A 30-something Beijing resident, identified only as Zhao, has become the latest victim in a growing wave of sophisticated scams targeting Chinese citizens, losing over $100,000 in May to a romance scammer who leveraged the legitimate business communication platform Microsoft Teams. The incident highlights a concerning trend where trusted enterprise software is being co-opted by fraudsters to isolate victims, build false trust, and facilitate elaborate financial schemes, often culminating in significant monetary losses.
The scam began innocuously on Xiaohongshu, a popular Chinese social media platform, where the perpetrator, posing as a Microsoft researcher, initiated contact with Zhao. Their initial interactions were reportedly amiable, fostering a sense of connection. However, the scammer soon suggested a transition to Microsoft Teams, a move that Zhao initially found reassuring due to the platform’s association with a globally recognized tech giant. "I didn’t think much because I had used this app before. And since it was developed by Microsoft, I kind of trusted it," Zhao recounted, her request for anonymity underscoring the sensitive nature of her experience. The scammer even provided Zhao with a dedicated account and password, further solidifying the illusion of legitimacy.
Once ensconced within the Teams environment, the scammer shifted their focus from romance to finance. They began painting a picture of a shared future, subtly weaving in a cryptocurrency investment opportunity that was purportedly far more lucrative than traditional stock trading. Enticed by the prospect of rapid financial gains, and fueled by promises of a future together, Zhao became increasingly invested. In her eagerness to capitalize on the supposed opportunity, she took out loans from several banks to funnel more money into the cryptocurrency scheme. The transition to Teams proved to be a critical turning point, as it allowed the scammer to isolate Zhao from her usual communication channels and exert greater control over the narrative.
The abrupt disappearance of the scammer, along with all of Zhao’s invested funds, left her devastated and unable to log into the Teams account provided to her. This lack of access meant she could not retrieve the chat logs, crucial evidence that could have been presented to law enforcement. Her subsequent sharing of her experience on social media platforms unearthed a chilling revelation: she was far from alone. Dozens of other individuals in China came forward, detailing strikingly similar encounters with the same scheme. Their reported losses ranged from a few thousand dollars to as much as $300,000, with only one victim managing to recover some of their funds by successfully tracing the recipient’s bank account.
A Pattern of Deception: The Microsoft Teams Modus Operandi
Victims consistently described a shared pattern of manipulation, at the core of which was the instruction to download and use Microsoft Teams with credentials supplied by the scammers. This tactic has become so prevalent that local law enforcement agencies across China have begun issuing explicit warnings, directly naming Teams as a platform exploited by fraudsters. One such warning from a local police bureau even labeled Teams as a "fraud-related app," highlighting the severity of the issue. The Chinese professional networking platform Maimai also reported last year that it automatically flagged high-risk keywords such as "Teams" and "Skype" in user messages, issuing alerts to advise users on avoiding scams.
The exploitation of Microsoft Teams is not a new phenomenon. For years, individuals who have fallen victim to these scams have been posting scathing reviews of the application on Chinese app stores, cautioning others against its download. An analysis of Microsoft Teams reviews on Apple’s Chinese app store over an 18-month period revealed that approximately 30 percent of 500 reviews contained explicit complaints about scammer activity. The earliest recorded review mentioning scams dated back to 2022, indicating a persistent and evolving problem.
One particularly stark review from January of this year detailed a loss of RMB 1.48 million (approximately $220,000), stating, "The scammers had me register for this app so they could contact me, and they defrauded me of RMB 1.48 million [$220,000]. The police have opened a case. This was unquestionably a ‘pig-butchering’ scam. Beware of fraud—this was a bitter and costly lesson!" The term "pig-butchering scam" refers to a long-term investment fraud that often begins with romance and culminates in the victim being convinced to invest in fake cryptocurrency or trading platforms.
Microsoft has acknowledged the issue, stating that scammers routinely exploit trusted brands and communication platforms for social engineering schemes. Steven Masada, the global head of Microsoft’s digital crimes division, issued a statement affirming the company’s commitment to addressing these abuses. "As these tactics evolve, the company says it ‘investigates reports of abuse, takes action against accounts that violate our policies, and continues to strengthen protections designed to identify and disrupt fraudulent activity,’" Masada stated.
In response to the escalating problem, Microsoft began displaying a general warning banner to Teams users in China in June, advising them about common scams and urging caution when sharing sensitive information. Furthermore, the company has discontinued the personal version of Teams in China, making the service exclusively available through enterprise accounts within the country.
Broader Exploitation of Enterprise Software
The modus operandi of using legitimate enterprise communication tools is not limited to Microsoft Teams. Reports have emerged of similar scams utilizing other corporate software applications, including Webex, a video conferencing platform owned by Cisco, and Zoho Cliq, a workplace communication app developed by the Indian software giant Zoho. An analysis of Webex reviews on Apple’s Chinese app store revealed that as of February 2025, 71 percent of over 150 reviews referenced being scammed on the platform. Cisco has not yet responded to requests for comment on this issue.
Zoho, however, has taken proactive steps. A spokesperson for the company, Sam Wunderl, acknowledged "a limited number of instances involving scammers using Zoho Cliq to defraud victims." Zoho’s internal investigations uncovered suspicious usage, leading them to disable online payments to Cliq in China as of August 27. Additionally, they have suspended all accounts identified as belonging to suspected scammers and plan to discontinue the free version of Cliq in China.
The Allure of Enterprise Platforms for Scammers
The widespread adoption of enterprise-grade communication tools like Microsoft Teams and Webex by legitimate businesses makes them attractive targets for scammers. These platforms are not subject to the same government-imposed restrictions as some Western messaging apps, such as Telegram or WhatsApp, which are blocked in China. This accessibility, coupled with advanced features, creates a fertile ground for fraudulent activities.
Why Microsoft Teams is an Ideal Tool for Fraudsters
Microsoft Teams possesses several key attributes that make it particularly well-suited for sophisticated scams:
- Legitimacy and Trust: Developed by a globally recognized and trusted technology company, Teams carries an inherent air of legitimacy. Victims are less likely to suspect malicious intent when using a platform endorsed by a multinational corporation.
- Enterprise Features: The platform offers advanced functionalities such as screen sharing, remote control, and the ability to create and manage organizational accounts. Scammers leverage these features to create accounts for their targets, provide pre-made login credentials, and maintain control over the communication environment.
- Isolation: By directing victims to a dedicated Teams account, scammers can isolate them from their usual social networks and communication channels. This isolation makes it harder for victims to seek advice or verification from trusted sources.
- Control Over Evidence: Scammers can create an "organization" within Teams, granting them the power to deactivate accounts once the scheme is complete. This action effectively erases chat histories, making it exceedingly difficult for victims to gather evidence for law enforcement.
- Plausible Deniability: To explain the unusual setup, scammers often provide fabricated reasons, such as claiming to use work devices that restrict app usage or setting up a private Teams account for "confidential" communication.
Zhao’s experience illustrates this perfectly. When she inquired about using Teams instead of WeChat, the dominant messaging app in China, the scammer claimed his colleagues could monitor his WeChat messages due to a work project, positioning Teams as their "secret base." He described the provided account as being "for team members to contact family while on the project," a story designed to preempt suspicion.
A History of Exploitation and Evolving Tactics
The exploitation of Microsoft Teams by scammers has been ongoing for years. Victims have consistently reported their experiences, with many actively warning others through app store reviews. The longevity of these scams suggests a persistent vulnerability that scammers have been adept at exploiting.
A significant aspect of the scam involves the scammer’s control over the Teams environment. By creating and managing the organizational accounts, they can effectively disappear with the victim’s funds and simultaneously wipe out any digital trail. This lack of recoverable evidence presents a major hurdle for victims seeking justice and for law enforcement agencies investigating these cases.
Official Responses and Future Implications
Microsoft’s recent actions, including the deployment of warning banners and the discontinuation of the personal version of Teams in China, indicate a growing awareness and response to the issue. However, the continued availability of Teams through enterprise accounts means that the platform remains a potential avenue for scammers.
The broader implication of these scams extends beyond the financial losses incurred by victims. The erosion of trust in legitimate technology platforms is a significant concern. As scammers become more adept at leveraging sophisticated tools, individuals may become increasingly wary of online interactions and the use of commonly accepted communication software. This could have a chilling effect on digital collaboration and the adoption of new technologies.
The trend of using enterprise software for scams also highlights a potential gap in the cybersecurity measures of these platforms. While companies like Microsoft and Cisco are investing in security protocols, the dynamic nature of social engineering requires constant vigilance and adaptation. The ability of scammers to quickly identify and exploit new vulnerabilities means that a multi-pronged approach involving platform providers, law enforcement, and public education is crucial.
The Chinese authorities are actively working to combat these scams, but the transnational nature of some of these operations and the sophisticated methods employed by fraudsters present ongoing challenges. The recovery of funds is often difficult, and the psychological impact on victims can be profound.
In conclusion, the case of Zhao and the numerous other victims underscore a disturbing trend where the very tools designed to facilitate communication and collaboration are being weaponized by criminals. The continued exploitation of Microsoft Teams and similar platforms serves as a stark reminder of the evolving landscape of cybercrime and the critical need for enhanced vigilance and proactive security measures from both technology providers and users alike. As scams become more elaborate, the battle against them will require a coordinated effort to safeguard individuals and preserve trust in the digital realm.
