Advantage is alerting customers and partners to a rise in fraudulent Microsoft Teams calls targeting New Zealand organisations. The activity involves social engineering tactics designed to trick users into granting unauthorised remote access to their devices.
Over the past week, several organisations have reported receiving Microsoft Teams calls from individuals impersonating internal IT staff or trusted contacts. In these cases, callers attempted to persuade users to install remote assistance tools, such as Quick Assist, under the guise of resolving an urgent technical issue.
Importantly, no systems were compromised in the incidents reviewed by Advantage. In each instance, users recognised the activity as suspicious, reported it promptly, and did not grant remote access.
A Shift in Attack Techniques
These incidents highlight a growing shift away from traditional phishing emails toward real‑time collaboration platforms such as Microsoft Teams. By impersonating familiar contacts and creating a sense of urgency, attackers aim to bypass technical controls and exploit human trust.
- Across recent reports, we are seeing:
- Impersonation of internal staff or known contacts
- Requests to install remote support software
- Attempts to establish unauthorised remote access
- Targeting via collaboration platforms rather than email
While this technique is not new internationally, it is appearing with increasing frequency within New Zealand organisations.
Recommended Actions for Organisations
Advantage recommends organisations take the following steps to reduce risk:
- Restrict Remote Access Tools – Ensure only approved remote support tools are permitted and that their use is limited to authorised personnel.
- Review Microsoft Teams External Access Settings – Confirm that external access, federation, and trusted domain settings align with business requirements and security policies.
- Reinforce Staff Awareness – Remind staff that IT teams (and Microsoft) will not request software installation via unsolicited calls. Encourage immediate reporting of suspicious activity.
- Enhance Monitoring and Logging – Ensure collaboration activity, authentication events, and remote access tool usage are logged and monitored for unusual behaviour.
Our Position
These incidents reinforce the importance of layered security controls, informed users, and rapid internal reporting. In the cases reviewed, early detection and swift action prevented escalation.
Collaboration platforms are expected to remain an active attack vector throughout 2026.
How Advantage Can Help
Advantage supports organisations with:
- Microsoft 365 and Teams security configuration reviews
- Remote access governance and control design
- Security monitoring enhancements
- Staff awareness refresh campaigns
- Incident response readiness assessments
Organisations seeking guidance are encouraged to contact their Advantage representative.
