Microsoft is rolling out a "Report a concern" feature in Microsoft Teams that lets meeting participants flag suspected phishing, impersonation, scams, social engineering, and other suspicious behavior tied to meetings or meeting chat. Reports will be surfaced to defenders through the Teams admin center and Microsoft Defender portal, where security teams can review meeting metadata and limited contextual information as they investigate possible abuse. Microsoft is also adding controls to detect external meeting bots and improve organizer visibility into unauthorized AI assistants joining meetings, with the feature enabled by default as part of a broader push to harden collaboration platforms against fraud.
The move follows Microsoft's warning that AI-powered deception is accelerating fraud operations, including deepfake participants, voice cloning, and other impersonation tactics that exploit trust in digital communications. Separate user reporting has also highlighted how Microsoft security workflows can create confusion for administrators and employees, particularly when phishing-reporting actions in Outlook appear in security tooling as user interaction with a malicious message. Together, the updates show Microsoft expanding in-product reporting and investigation capabilities while organizations contend with increasingly convincing AI-enabled scams across email and meetings.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
A Reddit discussion described how reporting emails as phishing in Microsoft Outlook can generate alerts in Microsoft Defender that show the email details and the reporting mailbox. Commenters also claimed the built-in Microsoft report button can appear as a "click" during phishing testing, causing confusion for administrators and users.
Microsoft confirmed it is rolling out a new Teams feature called "Report a concern" that lets participants flag phishing, impersonation, scams, social engineering, and other suspicious behavior during meetings or from meeting chat. Reports are made available to organizations through the Teams admin center and, for customers with Defender, the Microsoft Defender portal.
Microsoft published Cyber Signals Issue 9 describing AI-powered deception and fraud trends, including attackers using AI to scrape company information, create deepfake participants, and clone voices. The report said AI-powered fraud attacks were occurring globally and highlighted activity from China and Europe, with rising threats in Germany.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
windowslatest.com
Open sourcereddit.com
Open sourcemicrosoft.com
Open sourceadmin.cloud.microsoft
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.