Register for Semperis' Hybrid Identity Protection (HIP) Conference - June 30 - July 1 Register for Semperis' Hybrid Identity Protection (HIP) Conference - June 30 - July 1
Microsoft 365|Office|Office 365

FCM Messages Blasted out to Teams Customers on Android

We have all been there, one slip of the script and instead of working in the dev environment, you nuke a production server. While this instance isn’t nearly that catastrophic, Microsoft is dealing with an issue of blasting out “Test” messages to Teams users but it’s not entirely clear who is at fault though.

The company is aware of the issue and has indicated that users, only on their mobile device, may receive “Test” notifications that state “FCM Messages Test Notifications” according to TM221041. According to reports on Twitter, these are not one-off instances with reports of up to 10 messages being received. But it may not be Microsoft’s fault (initially), users on Reddit suspect it may be related to Firebase but nothing official is known at this point; Microsoft has stated that this issue only impacts Android users.

If the issue is with Firebase, this is not a vulnerability in Teams but in the notification system for Android. Meaning, it looks like the Android SDK notification service is being hit with the result being non-geniune Teams notifications appearing that are not actually from the Teams app but from a potential weakness in Firebase/Android notification platform.

Image #1 Expand
Microsoft accidentally sent out test messages to Teams users

Christian on Twitter was one such “lucky” recipient and Todd Klindt shared the screenshot you see in this post. If you have users reporting this problem, you are not alone and there is not much that you can do. This is on Microsoft to resolve and hopefully, they will stop sending out these alerts.

While this is not the most significant issue to impact Teams, having test overlap with production is always a bit concerning about what other gremlins are making their way to production; no other major issues for Teams are being reported at this time.

To stay updated on this issue (and any others), login to your admin portal and click Health in the left rail and then on Service health.

Related Topics:

BECOME A PETRI MEMBER:

Don't have a login but want to join the conversation? Sign up for a Petri Account

Register
Comments (1)

One response to “FCM Messages Blasted out to Teams Customers on Android”

  1. moogleassassin

    Hi Brad,

    I’m not sure this is (or was originally as its been going on for a few days across various services including Google, etc) Microsoft pushing these messages in error, it looks like it might be part of an exploit confirmed a few days ago by a researcher.

    Many services are reporting the same thing and reddit is full of people expressing their happiness to receive such messages at all hours of the day/night across multiple services not specific to Microsoft.

    Hope that helps. Cheers. J.

Leave a Reply

Brad Sams has more than a decade of writing and publishing experience under his belt including helping to establish new and seasoned publications From breaking news about upcoming Microsoft products to telling the story of how a billion dollar brand was birthed in his book, Beneath a Surface, Brad is a well-rounded journalist who has established himself as a trusted name in the industry.

Register for the Hybrid Identity Protection (HIP) Europe Conference!

Hybrid Identity Protection (HIP) Europe 2021 - Virtual Conference

Mobile workforces, cloud applications, and digitalization are changing every aspect of the modern enterprise. And with radical transformation come new business risks. Hybrid Identity Protection (HIP) is the premier educational forum for identity-centric practitioners. At the inaugural HIP Europe, join your local IAM experts and Microsoft MVPs to learn all the latest from the Hybrid Identity world.