Security experts at Barracuda Networks warns of email-based attacks where well-known platforms such as Microsoft Teams and Facebook used to trick recipients into handing over login credentials and payment information. The threats are a couple of several highlighted in Barracuda's latest "”Email Threat Radar”.
One of the methods is based on the attackers exploiting Microsoft Teams for so-called callback phishing. Victims are added to Teams groups with names that signal urgency and are greeted with fake messages about invoices, automatic renewals, or unauthorized charges.
To avoid charges, the recipient is asked to call a specified phone number that actually goes directly to the scammers. Using a trusted collaboration tool and stressful language increases the chance of the attack being successful, while also allowing it to bypass traditional email filters.
Another growing threat is fake phishing emails from Facebook claiming that the recipient has violated copyright. The emails mimic Facebook's legitimate legal warnings and link to what appears to be a regular web page with "details of the infringement.".
In fact, it is a fake login page where the attackers collect the user's account details.
To reduce the risk of being affected, it is recommended, among other things, to tighten the settings for collaboration tools, increase awareness and training for employees, and use multi-factor authentication and security solutions that also cover collaboration platforms. The usual advice to be especially vigilant about emails that ask you to click on links also applies here.








