HomeSecurityMicrosoft Teams: New “Chat with Anyone” feature exposes users to...

Microsoft Teams: New “Chat with Anyone” Feature Exposes Users to Phishing Attacks

The upcoming Microsoft Teams update, scheduled for targeted releases in early November 2025 and worldwide by January 2026, will allow users to start conversations with just an email address, even if the recipient is not a Teams user. This feature has raised security concerns among experts.

See also: New BOF tool exploits Microsoft Teams cookie encryption

Microsoft Teams: New “Chat with Anyone” Feature Exposes Users to Phishing Attacks

The invitee joins as a guest via email, enabling seamless external communication across Android, desktop, iOS, Linux, and Mac. While aimed at flexible working, this feature, which is enabled by default, opens the door to phishing attacks and malware infiltration, potentially leaking sensitive data. The main problem lies in the feature’s broad accessibility. By allowing conversations with external email addresses without prior validation, Teams creates an expanded attack surface.

Phishing attackers could forge legitimate invitations, tricking users into clicking malicious links or sharing credentials. For example, a fake “chat request” from a supposed business partner could embed malware payloads, exploiting the guest opt-in process to deliver ransomware or spyware directly into the organization’s chats.

Security researchers warn that this mirrors tactics seen in OAuth phishing campaigns, where attackers impersonate trusted services to collect data. With conversations governed by Entra B2B Guest but still confined to the organization’s boundaries, the risk of inadvertent data exposure increases. Employees may unwittingly disclose proprietary information to fraudsters, leading to intellectual property theft or compliance violations under regulations such as GDPR.

See also: Microsoft Teams introduces multitasking mode

Microsoft Teams: New “Chat with Anyone” Feature Exposes Users to Phishing Attacks

In practice, this could amplify threats in hybrid work environments. Think of a sales team chatting with a “prospect” via email invitation. If the contact is compromised, attackers gain access to monitor or escalate privileges. Malware distribution also becomes easier, as visitors could unwittingly forward infected files, bypassing traditional email filters, since interactions take place within the Teams ecosystem.

Microsoft acknowledges that the change affects all users and urges organizations to update documentation and train support teams. However, the default enablement means that many companies may overlook it until incidents occur, reminiscent of previous omissions like the SolarWinds breach, where unupdated features fueled widespread breaches.

Administrators are not powerless. To disable the feature, they can use PowerShell to set the UseB2BInvitesToAddExternalUsers attribute in the TeamsMessagingPolicy policy to false , effectively blocking external email conversations.

See also: Fake Microsoft Teams installers distribute Oyster backdoor

GIFShell attack infects Microsoft Teams using GIFs

This simple setting reinstates stricter controls, limiting invitations to verified B2B connections. Experts recommend combining it with multi-factor authentication enforcement, regular policy checks, and user awareness training to counter phishing attempts.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS