy to find. Technical controls can limit exposure, but they cannot replace verification when an attacker uses a valid account and a convincing story.

The broader lesson is that a trusted application is only the venue. Identity, account ownership and the requested action still need independent verification.

Sources

Tags:

#Microsoft Teams #social engineering #phishing #China #online fraud #enterprise security

19

views

0

shares

0

likes

Related Articles