Hacker twins accidentally record own crimes on Teams

๐กA stark reminder that enterprise collaboration tools leave permanent audit trails that can compromise security.
โก 30-Second TL;DR
What Changed
Hackers failed to terminate a Microsoft Teams session recording.
Why It Matters
This serves as a cautionary tale for security professionals regarding the persistence of data in cloud-based collaboration platforms. It emphasizes that metadata and logs in enterprise tools can be critical forensic evidence.
What To Do Next
Review your organization's Microsoft Teams retention and recording policies to ensure sensitive data is not inadvertently stored or accessible.
Key Points
- โขHackers failed to terminate a Microsoft Teams session recording.
- โขThe recording served as self-incriminating evidence for their illegal activities.
- โขThe incident underscores the importance of operational security (OpSec) when using enterprise communication tools.
๐ง Deep Insight
Web-grounded analysis with 17 cited sources.
๐ Enhanced Key Takeaways
- โขThe hackers involved in the incident were identified as Muneeb and Sohaib Akhter, federal contractors who had prior convictions for wire fraud and hacking-related offenses in 2015.
- โขThe illicit activities, which were inadvertently recorded, included the deletion of over 90 U.S. government databases, such as those belonging to the IRS, DHS, and EEOC, and the copying of sensitive files immediately following their termination on February 18, 2025.
- โขDuring the recorded crime, the brothers discussed their actions, with Sohaib asking about 'plausible deniability' and Muneeb dismissing the impact by suggesting the victims 'can recover from yesterday,' implying reliance on daily backups.
- โขIn response to such data leak concerns, Microsoft Teams Premium introduced a 'Prevent screen capture' feature, rolling out globally by late November 2025, which blocks unauthorized screenshots and recordings during sensitive meetings on supported platforms.
๐ Competitor Analysisโธ Show
| Feature/Platform | Microsoft Teams | Zoom | Google Meet | Webex |
|---|---|---|---|---|
| Primary Focus | Integrated collaboration (chat, meetings, files) | Video conferencing | Video conferencing (Google Workspace integration) | Enterprise conferencing |
| Recording | Cloud-based (OneDrive/SharePoint); notifications to participants; admin controls for retention/access; 'Prevent screen capture' in Premium | High-quality audio/video recording; cloud storage; automatic transcription | Easy to use; real-time captions; integrated with Google Workspace | High-quality video meetings; local recording; post-meeting summaries |
| Security | Data encrypted in transit (TLS, SRTP) and at rest (AES 256-bit); FIPS 140-2 Level 2 validated for SharePoint; E2EE available for calls (disables recording) | Comprehensive security features; cloud storage for recordings | Secure video communication; integrated with Google ecosystem | End-to-end encryption; strong in enterprise conferencing |
| Integrations | Deep integration with Microsoft 365 apps | Integrations with third-party apps | Seamless integration with Google Workspace (Gmail, Drive, Calendar) | Connects with Google Workspace, Microsoft 365, Salesforce |
| Deployment | Cloud-based (Microsoft 365) | Cloud-based | Cloud-based (Google Workspace) | Cloud-based |
| Key Differentiator | All-in-one hub for Microsoft ecosystem users | User-friendly, robust for large virtual events/webinars | Simplicity and efficiency for Google users | Enterprise-grade features, AI-powered enhancements |
๐ ๏ธ Technical Deep Dive
- Recording Storage: Microsoft Teams meeting recordings are saved as .mp4 video files. For private or non-channel meetings, recordings are stored in the meeting organizer's OneDrive for Business. For meetings held within a specific Teams channel, recordings are stored in the SharePoint document library associated with that channel, typically in a 'Recordings' folder.
- Encryption in Transit: All Teams data, including messages, files, and meeting content, is encrypted in transit using industry-standard technologies such as Transport Layer Security (TLS) and Secure Real-time Transport Protocol (SRTP).
- Encryption at Rest: Data at rest within Microsoft services is encrypted. Files stored in SharePoint and OneDrive, which house Teams recordings, are protected by multiple layers of encryption, including AES 256-bit keys. SharePoint stores files as encrypted blobs in Azure storage, with encryption keys managed separately and the entire process being FIPS 140-2 Level 2 validated. Database access controls and Transparent Data Encryption (TDE) are used for underlying SQL Server databases.
- End-to-End Encryption (E2EE): Teams offers E2EE for individual calls and meetings for enhanced protection. However, enabling E2EE disables several features, including recording and transcription.
- Screen Capture Prevention: The 'Prevent screen capture' feature in Teams Premium restricts visual access to meeting elements. On Windows desktops, screenshot attempts result in black rectangles, while Android devices experience complete screenshot and recording blockage. Unsupported platforms like iOS, macOS, and web browsers are forced into audio-only mode.
๐ฎ Future ImplicationsAI analysis grounded in cited sources
โณ Timeline
๐ Sources (17)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
Weekly AI Recap
Read this week's curated digest of top AI events โ
๐Related Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: Ars Technica โ