KongTuke’s shift to Microsoft Teams for corporate breaches shows how attackers are moving their social engineering directly into trusted business communication channels. According to the report, the group is abusing Teams chats to impersonate IT support and gain persistent access to corporate networks in minutes, turning a collaboration platform into an initial access path. This is especially dangerous because users are more likely to trust messages received inside familiar enterprise tools than random emails or unknown websites.
Organizations should treat collaboration platforms like Microsoft Teams as part of the security perimeter. External messaging controls, strict tenant federation settings, user awareness training, MFA, conditional access, endpoint detection, and monitoring for suspicious remote-access tools are now essential. KongTuke has already been linked to ClickFix-style attacks, fake CAPTCHA lures, compromised WordPress sites, and malware delivery, so this Teams abuse is not a random trick; it is an evolution of a well-practiced social engineering playbook. Because naturally, after ruining email, attackers have discovered the office chat window too.
Initial access broker KongTuke has moved to Microsoft Teams for social engineering attacks, taking as little as five minutes to gain persistent access to corporate networks. [...]
Source: KongTuke hackers now use Microsoft Teams for corporate breaches via Bleeping Computer — published 14 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.