Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Steal Microsoft Teams Chats & Emails by Grabbing Access Tokens

Security researchers have identified a method enabling attackers to steal access tokens from Microsoft Teams. This vulnerability potentially allows unauthorized access to sensitive corporate communications, emails, and SharePoint documents.

Security researchers have identified a method enabling attackers to steal access tokens from Microsoft Teams. This vulnerability potentially allows unauthorized access to sensitive corporate communications, emails, and SharePoint documents.

The discovered attack vector poses a significant security risk for organizations using Microsoft's productivity suite. Access tokens, once stolen, can be exploited for lateral movement within company networks and for social engineering attacks.

The attack targets the way Microsoft Teams stores encrypted authentication data. During the authentication process, Microsoft Teams uses an embedded Chromium-based browser engine, msedgewebview2.exe, which writes encrypted cookies to a database file in the user's AppData directory.

The encryption mechanism relies on DPAPI (Data Protection API), a Windows feature that encrypts sensitive data using machine-specific keys. Attackers can bypass this encryption by accessing the encryption key stored in a JSON configuration file within the Teams local cache. By extracting this key and the encrypted cookie value, they can decrypt the authentication tokens using AES-256-GCM encryption.

Security researchers have identified a method enabling attackers to steal access tokens from Microsoft Teams.
Brooke Sanders · Thehackingpost

Researchers have developed a proof-of-concept tool in Rust that automates this extraction process, demonstrating the feasibility of the attack. Once attackers obtain Teams access tokens, they can interact with the Microsoft Graph API to execute various malicious activities.

These activities include retrieving Teams conversations, reading and sending messages, and accessing emails within the context of the compromised user account. Stolen tokens can also be loaded into post-exploitation tools like GraphSpy, enabling unauthorized interaction with Microsoft Graph API endpoints without additional authentication.

Implications of the attack extend beyond simple data theft. Compromised accounts can be used to send phishing messages, establish persistence within the network, and conduct social engineering attacks with increased credibility. Since these activities appear to originate from a trusted internal account, detection becomes significantly more challenging.

Advertisement

Organizations are advised to implement endpoint detection and response (EDR) solutions to monitor access to Teams configuration files and encryption keys. Security teams should enforce strict access controls, monitor for suspicious Teams API activity, and educate users about protecting their devices from initial compromise. Additionally, users should ensure their systems receive regular security updates and run contemporary antivirus solutions to prevent initial access required for this attack.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories