Microsoft detects 7.6B email phishing threats, Teams vishing up 10x
Key Takeaways Microsoft detected 7.6 billion email phishing threats targeting businesses between April and June 2026. Credential theft remains the primary objective of these sophisticated phishing...
Key Takeaways
- Microsoft detected 7.6 billion email phishing threats targeting businesses between April and June 2026.
- Credential theft remains the primary objective of these sophisticated phishing campaigns.
- Vishing attacks via Microsoft Teams have surged tenfold since mid-2025, with a notable 80% increase in weekly malicious calls since early 2026.
- Attackers are increasingly leveraging trusted collaboration platforms like Teams and employing social engineering tactics, often impersonating IT support.
- Organizations must implement robust email and Teams security measures, including advanced threat protection, phishing-resistant MFA, and comprehensive user training to mitigate these evolving threats.
Email phishing continues to be a dominant initial access vector for cybercriminals aiming to compromise business accounts. Throughout the second quarter of 2026, threat actors persistently deployed deceptive login pages, weaponized attachments, and convincing business-themed messages to pilfer credentials or deliver malware.
Table Of Content
However, the threat landscape is expanding beyond traditional email. Adversaries are increasingly exploiting collaboration platforms, directly contacting employees via tools like Microsoft Teams. They often impersonate technical support, pressuring users to grant access, execute malicious tools, or navigate to fraudulent websites.
Analysts at Microsoft have observed a significant uptick in phishing activities across both email and Microsoft Teams, indicating a strategic shift by attackers to exploit multiple trusted workplace communication channels. This trend involves large-scale email campaigns combined with voice phishing, or vishing, specifically targeting employees during their active online hours. The sheer volume and human-centric nature of these attacks pose a substantial challenge for organizations, as successful compromises often hinge on exploiting human trust rather than technical vulnerabilities. A seemingly routine message or an unexpected call purporting to be from internal IT can be sufficient to initiate a costly security incident.
Microsoft said in a report shared with Cyber Security News (CSN) that it identified approximately 7.6 billion email-based phishing attempts from April to June 2026. While the monthly volume saw a slight decrease from 2.7 billion in April to 2.4 billion in June, credential theft remained the primary motivation behind these attacks.
7.6 Billion Email Phishing Threats as Teams Vishing Attacks
Credential phishing accounted for an overwhelming 94% to 96% of all payload-based attacks observed during the quarter. These campaigns typically lure victims to counterfeit sign-in portals or locally render cloned login screens, enabling attackers to capture credentials and potentially bypass standard account security measures.
HTML and PDF files were the most prevalent formats for delivering malicious payloads, collectively making up 60% to 70% of these attacks. Users are advised to exercise extreme caution with unexpected documents, especially given that certain Microsoft 365 device code phishing campaigns can exploit legitimate authentication processes, making them harder to detect than overtly malicious sites.
QR code phishing also remained a significant threat, despite a decrease from its peak of 18.7 million attacks in March to 8.3 million in June. Most QR code lures were embedded in attachments, with attackers frequently switching between PDF and Word formats to adapt their tactics, mirroring patterns observed in other sophisticated QR code phishing operations.
Microsoft’s successful disruption of the Tycoon2FA phishing service significantly reduced activity linked to that platform by 92% from its previous levels. However, the overall phishing threat persists as attackers quickly diversified their delivery methods, exploited trusted services, and continued to develop new infrastructure.
One particularly aggressive automated business email compromise (BEC) campaign impacted over 67,000 users across more than 42,000 organizations in under three hours. This campaign utilized executive impersonation, requests for aging reports, and payroll diversion schemes to initiate conversations with recipients, ultimately leading to fraudulent financial requests.
Teams Vishing Activity Surges
Microsoft Teams has emerged as an increasingly attractive attack vector due to the inherent trust users place in messages and calls received through the platform, which often appear more legitimate than unsolicited emails. During Q2 2026, Teams phishing detections increased by 19% from March to April, followed by another 10% rise in June.
Vishing, or voice phishing, has shown the most dramatic growth. Weekly malicious call attempts have surged by approximately 80% since the start of 2026, reaching nearly ten times the volume observed in mid-2025 by late June. The majority of this activity occurred on weekdays, between 14:00 and 20:00 UTC.
Attackers frequently impersonate IT support personnel, warning victims about fabricated account lockouts or security incidents. They are increasingly employing generic display names rather than obvious “help desk” labels, and their email addresses often contain terms related to software, scanning, updates, or infrastructure to enhance their credibility.
This type of social engineering can lead to unauthorized remote access, credential theft, or malware deployment. In a notable incident, a Teams support impersonation call successfully convinced an employee to grant access via Quick Assist, underscoring the critical need for immediate verification of any <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/1cab32dd-04d6-474a-a7ae-9858a5ba4fcd/Microsoft-Detects-7.6-Billion-Email-Phishing-Threats-as-Teams-Vishing-Attacks-Increases-10-Fold.pdf?AWSAccessKeyId=ASIA2F3EMEYEVBIRN3DL&Signature=YHxcyhaMM14vACJt5OUIpsU2UVw%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEDYaCXVzLWVhc3QtMSJGMEQCIEAB1KPkxH4aQA0hkIOwWwWdlVAZeYPSk2tNV6UAiAmlSVyxxZrauC5Z%2FNGeTDclMABXdoq%2Bl1jPzQkggaeuyr8BAj%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMSucfdP1OO41LVTPfKtAELahFwDS70%2FDYuQbZh9Zs8Lskj5oBX%2B5sXX4cwVasgNxXhmZUB2HqGTkYKQwJgpftyKiF52rDIeCriiWY8OLkUXEG1PGO8dm8gu3INCe6GcEBpx51q0feYP%2BQtuQpDpO5ODVutqQcmXoK4fyruXv42ki5pya%2BpNxfhLbxtdwZA%2BS896VNScB%2BdTgb8%2FjukNkRFQr6ZyPaLqs5guH9BHp%2BlHKIqAE6%2B7yATw6rCtNq47UPEodPnrNZovf645kBqOEKSDFO9aOir2aLPz1Sy6goYP4jwK7gNlCQ2rFJupsP6IB7n7QIOtKMVf1hsZ3wFDa6vhAB%2F9kEdXsQeyIo5Codrbl1vlMQQkY8FSBG06FbH0WVUGeDmKJ4Q%2BF46AHLd5IX9GNHYksl53oFFsxSMCF9%2BQB3Vaq%2Bb3k1SF1raWPeQJ58W71zRjQqSek78%2
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.