Midnight Blizzard Phishes Through Microsoft Teams (Aug 2023): External Chat as an Attack Vector
Retrospective: this article looks back at events from August 2023, written in 2026 with the benefit of hindsight.
On August 2, 2023, Microsoft reported that Midnight Blizzard — the Russian state actor also known as APT29 or Nobelium, linked to SolarWinds — was using Microsoft Teams chats to phish targets for credentials and MFA approvals.
How the campaign worked
- The attacker compromised Microsoft 365 tenants belonging to small businesses.
- In those tenants, they created new
onmicrosoft.comsubdomains with security- or product-themed names (for example, names resembling "Microsoft Identity Protection" or "security team"). - Using accounts in those tenants, they sent external Teams chat requests to targeted users in other organizations, posing as technical support or security staff.
- The messages urged users to approve an MFA prompt or enter a code into the Microsoft Authenticator app — completing the attacker's sign-in.
Microsoft said fewer than 40 organizations were targeted, mainly government, NGOs, IT services, technology, discrete manufacturing and media.
Why it mattered
- Chat bypassed email defenses. Many organizations had invested heavily in email filtering; Teams external chat had far fewer controls.
- Trust in internal-looking names. A message from "Microsoft Security" in Teams looked authoritative.
- MFA social engineering worked because users approved prompts when asked.
Microsoft's response
Microsoft mitigated the actor's use of the domains and improved warnings for external messages. Teams added external-sender labels and message request acceptance flows.
Lessons in hindsight
- Restrict Teams external access to approved domains where possible.
- Train users that IT will never ask them to approve MFA prompts via chat.
- Phishing-resistant MFA prevents the code-approval trick.
- Teams is a phishing channel — and attackers continued using it for malware delivery and help desk impersonation in later years.
- How to Restrict External Access and Federation in Microsoft Teams How-To & Hardening
- Detecting Teams External Chat Phishing: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: Your Chat Tool Is an Email Inbox Without Spam Filters CIO Briefings