Cybercriminals in China have devised a dangerous vector for orchestrating financial fraud by moving away from traditional consumer messaging channels and exploiting Western enterprise communication software. Trusted workplace platforms including Microsoft Teams, Cisco Webex, and Zoho Cliq are increasingly being manipulated by fraudsters to run sophisticated schemes, taking advantage of the high credibility associated with global tech brands to deceive victims out of millions of dollars.
The Mechanics of Trust and the Pig-Butchering Scam
The scale of the problem came to light after a victim identified by her last name, Zhao, shared her experience regarding a severe financial loss. Zhao explained that when a contact she met online suggested communicating through Microsoft Teams, she felt no immediate suspicion. Having previously used the application and knowing it was developed by Microsoft, she assumed the channel was safe and trusted the interaction.
The fraudster initially established a personal relationship with Zhao, building rapport before introducing a cryptocurrency investment opportunity. He claimed the project offered far faster returns than standard stock market trading. Encouraged by the promise of rapid gains, Zhao secured loans from multiple banking institutions to maximize her investment. Shortly after the funds were transferred, the scammer cut off all contact and vanished with her money. When Zhao attempted to file a police report, she discovered that she could no longer log into the Teams account assigned to her, rendering her unable to retrieve chat logs or present digital evidence to law enforcement.
After sharing her story on social media, Zhao connected with dozens of other victims across China who were targeted through identical methods. The losses reported by these individuals range from $1,500 to $300,000. Among all the victims who came forward, only one managed to recover a portion of their stolen funds, which was achieved independently by tracing the recipient's bank account details.
Exploiting Enterprise Administrative Features to Erase Evidence
Victim accounts reveal a consistent pattern of operation. Fraudsters locate targets on various online platforms and direct them to download Microsoft Teams, providing pre-configured enterprise login credentials. The tactic has become so widespread that local police bureaus in China have released official warnings naming Teams as a tool used in fraudulent operations, with at least one law enforcement agency explicitly classifying it as a fraud-related application. Similarly, Chinese professional networking platform Maimai confirmed that its system automatically issues safety warnings to users whenever high-risk terms such as 'Teams' or 'Skype' are detected in internal messages.
The primary advantage for scammers lies in the administrative capabilities of enterprise accounts. Cybercriminals set up a fake corporate organization within the app and generate managed login credentials for their targets. Because the scammers maintain complete administrative control over the organizational account, they simply deactivate the target's account once the financial theft is completed. This action immediately wipes out the victim's access to chat history, destroying critical evidence required by authorities.
To justify using a dedicated corporate account, fraudsters offer plausible excuses. They frequently tell targets that company policy restricts their work computers to specific approved software, or claim to have created a private, secure Teams workspace exclusively for their interaction. In Zhao's case, when she inquired why they could not converse on WeChat—the dominant messaging application in China—the scammer claimed his colleagues could monitor his WeChat activity while on a work assignment, presenting Teams as a secure alternative for private communication.
App Store Reviews Signal Widespread Abuse
User feedback on official application distribution channels highlights that complaints regarding scam activity on enterprise platforms have been mounting for years. An analysis of 500 reviews of Microsoft Teams on Apple's Chinese app store spanning an 18-month period revealed that 30 percent contained explicit complaints about fraudulent schemes. The earliest recorded reviews calling out scam operations on the platform date back to 2022.
In one review posted in January, a user detailed losing RMB 1.48 million ($220,000) after registering for an account at the direction of fraudsters, noting that law enforcement had launched a formal investigation. The reviewer explicitly warned others that the operation was a classic pig-butchering scam and urged users to exercise extreme caution.
Corporate Responses and Security Measures
Addressing the trend, Steven Masada, global head of Microsoft's digital crimes division, stated that bad actors frequently attempt to misuse trusted brand names and communication tools for social engineering operations. He noted that Microsoft actively investigates reports of abuse, takes corrective action against non-compliant accounts, and continuously enhances protective mechanisms to identify and stop fraudulent behavior.
In June, Microsoft implemented a prominent warning banner within Teams for users in China, cautioning against common scam tactics and advising against sharing sensitive information. Additionally, the company discontinued the personal version of Teams in China, restricting the application's availability within the country strictly to enterprise accounts. Zhao observed this shift firsthand; while no safety alerts were visible when she was defrauded in May, returning to the app in August triggered clear safety banners warning users not to share confidential data or grant screen control to unknown contacts.
Cisco Webex and Zoho Cliq Face Parallel Vulnerabilities
Reports across Chinese social channels indicate that the exploitation of workplace software extends beyond Microsoft. Cisco's Webex video conferencing platform and Zoho's workplace communication tool, Cliq, have also been targeted. An analysis of over 150 reviews for Webex on Apple's Chinese app store since February 2025 revealed that 71 percent explicitly cited scam incidents occurring on the platform.
Sam Wunderl, a spokesperson for Zoho, acknowledged that the company identified a limited number of instances where bad actors used Zoho Cliq for fraudulent purposes. Wunderl stated that Zoho uncovered the suspicious activity through internal monitoring. By August 27, Zoho took preventive measures by disabling online payments for Cliq in China, suspending accounts associated with suspected scammers, and initiating plans to phase out the free version of Cliq in the Chinese market.
Vulnerabilities in Western Enterprise Software
Detailed accounts on Chinese platforms such as Xiaohongshu and Douyin show that scammers source potential targets across diverse online environments. Fraudsters impersonate corporate job recruiters, prospective tenants contacting landlords, dating profiles on Tinder, and overseas buyers seeking goods from Chinese manufacturers.
Western enterprise applications offer several distinct advantages to fraudsters operating in China. Unlike consumer messaging apps such as Telegram or WhatsApp, platforms like Teams and Webex are not blocked by Chinese network filters. Furthermore, these applications incorporate features such as screen sharing and remote desktop control, which allow scammers to gain direct access to a victim's device. Tan Chenxin, a software engineer based in New York, recalled an incident where a caller impersonating US Customs and Border Protection officials instructed him to download Webex for a video meeting. Recognizing the brand reputation of Cisco, Tan initially complied before identifying the scam and terminating the call prior to any financial loss.
Unlike native Chinese messaging platforms like WeChat and Xiaohongshu—which actively scan private and public communications for financial risk keywords and display automated warnings—Western workplace tools have historically lacked equivalent localized fraud prevention controls, leaving users vulnerable to social engineering.



















