Skip to content
Malware

Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold

Email phishing remains one of the most common ways attackers gain access to business accounts. During the second quarter of 2026, criminals continued to use fake login pages, malicious attachments, and convincing business messages to steal credentials or deliver malware. The problem is no longer lim...

· Jul 24, 2026 · 5 min read · 👁 2 views

Email phishing remains one of the most common ways attackers gain access to business accounts.

During the second quarter of 2026, criminals continued to use fake login pages, malicious attachments, and convincing business messages to steal credentials or deliver malware.

The problem is no longer limited to the inbox. Attackers are increasingly using collaboration tools to contact employees directly, posing as technical support staff and pressuring them to share access, run a tool, or visit a fraudulent site.

Microsoft analysts identified a sharp rise in phishing activity across email and Microsoft Teams, showing how attackers are moving between trusted workplace channels.

The activity combines high-volume email campaigns with voice phishing, also called vishing, that targets employees when they are active online.

The scale creates a serious challenge for organizations because many of these attacks rely on human trust rather than software flaws.

A message that looks routine, or a call that appears to come from internal IT, can be enough to start a costly compromise.

Microsoft said in a report shared with Cyber Security News (CSN) that it detected approximately 7.6 billion email-based phishing threats between April and June 2026.

Monthly volume fell slightly from 2.7 billion in April to 2.4 billion in June, but credential theft remained the main goal.

7.6 Billion Email Phishing Threats as Teams Vishing Attacks

Credential phishing made up 94 to 96 percent of malicious payload attacks observed during the quarter.

These campaigns typically direct victims to a fake sign-in page or load a copied login screen locally, allowing attackers to capture passwords and potentially bypass normal account controls.

HTML and PDF files were the most frequent delivery formats, together representing about 60 to 70 percent of payload-based attacks.

Users should remain cautious of unexpected documents, particularly because Microsoft 365 device code phishing campaigns can abuse legitimate authentication workflows instead of relying on obviously malicious websites.

QR-code phishing also remained a notable threat despite declining from its March peak of 18.7 million attacks to 8.3 million in June.

Most QR lures arrived in attachments, and attackers shifted between PDF and Word files as they adapted their methods, a pattern also seen in sophisticated QR code phishing operations.

Microsoft’s disruption of the Tycoon2FA phishing service helped reduce activity connected to the platform by 92 percent from pre-disruption levels.

Rendered example of payroll diversion email used in this campaign (Source - Microsoft)
Rendered example of payroll diversion email used in this campaign (Source – Microsoft)

However, the broader threat did not disappear, as actors diversified delivery methods, used trusted services, and continued to test new infrastructure.

One automated business email compromise campaign reached more than 67,000 users at over 42,000 organizations in less than three hours.

It used impersonated executive messages, aging-report requests, and payroll-diversion lures to start conversations with recipients before making fraudulent financial requests.

Teams Vishing Activity Surges

Microsoft Teams has become an attractive channel because messages and calls can appear more trustworthy than an unexpected email.

Rendered sample of initial campaign email (Source - Microsoft)
Rendered sample of initial campaign email (Source – Microsoft)

During Q2, Teams phishing detections rose 19 percent from March to April and increased another 10 percent in June.

Vishing showed the steepest growth. Weekly malicious call attempts increased roughly 80 percent since the beginning of 2026 and reached nearly 10 times the mid-2025 baseline by late June, with most activity occurring on weekdays between 14:00 and 20:00 UTC.

Attackers commonly impersonate IT support staff and warn victims about a supposed account lockout or security issue.

They increasingly use generic display names instead of obvious help-desk labels, while their email addresses use software, scanning, update, or infrastructure-related wording to appear credible.

This approach can lead to remote-access abuse, credential theft, or malware execution.

In one reported incident, a Teams support impersonation call persuaded an employee to provide access through Quick Assist, illustrating why Teams support call compromise attempts require immediate verification through an approved internal channel.

Organizations should review email-protection settings, enable post-delivery message removal, and turn on link and attachment protections.

Source code of Financial_report.bat (Source - Microsoft)
Source code of Financial_report.bat (Source – Microsoft)

They should also use phishing awareness training, adopt phishing-resistant multifactor authentication for privileged accounts, restrict untrusted external Teams communications, and disable remote-support tools that are not operationally necessary.

Security teams should investigate unexpected Teams calls, unusual external chats, and suspicious requests to run remote-access tools.

Monitoring both identity activity and endpoint behavior is essential, especially as external collaboration features abused in vishing campaigns can bypass traditional email-focused controls.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
Domain9i6pokerdepot[.]comSending domain; DKIM-signed by the operator
Email addressCustomer.Service[@]9i6pokerdepot[.]comCampaign sender address
Domaint90141296286.p.clickup-attachments[.]comClickUp attachment subdomain hosting the stage 2 BAT dropper
URLhxxps://t90141296286.p.clickup-attachments[.]com/t90141296286/fb39c3a9-3161-40ad-847b-0683e0409d6f/Financial_report.batStage 2 BAT dropper download URL
URLhxxps://pixeldrain[.]com/api/file/3v92oJiLFinal installer payload download URL
File nameRe: Teams Archive Recording for {{DATE2}}.emlNested EML attachment template name
File nameFinancial_report.batStage 2 dropper batch file
Domainecajovna[.]skDomain used to send campaign emails
Domainilyff[.]comReply-to domain used to receive victim responses
Domainj-gmails[.]comReply-to domain used to receive victim responses
Domainx2mails[.]comReply-to domain used to receive victim responses
Email addresscontact[@]ecajovna[.]skAddress used to send campaign emails
Email addressmail[@]ilyff[.]comReply-to address
Email addressme[@]j-gmails[.]comReply-to address
Email addressme[@]x2mails[.]comReply-to address
Domaincompliance-protectionoutlook[.]deDomain hosting malicious campaign content
Domainacceptable-use-policy-calendly[.]deDomain hosting malicious campaign content
Domaincocinternal[.]comDomain hosting sender email address
Domaingadellinet[.]comDomain hosting sender email address
Domainharteprn[.]comDomain hosting sender email address
Email addresscocpostmaster[@]cocinternal[.]cmEmail address used to send campaign emails
Email addressnationaladmin[@]gadellinet[.]comEmail address used to send campaign emails
Email addressnationalintegrity[@]harteprn[.]comEmail address used to send campaign emails
Email addressm365premiumcommunications[@]cocinternal[.]comEmail address used to send campaign emails
Email addressdocumentviewer[@]na[.]businesshellosign[.]deEmail address used to send campaign emails
SHA-2565DB1ECBBB2C90C51D81BDA138D4300B90EA5EB2885CCE1BD921D692214AECBC6File hash of campaign PDF attachment
SHA-256B5A3346082AC566B4494E6175F1CD9873B64ABE6C902DB49BD4E8088876C9EADFile hash of campaign PDF attachment
SHA-25611420D6D693BF8B19195E6B98FEDD03B9BCBC770B6988BC64CB788BFABE1A49DFile hash of campaign PDF attachment

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you