ITIT Lunchroom
When it's already happened

That Teams message from your coworker — is it really them?

A chat message carrying a name you know can still come from a stranger, or from your coworker's stolen account. This walks you through the External and Guest labels, the address hiding behind the display name, the gift-card and payment-change scripts, and the ten-second check that settles it without offending anyone.

Verify on a different channel than the one the message arrived on — and report before you delete.

Last reviewed 2026-08-18 by Grayson Dodson. Free, plain-English guidance for everyday work technology.

What you'll be able to do

read a suspicious Teams or Slack message the way a security team reads it, confirm in ten seconds whether your coworker really sent it, report it properly in either app, and know exactly what to do if you already replied or clicked.

the external and guest labelsa display name that matchesan account that has neverurgency paired with a requesta request that skips thethe gift-card and "are youpayment-change and bank-detail fraudout-of-band verification, and reporting before deleting

Chat feels safer than email, and attackers know it

If a message on Microsoft Teams or Slack made you pause, that pause is worth listening to. You are not being paranoid, and you are not slow for asking. Chat simply feels different from email. Email arrives from the whole world, so you learned to squint at it. Chat is where your team lives, so a message there feels like someone tapping you on the shoulder, already inside the building, already vetted. That feeling is exactly what attackers went looking for. As companies got better at filtering email, criminals moved to the places people trust more and check faster: Teams chats, Slack direct messages, even texts claiming to be a coworker's new number. Two things make it work. Chat is fast, so you answer between meetings without reading closely. And chat shows a display name in big friendly letters while hiding the actual account behind it. Nothing about your judgment failed here. The message was built to arrive in the one place that never felt like it needed checking, and you checked anyway. Here is what to look at, in the order that takes the least effort.

The five tells, in the order you can check them

Start with the label. Microsoft Teams puts the word External next to the name of anyone messaging you from outside your organization, and Guest next to someone added into one of your teams from outside. Slack marks outside conversations differently: Slack Connect channels and direct messages sit in their own external connections section of the sidebar, the other person's profile photo carries their organization's Slack icon in the corner, and an orange banner sits above the message box. A coworker three desks away carries none of that. Next, open the profile. In Teams, select the person's name or picture at the top of the chat to open their profile card, which shows the actual email address on the account. In Slack, click their name to open the profile panel, where the email address and their organization usually appear. Watch for a display name matching someone you know while the address underneath belongs to a domain your company has never used. Third, check the history. Scroll up. If this is the first message this account has ever sent you and it opens with a request, that is unusual on its own. Fourth, urgency paired with secrecy: needs it now, please do not mention it yet. Fifth, a request that skips the normal process, such as a payment with no purchase order.

The three scripts that show up again and again

The first script starts small. A message appears under your manager's name, or the chief executive's, and says only: Are you at your desk? The point of that opener is to get a yes before any request arrives. Then comes the ask, always with a reason you cannot check by voice, such as being stuck in a board meeting. Then the real request: buy gift cards for a client thank-you, send photos of the codes on the back, expense it later. A legitimate employer does not need you to buy gift cards from your own pocket and photograph the codes. That request alone is the answer. The second script targets money already moving. Someone claiming to be a vendor or a colleague in accounts payable says their bank details have changed and wants them updated before this afternoon's payment run. Treat any banking change that arrives by chat as unverified until you confirm it by phone on a number you already had, which our lesson on fake payment and invoice requests covers in full. The third script arrives as a helpful link or file, a QR code, a sign-in page dressed up as SharePoint, or a message from IT Help Desk asking you to approve a prompt or read back a six-digit code. Real help desks never ask for that code, and our lesson on the fake IT support call is devoted to it.

How to verify in ten seconds without insulting anyone

Here is the whole technique, and it works even when the account genuinely belongs to your coworker, because real accounts get stolen and a hijacked account passes every label check. Reach the person a different way than the way the message came. If they sit in the building, walk over. If they do not, call the number listed in your company directory, never a number supplied in the message. In Microsoft 365, open microsoft365.com or Outlook, search the person's name, and use the phone number on their contact card. In Teams, select their profile picture and open the Organization tab, where your admin has enabled it, to confirm they really sit where the message claims. If you would rather chat, start a brand-new conversation with them from your contact list instead of replying in the suspicious thread, because whoever sent it controls that thread and your reply just reaches them. Then ask one plain question: did you just message me about gift cards? Ten seconds. Almost nobody minds being asked. If they did send it, you lost ten seconds. If they did not, you just caught something real. And if the account is theirs but taken over, you have told them something they urgently needed to know.

Reporting it, concretely, in Teams and in Slack

In Microsoft Teams, hover over the message without selecting it, choose More options, then Report this message, and confirm the reason shown as Security risk, spam, phishing, malicious content. That route exists only where your employer licenses Microsoft Defender for Office 365 and has left reporting switched on, so it may simply be missing. Slack is thinner than people assume. Its built-in tool is called Flag content, reached by hovering the message and clicking the three-dot icon, and it appears only on Enterprise plans where an org owner has turned content flagging on. Most workspaces will not have it. So plan on the ordinary path: take a screenshot, post it in your internal security or help desk channel, or send it to the security address in your handbook, often something like security@ or helpdesk@. Separately, Report to Slack in that same three-dot menu tells Slack the company about abuse, though it is not offered in every country, and feedback@slack.com reaches Slack support. In Teams you can also block a sender from outside your organization: in the chat list, select More options on that conversation, then Block. Do not delete the message before you report it. Security needs the original to see who else received the same thing.

If you already replied, clicked, or sent something

Nothing is ruined, and you are not in trouble for being helpful. Speed is the only thing that changes the outcome, so say something quickly. If you typed your work password into a page that opened, three steps cover it: change that password, sign every other session out, and tell your IT or security contact what you clicked and roughly when. For a Microsoft 365 account, change the password at myaccount.microsoft.com, then go to mysignins.microsoft.com, read Recent activity for sign-ins you do not recognize, and use Sign out everywhere under Security info. For Google Workspace, use myaccount.google.com and myaccount.google.com/device-activity. Our lesson on clicking a phishing link at work walks that sequence through properly, including what to do when you are unsure what you typed. Two situations need their own call. If you approved a sign-in prompt or read out a six-digit code, say so immediately, because someone may be inside the account right now and IT can end those sessions in minutes. If you bought gift cards, tell your manager the same hour and keep the cards and receipts, because some retailers can freeze a balance if they hear soon enough. Embarrassment is the one thing that does not help. Every security team would rather hear this the afternoon it happened than find it in an audit three weeks later.

Common questions

How do I know if a Teams message is really from my boss?

Verify through a different channel than the one the message arrived on. Walk to their desk, or call the number on their contact card in Outlook or at microsoft365.com, never a number supplied inside the message itself. If you would rather chat, start a new conversation with them from your contact list instead of replying in the suspicious thread, since whoever sent it controls that thread. Then ask directly: did you just message me about this? Real managers are relieved that you checked, and the whole thing takes about ten seconds.

Someone on Teams asked me to buy gift cards, is IT a scam?

Yes, treat it as a scam every time. The pattern is always the same: a short opener such as Are you at your desk? under a boss's name, a reason they cannot take a call, then a request to buy gift cards and photograph the codes with a promise of reimbursement. No employer legitimately runs client gifts that way. Do not reply, do not buy anything, and report the message. If you already bought cards, tell your manager the same hour and keep the cards and receipts, because reporting fast is what gives anyone a chance to recover the money.

What does External mean next to someone's name in Teams?

External means the person is messaging you from outside your organization, from a different company's Microsoft 365 tenant. Guest means someone from outside was added into one of your teams. Neither label is automatically bad; suppliers, clients, and contractors appear that way every day. It becomes a warning sign when an External account uses the display name of someone who actually works with you, or when it opens with a request about money, passwords, or urgency. Select the profile picture to open the profile card and read the real email address before you answer anything.

I clicked a link in a Teams message, what should I do?

A click alone usually does nothing; the risk starts if you typed something into the page that opened or approved a prompt. If you entered your work password, change it at myaccount.microsoft.com or myaccount.google.com, then end other sessions at mysignins.microsoft.com or myaccount.google.com/device-activity. Tell your IT or security contact what you clicked and roughly when, even if you are unsure anything happened. Report the message rather than deleting it, because your security team needs the original. Our lesson on clicking a phishing link at work covers the full sequence.

How do I report a phishing message in Teams or Slack?

In Microsoft Teams, hover over the message, select More options, choose Report this message, then confirm the security risk reason. That option exists only where your employer has Microsoft Defender for Office 365 and has left reporting enabled. Slack has no general report button. Its Flag content tool sits behind the three-dot icon on a message, but only on Enterprise plans where an admin has turned content flagging on. Otherwise screenshot the message into your internal security channel or send it to your help desk address, and use Report to Slack in that same menu for abuse aimed at Slack itself.

Practice it hands-on

Reading is a good start — now try a short, interactive version. Spotting Phishing and Scam Messages lets you make the real decision in a safe practice run, no login needed.

Make it stick

Create a free account to save your place across all the free lessons. Work through an interactive track and you earn a shareable certificate you can add to a résumé or job application. No payment, no catch.