10/27/2025
๐จ Hackers Can Steal Microsoft Teams Chats & Emails Using โAccess Tokensโ
Security experts found a new trick hackers are using to break into Microsoft Teams accounts โ and from there, they can read your chats, emails, and even company files on SharePoint.
๐ง Whatโs happening
Hackers donโt need your password for this.
Instead, they grab something called an โaccess token.โ
Think of an access token like a digital key that tells Microsoft, โHey, this person is already logged in โ let them through.โ
If hackers get that token, they can pretend to be you inside Teams, Outlook, or SharePoint.
๐ป How they steal the tokens
When you use Teams, it saves login data (including tokens) on your computer.
That data is protected by Windows security features.
But researchers found that hackers can find the encryption key Microsoft Teams uses to protect those tokens.
With that key, hackers can unlock the tokens and use them as if they were you.
Researchers even built a proof-of-concept tool (in the Rust programming language) to show how easy it is to automate this.
๐ What hackers can do with stolen tokens
Once they have them, hackers can:
Read and send Teams messages as you
Access your emails and shared files
Pretend to be you in chats to trick coworkers
Spread through the company network quietly
Since it looks like the real user doing these things, itโs hard for security systems to notice.
๐ก๏ธ How companies can protect themselves
Use endpoint protection tools that can spot strange activity on devices
Watch for weird or unexpected use of the Teams API (the system that talks to Microsoft servers)
Teach employees to be careful with suspicious links or downloads
Keep Windows and Teams fully updated and run modern antivirus software
In short:
Hackers can hijack Microsoft Teams accounts by stealing hidden โlogin tokensโ from a userโs computer. Once they do, they can spy on chats and emails or impersonate people at work โ all without needing passwords.
Source: https://gbhackers.com/hackers-steal-microsoft-teams-chats-emails/