Home Cyber Security News Microsoft Warns Phishing Attacks Are Moving Beyond Email Into Workplace Communication Tools

Microsoft Warns Phishing Attacks Are Moving Beyond Email Into Workplace Communication Tools

0
Workplace Tools Face Phishing
Workplace Tools Face Phishing

Microsoft has warned that phishing operators are increasingly targeting workplace communication platforms such as Microsoft Teams, using chat messages and voice calls to exploit the trust employees place in internal collaboration tools.

While email remains the primary initial-access channel, Teams-based social engineering and voice phishing surged during the second quarter of 2026

Microsoft Threat Intelligence observed that weekly malicious Teams call attempts climbed to nearly 10 times the mid-2025 baseline by late June.

Attackers commonly impersonate IT support personnel, claiming that a user’s account will be locked or requires an urgent security fix. The shift represents a major challenge for enterprise defenders.

Unlike conventional phishing email, Teams communications may avoid secure email gateways and can appear to originate from a trusted colleague, help-desk agent, or business contact.

Trend of QR code phishing attacks by weekly volume (January 2026–June 2026) (Source: microsoft)
Trend of QR code phishing attacks by weekly volume (January 2026–June 2026) (Source: microsoft)

Workplace Tools Face Phishing

Teams-based phishing activity increased through Q2, with detected attacks rising 19% from March to April and another 10% from May to June.

Technical-support impersonation remained the most common lure, but operators increasingly used generic display names rather than obvious “IT Support” or “Help Desk” identities.

Voice phishing, or vishing, showed the strongest growth. Average weekly malicious call attempts increased 31% from April to May and 27% from May to June, while the highest activity occurred on weekdays between 14:00 and 20:00 UTC, when employees were most likely to be available.

Attackers are also moving away from support-themed domains. Microsoft said malicious Teams accounts increasingly use SaaS, scanning, update, and infrastructure-related terminology language that can support ClickFix-style social engineering.

In these attacks, victims are persuaded to copy and run commands or install a supposed update to resolve a fabricated technical issue.

QR code phishing delivery method share by month (January-June 2026) (Source: microsoft)
QR code phishing delivery method share by month (January-June 2026) (Source: microsoft)

The objective is often credential theft, remote access, or malware delivery.

A convincing Teams chat or call can persuade a target to approve a multifactor authentication prompt, disclose credentials, install remote-management software, or follow a malicious link outside normal email-security controls.

Despite the expansion into collaboration platforms, Microsoft detected approximately 7.6 billion email-based phishing threats during Q2 2026.

Monthly volumes declined from 2.7 billion in April to 2.4 billion in June, but credential phishing remained the leading purpose of malicious payloads, representing 94% to 96% of payload-based attacks.

The decline followed Microsoft Digital Crimes Unit action against Tycoon2FA, a major adversary-in-the-middle phishing-as-a-service platform.

Tycoon2FA-linked phishing fell to 1.2 million messages in June, a 92% decrease from its pre-disruption average, and its share of CAPTCHA-gated phishing dropped to 12%.

Indicators of Compromise

IndicatorTypeDescriptionFirst SeenLast Seen
9i6pokerdepot[.]comDomainSending domain used in the staff update phishing campaign2026-06-152026-06-15
Customer.Service[@]9i6pokerdepot[.]comEmail addressCampaign sender address2026-06-15202

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here