Product1 distinct publisher3 min readPublished
Microsoft has retired the personal tier of Teams in China and added a warning banner, but the abuse lives in provisioning, where whoever created the account keeps the recovery path and the chat logs with it.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
Follow any of these and your For You feed starts watching them — no settings page required.
product
Cisco and Nvidia go looking for the other third of AI spending1 distinct publisher
leadership
Microsoft puts AI agents in Entra, which makes agent sprawl an identity team problem1 distinct publisher
product
A judge is about to price 34 years of Spirit Airlines paperwork at under two cents a record1 distinct publisher
security
AI skills now in 28.5% of security job ads, and the SOC job family is being quietly rewritten2 distinct publishers
Provisioning is the part of this that a product team can act on. When one person creates an account and hands the login to someone else, the second person occupies the account rather than owning it. The recovery path stays with the creator, which means the linked email or phone stays there too, and so does the power to reset the password. Zhao's scammer met her on Xiaohongshu, moved the conversation to Teams, and offered her an account and password to use [2]. She told WIRED she took it because she had used the app before and it was made by Microsoft [3].
An invited-user flow is supposed to mean an employee whose employer already vetted them, joining a tenant, with an IT desk to walk to. In practice, some users sign in with credentials from a stranger they met on a social app, then let the entire record of a financial relationship accumulate inside an account they cannot recover. Zhao took loans from several banks to put more money into the crypto project he pitched her [4].
The review data is worth doing the arithmetic on. Thirty percent of the 500 Teams reviews WIRED sampled works out to 150 posts complaining about scammers [10][16]. On Webex, 71 percent of more than 150 reviews since February 2025 is at least 106 posts [14][17], a rate roughly 2.4 times the Teams figure [18]. Those percentages are not fraud rates. App store reviews count the people angry enough to type, which makes them a floor on incidence and a weak basis for ranking platforms of different sizes. What they do establish is duration and spread: the oldest scam complaint on Teams dates to 2022 [10], some Chinese police bureaus have named the app in public warnings, one of them calling it a fraud-related app [8], and Maimai told Chinese media last year that it warns its own users when a message contains words like "Teams" or "Skype" [9].
The remedies address the two ends and not the middle. The June banner arrives in front of someone who already believes their counterpart is a Microsoft researcher, and retiring the consumer tier means an account now costs a tenant [13]. That is real friction, though the underlying design still works against victims: "your organisation issued this login and can take it away" is exactly what enterprise identity is built to do, so the handover the scammers rely on looks like ordinary administration. Steven Masada, who runs Microsoft's digital crimes division, told WIRED the company investigates abuse reports and takes action against accounts that break its policies [12]. Of the dozens of victims who contacted Zhao, one reported recovering any money, and did it by tracking down the recipient's bank account rather than through anything a platform did [6].
For anyone shipping an invite or provisioning flow, draw two axes: who created the account, and who holds recovery. Self-created plus self-recovery is the consumer case. Third-party-created plus third-party-recovery is corporate IT, and it is also the quadrant this scam sits in, which is why keyword filters and banners are doing the detection work instead of the identity system. In that quadrant, the open question is narrower: can a user export their own message history without the creator's cooperation, and can the platform's logs tell an account minted by a paying admin apart from one minted by a signup from last week. Zhao's case and the review claiming RMB 1.48 million in losses [11] both turn on evidence the victim could not retrieve.</body_markdown> </invoke>
Ranked by verification strength, evidence, and original report placement.
Zhao, a woman in her 30s living in Beijing, says she lost over $100,000 in May to a romance scammer who claimed to be a researcher working for Microsoft.
The scammer first chatted with Zhao on the Chinese social platform Xiaohongshu, then asked to move the conversation to Microsoft Teams, where he provided her with an account and password to use.
Zhao said she did not think much about it because she had used the app before and, since it was developed by Microsoft, she trusted it.
On Teams the scammer introduced Zhao to a cryptocurrency investment project, and she took out loans from several banks so she could invest more.
Because Zhao can no longer log into the Teams account the scammer told her to use, she cannot share the chat logs with police.
After Zhao described her experience on social media, dozens of other people in China told her they had fallen for the same scheme, claiming losses of $1,500 to $300,000; only one reported recovering some funds, by tracking down the recipient's bank account.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One newsroom, its own count, two vendors on record
WIRED did the measurable work itself and shows it: sample sizes, windows, the earliest scam review it found. It also got named people to speak — Microsoft's digital crimes chief and a Zoho spokesperson — which is more than most pig-butchering coverage carries. What is missing is anything an outsider could check: no vendor figures on how many provisioned accounts or fraudulent tenants existed, no loss confirmed against a bank record, a central victim identified by surname only, and Cisco declining to say a word.
Countermeasures dated and shipping; the mechanic untouched
The responses are real and time-stamped: a banner and the end of consumer Teams in China in June, Zoho cutting Cliq payments and suspending the scammer's accounts by August 27. Around them sits recognition no vendor would have chosen — police bureaus naming a Microsoft product in fraud alerts, Maimai treating the word 'Teams' as a risk keyword, and the same playbook surfacing on a third vendor's app. What nobody has changed is the step that makes it work: an organization can still create an account for a stranger and take it back, chat history included.
The word 'haven' outruns WIRED's own numbers
Teams gets the headline, but by WIRED's own instrument Webex reviews mention scams at roughly two and a half times the Teams rate — 71 percent against 30 percent, on a shorter window and a smaller sample. The vendor that said nothing generated the smaller story. App-store reviews also measure who was angry enough to post, not how many people were taken, so the percentages are sentiment shares dressed as prevalence. The mechanism is not overstated at all; the sizing is.
Remediation announcements double as the evidence
Two of the three vendors speak here through their own fixes, and those fixes are simultaneously the best proof that something was wrong — Microsoft pulling a consumer tier, Zoho blocking payments and pre-announcing the end of a free plan. Cisco's silence costs it a quote and buys it distance from a 71 percent figure. The percentages themselves are a publisher's construction rather than a disclosure anyone was compelled to make, and the victim who gathered the other victims and posed as bait has a stake in the pattern being named and believed.
Trust the how; hold the how-much loosely
The mechanics are the sturdy part — provisioned credentials, a tenant the scammer controls, evidence that vanishes when the account does — and they are corroborated by police warnings, a keyword filter at an unrelated platform and vendor action at two companies. Scale is where it thins: one publisher, app-store sentiment as a proxy for prevalence, unverified losses and no telemetry from anyone who has it.