Microsoft Teams can be really bad for your (security) health – hackers are spoofing bosses, sending fake messages and more


  • Microsoft Teams flaw allowed editing of messages, spoofed alerts, and spoofed caller identities
  • Attackers can exploit these flaws for phishing, wire fraud, and malware delivery
  • Microsoft patched CVE-2024-38197; no user action required after October 2025 fixes

Experts have found that Microsoft Teams contained several vulnerabilities that allowed threat actors to edit messages, spoof notifications, and change usernames, opening it up to various phishing and social engineering attacks, putting users at risk of data theft, wire fraud, and malware/ransomware infections.

In a new report, experts from Check Point Research detailed the flaws in the popular online collaboration platform, noting that attackers were able to reuse unique identifiers in the Microsoft Teams messaging system and change the content of previously sent messages without triggering the “Edited” label.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top