CIO Brief: Your Chat Tool Is an Email Inbox Without Spam Filters
Retrospective: this article looks back at events from August 2023, written in 2026 with the benefit of hindsight.
The short version: In 2023, Russian state hackers used Microsoft Teams chat — not email — to trick people into approving login requests. Companies have spent years filtering email for phishing. Most haven't applied the same protection to chat.
Why chat is the new phishing inbox
Email has spam filters, link scanning and warning banners. Chat tools often let anyone from another company send a message, with fewer checks. Messages that look like they're from "IT Support" feel urgent and trustworthy. Attackers have also used Teams to deliver malware and impersonate help desks.
The business impact
- Account takeover through approved MFA requests.
- Malware delivery through chat attachments.
- Bypassed security investments focused only on email.
Questions to ask your team
- Can anyone outside our company send our employees Teams messages?
- Do employees know IT will never ask them to approve a login prompt in chat?
- Can employees report suspicious chats as easily as suspicious emails?
What good looks like
External chat limited to known partner organizations (at least for high-risk employees), clear warnings on external messages, easy reporting, and phishing-resistant MFA that can't be approved on an attacker's behalf.
The decision
Ask your team to restrict external Teams chat for executives, finance and IT administrators. It's a settings change that closes an increasingly common attack path.
- Midnight Blizzard Phishes Through Microsoft Teams (Aug 2023): External Chat as an Attack Vector Incident Teardowns
- How to Restrict External Access and Federation in Microsoft Teams How-To & Hardening
- Detecting Teams External Chat Phishing: Defender XDR and Sentinel Hunting Queries Detection & Response