It starts with a message that feels oddly professional, almost reassuring. On Chinese social media, a growing number of people are sharing the same unsettling story: they thought they were talking to a recruiter, a landlord, a romantic match, or a foreign buyer, only to be led away from familiar apps and onto Microsoft Teams, Webex, or Zoho Cliq. These are not random chat services. They are polished workplace tools made by trusted global companies. That trust, it turns out, is exactly what makes them dangerous. Scammers have discovered that a corporate logo can do the work of a lie. On WeChat, people are suspicious of strangers, but on a platform designed for office meetings and business collaboration, the guard comes down. Since February 2025, WIRED’s analysis of over 150 Webex reviews on Apple’s Chinese App Store found that 71 percent of them referenced being scammed on the platform. Cisco, which owns Webex, did not respond to a request for comment. Meanwhile, Zoho acknowledged that its workplace app Cliq had been abused by scammers in a limited number of cases. The company said it uncovered the suspicious usage internally and, as of August 27, disabled online payments to Cliq in China, suspended every account created by the suspected scammer it identified, and plans to discontinue the free version of Cliq in the country going forward. But the broader pattern is already clear: fraud is no longer confined to shady websites or unknown numbers; it has moved into the same software people use at their jobs every day.
The way these scams work is both simple and sophisticated. According to dozens of victim accounts on Xiaohongshu and Douyin, the scammers hunt for targets in all the usual places. They pose as job recruiters with open positions, prospective renters contacting landlords, potential dates on Tinder, or international buyers looking to source products from Chinese factories. Once they find someone willing to chat, they steer the conversation toward a legitimate corporate communication tool. Microsoft Teams is especially well suited for this because of its enterprise features. The scammer creates an account for the target and sends them pre-made login credentials, so the victim never has to sign up or download anything themselves. Because the scammer controls the organization behind that account, they can deactivate it at any time, wiping out the entire chat history and any evidence the victim might later want to show police or friends. This is a deliberate design choice: the scammer can erase the digital trail in seconds. To explain why everything feels strange, scammers offer plausible excuses. They might say they are using work devices that only allow certain apps, or that they created a private Teams account just for the two of them to talk safely. None of it sounds unreasonable, especially when the person on the other end is polite, patient, and using software that looks reassuringly corporate.
One woman’s experience shows just how elaborate the deception can be. Her name is Zhao, and she was defrauded in May. After sharing her story online, she discovered that other victims had encountered the exact same scammer she had. One of them was even able to share the Teams login credentials the scammer had provided. Instead of simply warning others, Zhao decided to dig deeper. She pretended to be a new potential victim and tried to get the scammer to explain his methods. She asked why he insisted on using Teams instead of WeChat, which is by far the most popular messaging app in China. The scammer replied that his colleagues could see his WeChat messages because he was working on a project, so Teams was “like our secret base together.” He said the account he gave her was “for team members to contact family while on the project.” When Zhao asked about the strange username “joy20706905,” he calmly explained that the account was assigned by the software when it is purchased from Microsoft. It was a smooth, confident answer, and it shows how much thought goes into making the story believable. Zhao noted that when she was first defrauded in May, Microsoft Teams did not warn her that the conversation might be dangerous. It was only when she spoke to the same scammer again in August that the app began showing a banner that read: “Don’t share confidential info or your screen with people you don’t know. Report anything suspicious.” By then, for many victims, the damage had already been done.
Why do scammers choose Teams and Webex in the first place? The answer has to do with access, functionality, and trust. Unlike Telegram or WhatsApp, Microsoft Teams is not blocked by the Chinese government, so it is easy to download and use without a virtual private network. It also includes advanced tools like screen sharing and remote control, which allow scammers to gain a frightening level of access to a victim’s device. They can watch what is happening on the screen, guide the victim through actions, or quietly steal sensitive information. But the most powerful weapon is reputation. Microsoft Teams is made by a well-known multinational technology company, and it is widely used in workplaces around the world. That legitimacy is precisely what makes people lower their guard. The same logic applies to Webex. A Chinese software engineer named Tan Chenxin, who lives in New York, nearly fell for a scam earlier this week. He received a call from someone claiming to be involved in a joint police investigation with U.S. Customs and Border Protection and Chinese law enforcement. The caller asked him to download Webex and join a video call to discuss the situation. Tan hesitated, but then he looked up Webex and saw that it was developed by Cisco, a company he knew to be a global leader in cybersecurity. “I happen to know what Cisco is, so I convinced myself it was fine,” he said. That moment of self-assurance, based on brand recognition, was almost exactly what the scammer was counting on.
The response from companies has been uneven. Cisco stayed silent, at least publicly. Zoho took more visible action, acknowledging the problem and trying to shut down the abuse on Cliq. But these piecemeal efforts may not be enough. The deeper issue is that enterprise communication platforms were designed for productivity, not for protecting consumers from social engineering. They allow administrators to create accounts, control permissions, and manage data in ways that make sense for a company, but these same features become dangerous when they fall into the wrong hands. A scammer can act as a system administrator, creating a contained world where the victim has no real ownership over their messages and no way to preserve evidence. The victim is essentially a guest in a fake digital office, and when the scam ends, the entire room is locked. This is a fundamental mismatch between the tools and how they are being abused. It also raises questions for Microsoft and Cisco about whether they need to do more than display a warning banner. If a victim is using Teams to talk to someone they have never met, should the platform block screen sharing? Should it require identity verification before allowing accounts to create private chats? Should it send stronger alerts when a user logs in with pre-generated credentials? These are not impossible changes, but they require companies to accept that their products are being used as instruments of fraud.
In the end, the most important lesson is also the most human one: anyone can be deceived. The victims in these scams are not careless or naive. They are people looking for a job, a place to live, a romantic connection, or a business deal. They want to believe the person on the other side is real, and the scammer gives them every reason to do so. The conversation is friendly, the reasons are logical, and the software looks trustworthy. That emotional vulnerability is the real target. The advice that emerges from these stories is simple but difficult to practice: verify through another channel, never accept a pre-made account, never share your screen with a stranger, and be deeply suspicious of anyone who asks you to move from a common messaging app to a more obscure or “official” one. But we should also ask more of the companies that build these tools. If a platform can shut down a scammer’s account, it can also warn a user before they become a victim. If it can display a banner about suspicious behavior, it can also design its features to make fraud harder to commit. Times change, technology changes, and the old advice about not talking to strangers now must include the most polished, familiar-looking strangers we meet online.