Microsoft Teams Ransomware Attack: Two-Minute Call Risk

Ransomware actors use brief Microsoft Teams calls to gain access and deploy Chaos

Microsoft Teams ransomware attack techniques have evolved, with recent campaigns demonstrating just how quickly an unsuspecting user can be compromised. In a newly documented operation, attackers used brief Teams calls to impersonate IT support, gaining remote access and ultimately deploying Chaos ransomware within targeted networks.

How the Microsoft Teams Ransomware Attack Unfolded

Between February and June 2026, Sophos tracked a financially motivated campaign dubbed STAC4749. The attackers targeted dozens of organisations across North America, highlighting a new threat vector for businesses relying on Microsoft Teams for internal and external communication.

Attack Timeline and Initial Access

Attackers initiated contact by posing as internal IT support staff on Microsoft Teams. The fraudulent calls were short, typically lasting two to two-and-a-half minutes, but proved highly effective. During these brief conversations, the threat actors used social engineering tactics to persuade employees to grant them remote access. The attackers often referenced urgent issues or routine maintenance, exploiting trust in corporate IT processes.

  • February 2026: Initial reports of suspicious Teams calls surface among North American businesses.
  • March to May 2026: Surge in incidents, with dozens of organisations reporting similar attack patterns.
  • June 2026: Sophos analysts confirm the use of Chaos ransomware as the payload in successful breaches.

Technical Details of the Attack

The attackers’ primary technique was impersonation. By mimicking IT staff and leveraging Teams’ built-in communication features, they bypassed typical email-based phishing defences. Once remote access was granted, attackers rapidly installed remote desktop utilities or exploited existing remote management tools. This initial foothold allowed them to move laterally within the victim’s network, escalating privileges and identifying high-value targets such as file servers and backup systems.

The entire process from initial Teams call to ransomware deployment could take as little as a few hours, with the Teams call itself rarely exceeding two or three minutes. The attackers’ efficiency relied on minimal interaction, reducing the chance of detection or user suspicion.

Chaos Ransomware: Impact and Current Exploitation

Upon achieving sufficient access, the attackers deployed Chaos ransomware. This malware is known for its capacity to encrypt files across Windows environments, disrupt business operations, and demand significant ransom payments. The ransomware not only encrypted critical data but also targeted backup solutions, making recovery challenging without payment or robust offsite backups.

The campaign’s impact was widespread, affecting organisations of various sizes across multiple sectors. Sophos reported that the attackers showed a preference for small and medium-sized businesses, which often lack dedicated security teams or advanced monitoring capabilities. However, no sector was completely immune, and the tactics could easily be adapted to target larger enterprises or organisations outside North America, including UK businesses.

As of June 2026, exploitation remains active. The attackers continue to refine their impersonation scripts and exploit gaps in remote access security. The campaign demonstrates that even the most trusted collaboration tools can be turned into attack vectors when user trust is manipulated.

Products and Versions Affected

  • Microsoft Teams: All versions with external communication enabled are at risk.
  • Remote Access Tools: Common utilities such as TeamViewer, AnyDesk, or built-in Windows tools, often targeted once initial access is granted.
  • Windows Environments: All supported and unsupported versions may be impacted depending on lateral movement and privilege escalation methods.

Why This Ransomware Campaign Matters

This event highlights the growing sophistication of social engineering attacks within everyday business tools. The speed and simplicity of the Microsoft Teams ransomware attack mean even organisations with basic security awareness can be caught off guard. The campaign underscores the need for heightened scrutiny of support requests and stricter controls around remote access, especially as hybrid work environments persist.

What Organisations Should Do Now

  • Review and restrict Teams external communications, limiting who can contact employees from outside the organisation.
  • Establish verification procedures for all IT support requests, especially those involving remote access.
  • Audit and harden remote desktop and management tools, ensuring only authorised personnel have access.
  • Train staff to recognise social engineering tactics specific to collaboration platforms like Teams.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call