Microsoft 365Incident TeardownsRetrospectives

Midnight Blizzard Phishes Through Microsoft Teams (Aug 2023): External Chat as an Attack Vector

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2023, written in 2026 with the benefit of hindsight.

On August 2, 2023, Microsoft reported that Midnight Blizzard — the Russian state actor also known as APT29 or Nobelium, linked to SolarWinds — was using Microsoft Teams chats to phish targets for credentials and MFA approvals.

How the campaign worked

  1. The attacker compromised Microsoft 365 tenants belonging to small businesses.
  2. In those tenants, they created new onmicrosoft.com subdomains with security- or product-themed names (for example, names resembling "Microsoft Identity Protection" or "security team").
  3. Using accounts in those tenants, they sent external Teams chat requests to targeted users in other organizations, posing as technical support or security staff.
  4. The messages urged users to approve an MFA prompt or enter a code into the Microsoft Authenticator app — completing the attacker's sign-in.

Microsoft said fewer than 40 organizations were targeted, mainly government, NGOs, IT services, technology, discrete manufacturing and media.

Why it mattered

  • Chat bypassed email defenses. Many organizations had invested heavily in email filtering; Teams external chat had far fewer controls.
  • Trust in internal-looking names. A message from "Microsoft Security" in Teams looked authoritative.
  • MFA social engineering worked because users approved prompts when asked.

Microsoft's response

Microsoft mitigated the actor's use of the domains and improved warnings for external messages. Teams added external-sender labels and message request acceptance flows.

Lessons in hindsight

  • Restrict Teams external access to approved domains where possible.
  • Train users that IT will never ask them to approve MFA prompts via chat.
  • Phishing-resistant MFA prevents the code-approval trick.
  • Teams is a phishing channel — and attackers continued using it for malware delivery and help desk impersonation in later years.
midnight blizzard teams phishing2023

More on this story