Hackers Registered New Domain with Exact Microsoft Teams Interface to Steal Logins
A four-day-old domain, teams-online.com, clones the Microsoft Teams login page to steal work credentials.
Security researcher Steven Lim reported that teams-online.com, registered about four days earlier, copies the Microsoft Teams login page and interface to harvest work credentials. At the time of his October 8, 2026 analysis, Microsoft Defender reportedly showed no detections. The report names no malware family, payload, attacker, or victims, and does not confirm how users reach the site. Defenders are advised to block the domain and review sign-ins rather than treat a visit as confirmed compromise.
- teams-online.com, registered four days earlier, copies the full Microsoft Teams login UI.
- Steven Lim advised blocking the domain in tenant and web filters.
- Defender reportedly had zero detections; no malware, victims, or lure path confirmed.
- The only indicator published is the domain itself, with no hashes or IPs.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | teams-online.com | mpt aimed at stealing work account credentials. The domain, teams-online[.]com, uses the name of the widely used meeting platform to mak |
Full article861 words · extracted from cybersecuritynews.com · click to collapse
A newly registered website is copying the Microsoft Teams login page and full user interface, raising concerns about a phishing attempt aimed at stealing work account credentials.
The domain, teams-online[.]com, uses the name of the widely used meeting platform to make a fake site look like a normal place to sign in. The alert says the domain was only four days old when examined. Microsoft Defender reportedly showed zero detections at that time.
That finding is a snapshot from the reported analysis, not proof that every Microsoft security service missed the site or that its detection status remains unchanged.
Security researcher Steven Lim, known on X as @0x534c, identified the suspicious domain in a threat alert posted on October 8, 2026. Lim said the website was actively mimicking the full Teams login and user interface.
He urged organizations to add the domain to their tenant block lists and web filtering policies rather than rely only on endpoint protection.
The available source describes a phishing website, not a confirmed malware infection. It does not name a malware family, show a downloaded payload, or explain how submitted login details are collected.
It also provides no victim count, attacker identity, or evidence that the operators have accessed Microsoft systems. Those limits matter when judging the scope of the threat.
Hackers Registered New Domain with Exact Microsoft Teams Interface
A copied Teams screen targets the trust employees place in a tool they use every day. The page can look familiar while the address belongs to someone else.
In credential phishing, the attacker tries to persuade the user to enter an email address and password into that false login screen, exposing details intended for a real service.
Lim’s report does not establish how people reach this particular website. Email links, chat messages, search results, and meeting invitations should not be presented as confirmed delivery routes.
However, Microsoft has documented phishing through Teams meetings, chats, and calls, showing why a familiar collaboration brand deserves the same care as an unexpected email requesting account access.
🚨 Threat Alert: A newly registered domain, 𝘁𝗲𝗮𝗺𝘀-𝗼𝗻𝗹𝗶𝗻𝗲[.]𝗰𝗼𝗺, created just 𝟰 𝗱𝗮𝘆𝘀 𝗮𝗴𝗼, is actively mimicking the full Microsoft Teams login and user interface.
— Steven Lim (@0x534c) October 8, 2026
At the time of analysis, 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗗𝗲𝗳𝗲𝗻𝗱𝗲𝗿 𝗿𝗲𝗽𝗼𝗿𝘁𝗲𝗱 𝘇𝗲𝗿𝗼… pic.twitter.com/otM577jzbV
Related Cybersecurity News coverage of blob URLs and Microsoft Teams shows how other operators have built fake login pages inside a browser.
Its report on the Tykit phishing kit describes another Microsoft 365 login imitation. These are useful comparisons for understanding brand abuse, but there is no evidence linking either operation to the domain Lim flagged.
Other reporting on Teams impersonation and unauthorized access covers fake meeting recordings used to prompt remote access tool downloads.
Coverage of passkey-themed phishing describes lookalike sign-in pages and stolen cloud sessions. Together, these cases show that similar branding can support different attack paths; they do not prove that this newly reported website installs software or steals session tokens.
Microsoft’s guidance on identity attacks explains that some phishing sites sit between the user and a real login service. This method, called adversary-in-the-middle phishing, can capture session tokens as well as passwords.
Lim’s alert does not confirm that technique here. A copied interface alone cannot establish whether an attacker can bypass multifactor authentication or reuse an authenticated session.
The reported zero detections also needs careful reading: Lim did not publish the Defender product, scan settings, or testing method behind that result.
It therefore cannot support claims of a complete security bypass. The practical concern is narrower: a reported phishing domain may need an explicit block while defenders investigate.
Teams chat restrictions and web filtering address different surfaces, so administrators should choose controls that actually prevent access to the reported website.
Reported Indicator and Recommended Response
The only indicator of compromise supplied for this incident is teams-online[.]com. The source contains no SHA-256, SHA-1, or MD5 hashes, and no IP addresses, file names, or additional malicious URLs.
Security teams should use the reported domain for blocking and investigation without adding indicators from unrelated campaigns. The defanged spelling helps readers share it without creating a clickable phishing link.
Administrators should apply Lim’s recommended domain blocks through supported controls and check relevant web access records for visits.
Any suspected exposure should be reviewed alongside account activity rather than treated as proof of compromise. Microsoft recommends investigating unusual sign-ins, newly added authentication methods, and unexpected cloud data access as connected events when assessing possible identity theft.
For confirmed account compromise, Microsoft’s response guidance calls for resetting credentials, revoking active sessions and refresh tokens, and removing attacker-added authentication methods and mailbox rules.
Longer term, phishing-resistant MFA, including FIDO2 security keys and passkeys, can reduce risk. Employees should verify unexpected login requests through a trusted channel and use known company entry points instead of relying on a page’s appearance.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.