Threat actors are abusing legitimate Microsoft Teams functionality—specifically the “Invite a Guest” workflow—to deliver billing-themed phishing lures via authentic Microsoft-generated email notifications. Attackers create Teams with deceptive names that resemble urgent financial alerts (e.g., subscription renewal/auto-pay notices) and then invite external users as guests; the resulting email originates from legitimate Microsoft infrastructure (e.g., noreply@email.teams.microsoft.com), allowing it to pass SPF/DKIM/DMARC and bypass many traditional email security controls. To evade content filtering, the lures use obfuscation (e.g., substituting 0 for O) and embed the fraudulent message directly in the Team name so it appears prominently in the notification.
Unlike common credential-harvesting campaigns that rely on malicious links, the observed activity emphasizes phone-based social engineering (vishing) by placing a fake support number in the Team name and instructing recipients to call to dispute a charge. Reporting indicates the campaign is highly active (on the order of ~990 messages/day) and disproportionately targets organizations in manufacturing/engineering/construction, technology/SaaS, and education, with the majority of observed activity in the United States. Separately, CloudSEK reported Canada-focused fraud operations tied to the PayTool phishing ecosystem (SMS lures impersonating government agencies and national brands), which is a different set of scams and infrastructure than the Microsoft Teams invite abuse described above.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Check Point Research disclosed telemetry showing the campaign operating at scale, peaking at 12,866 messages, or about 990 per day, reaching roughly 6,135 customers. The United States accounted for most observed activity, with manufacturing/engineering/construction, technology/SaaS/IT, and education among the most affected sectors.
Threat actors began abusing Microsoft Teams' legitimate "Invite a Guest" and notification features to send fake billing or invoice notices that appeared to come from trusted Microsoft infrastructure. The lures embedded fraudulent support phone numbers in finance-themed team names and used obfuscation such as lookalike characters and mixed Unicode to evade detection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.