← News

Microsoft Detects 7.6 Billion Phishing Emails as Teams Vishing Attacks Surge

2026-07-27 05:47:27
Microsoft has revealed that it detected approximately 7.6 billion email-based phishing attacks during the second quarter of 2026, highlighting the continued dominance of credential theft campaigns and the rapid rise of voice phishing attacks targeting Microsoft Teams users.

According to Microsoft's latest threat intelligence report, cybercriminals are increasingly combining traditional phishing emails with collaboration platforms such as Microsoft Teams to bypass conventional security controls and exploit employee trust.

Billions of Phishing Emails Blocked

Between April and June 2026, Microsoft identified nearly 7.6 billion phishing threats delivered through email.

Although monthly phishing volumes declined slightly—from 2.7 billion attacks in April to 2.4 billion in June—credential theft remained the primary objective behind most campaigns.

Microsoft reported that 94–96% of malicious payload attacks during the quarter were designed to steal user credentials through fake login portals, cloned authentication pages, or deceptive sign-in workflows.

Attackers most commonly delivered phishing payloads through HTML and PDF attachments, which together accounted for roughly 60–70% of observed attacks.

QR Code and Device Code Phishing Continue

While QR code phishing activity declined from its March peak of 18.7 million attacks to 8.3 million in June, the technique remains an active threat.

Most QR-based phishing campaigns used PDF and Microsoft Word attachments to direct victims toward fraudulent authentication pages.

Microsoft also warned about the continued use of Microsoft 365 device code phishing, where attackers abuse legitimate authentication workflows instead of relying on obviously malicious websites. These attacks can be particularly difficult for users to recognize because they leverage trusted Microsoft services during the login process.

Teams Vishing Attacks Increase Dramatically

Beyond email, Microsoft observed a significant increase in attacks conducted through Microsoft Teams.

Teams phishing detections rose by 19% from March to April and increased by an additional 10% during June.

The most notable trend involved voice phishing (vishing). Microsoft reported that malicious Teams calling activity increased by approximately 80% since the beginning of 2026 and reached nearly ten times the level observed during mid-2025.

Most attacks occurred during standard business hours, when employees were actively using collaboration tools.

Attackers Impersonate IT Support

Many of the observed attacks involved cybercriminals posing as internal IT support personnel.

Victims received Teams messages or voice calls claiming their account had been locked or that a security issue required immediate attention. Attackers then attempted to persuade employees to install remote-access software, disclose credentials, or approve malicious actions.

Microsoft noted that threat actors increasingly avoid obvious help desk names, instead using generic display names and email addresses containing words such as "support," "update," "infrastructure," or "software" to appear more legitimate.

In one documented incident, an employee granted remote access through Quick Assist after receiving a fraudulent Teams support call, illustrating how attackers can exploit trusted collaboration platforms to gain initial access.

Business Email Compromise Campaigns Continue

Microsoft also identified large-scale Business Email Compromise (BEC) campaigns during the reporting period.

One automated operation targeted more than 67,000 users across over 42,000 organizations within less than three hours.

The campaign used executive impersonation, payroll diversion requests, and financial reporting themes to establish conversations before attempting fraudulent financial transactions.

Although Microsoft's disruption of the Tycoon2FA phishing platform reduced activity associated with that service by approximately 92%, researchers noted that attackers quickly adapted by deploying new infrastructure and delivery methods.

Security Recommendations

Microsoft recommends organizations strengthen defenses by:

Enabling advanced email filtering and post-delivery message removal.
Activating protection for malicious links and attachments.
Deploying phishing-resistant multi-factor authentication (MFA) for privileged accounts.
Restricting communications from untrusted external Microsoft Teams users.
Disabling unnecessary remote support tools.
Providing regular phishing awareness training for employees.

Security teams are also encouraged to investigate unexpected Teams calls, suspicious external chats, and requests to install remote-access software or disclose sensitive information.

Evolving Phishing Landscape

Microsoft's latest findings demonstrate that phishing is no longer confined to email inboxes.

As organizations increasingly rely on collaboration platforms for daily communication, attackers are adapting their tactics by combining email, voice calls, messaging applications, and legitimate authentication workflows to increase the success rate of social engineering attacks.

The report underscores the importance of combining technical security controls with user awareness training to defend against increasingly sophisticated phishing campaigns.