Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold

Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold










Email phishing remains one of the most common ways attackers gain access to business accounts.

During the second quarter of 2026, criminals continued to use fake login pages, malicious attachments, and convincing business messages to steal credentials or deliver malware.

The problem is no longer limited to the inbox. Attackers are increasingly using collaboration tools to contact employees directly, posing as technical support staff and pressuring them to share access, run a tool, or visit a fraudulent site.

Microsoft analysts identified a sharp rise in phishing activity across email and Microsoft Teams, showing how attackers are moving between trusted workplace channels.

The activity combines high-volume email campaigns with voice phishing, also called vishing, that targets employees when they are active online.

The scale creates a serious challenge for organizations because many of these attacks rely on human trust rather than software flaws.

A message that looks routine, or a call that appears to come from internal IT, can be enough to start a costly compromise.

Microsoft said in a report shared with Cyber Security News (CSN) that it detected approximately 7.6 billion email-based phishing threats between April and June 2026.

Monthly volume fell slightly from 2.7 billion in April to 2.4 billion in June, but credential theft remained the main goal.

7.6 Billion Email Phishing Threats as Teams Vishing Attacks

Credential phishing made up 94 to 96 percent of malicious payload attacks observed during the quarter.

These campaigns typically direct victims to a fake sign-in page or load a copied login screen locally, allowing attackers to capture passwords and potentially bypass normal account controls.

HTML and PDF files were the most frequent delivery formats, together representing about 60 to 70 percent of payload-based attacks.

Users should remain cautious of unexpected documents, particularly because Microsoft 365 device code phishing campaigns can abuse legitimate authentication workflows instead of relying on obviously malicious websites.

QR-code phishing also remained a notable threat despite declining from its March peak of 18.7 million attacks to 8.3 million in June.

Most QR lures arrived in attachments, and attackers shifted between PDF and Word files as they adapted their methods, a pattern also seen in sophisticated QR code phishing operations.

Microsoft’s disruption of the Tycoon2FA phishing service helped reduce activity connected to the platform by 92 percent from pre-disruption levels.

Rendered example of payroll diversion email used in this campaign (Source - Microsoft)
Rendered example of payroll diversion email used in this campaign (Source – Microsoft)

However, the broader threat did not disappear, as actors diversified delivery methods, used trusted services, and continued to test new infrastructure.

One automated business email compromise campaign reached more than 67,000 users at over 42,000 organizations in less than three hours.

It used impersonated executive messages, aging-report requests, and payroll-diversion lures to start conversations with recipients before making fraudulent financial requests.

Teams Vishing Activity Surges

Microsoft Teams has become an attractive channel because messages and calls can appear more trustworthy than an unexpected email.

Rendered sample of initial campaign email (Source - Microsoft)
Rendered sample of initial campaign email (Source – Microsoft)

During Q2, Teams phishing detections rose 19 percent from March to April and increased another 10 percent in June.

Vishing showed the steepest growth. Weekly malicious call attempts increased roughly 80 percent since the beginning of 2026 and reached nearly 10 times the mid-2025 baseline by late June, with most activity occurring on weekdays between 14:00 and 20:00 UTC.

Attackers commonly impersonate IT support staff and warn victims about a supposed account lockout or security issue.

They increasingly use generic display names instead of obvious help-desk labels, while their email addresses use software, scanning, update, or infrastructure-related wording to appear credible.

This approach can lead to remote-access abuse, credential theft, or malware execution.

In one reported incident, a Teams support impersonation call persuaded an employee to provide access through Quick Assist, illustrating why Teams support call compromise attempts require immediate verification through an approved internal channel.

Organizations should review email-protection settings, enable post-delivery message removal, and turn on link and attachment protections.

Source code of Financial_report.bat (Source - Microsoft)
Source code of Financial_report.bat (Source – Microsoft)

They should also use phishing awareness training, adopt phishing-resistant multifactor authentication for privileged accounts, restrict untrusted external Teams communications, and disable remote-support tools that are not operationally necessary.

Security teams should investigate unexpected Teams calls, unusual external chats, and suspicious requests to run remote-access tools.

Monitoring both identity activity and endpoint behavior is essential, especially as external collaboration features abused in vishing campaigns can bypass traditional email-focused controls.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain 9i6pokerdepot[.]com Sending domain; DKIM-signed by the operator
Email address Customer.Service[@]9i6pokerdepot[.]com Campaign sender address
Domain t90141296286.p.clickup-attachments[.]com ClickUp attachment subdomain hosting the stage 2 BAT dropper
URL hxxps://t90141296286.p.clickup-attachments[.]com/t90141296286/fb39c3a9-3161-40ad-847b-0683e0409d6f/Financial_report.bat Stage 2 BAT dropper download URL
URL hxxps://pixeldrain[.]com/api/file/3v92oJiL Final installer payload download URL
File name Re: Teams Archive Recording for {{DATE2}}.eml Nested EML attachment template name
File name Financial_report.bat Stage 2 dropper batch file
Domain ecajovna[.]sk Domain used to send campaign emails
Domain ilyff[.]com Reply-to domain used to receive victim responses
Domain j-gmails[.]com Reply-to domain used to receive victim responses
Domain x2mails[.]com Reply-to domain used to receive victim responses
Email address contact[@]ecajovna[.]sk Address used to send campaign emails
Email address mail[@]ilyff[.]com Reply-to address
Email address me[@]j-gmails[.]com Reply-to address
Email address me[@]x2mails[.]com Reply-to address
Domain compliance-protectionoutlook[.]de Domain hosting malicious campaign content
Domain acceptable-use-policy-calendly[.]de Domain hosting malicious campaign content
Domain cocinternal[.]com Domain hosting sender email address
Domain gadellinet[.]com Domain hosting sender email address
Domain harteprn[.]com Domain hosting sender email address
Email address cocpostmaster[@]cocinternal[.]cm Email address used to send campaign emails
Email address nationaladmin[@]gadellinet[.]com Email address used to send campaign emails
Email address nationalintegrity[@]harteprn[.]com Email address used to send campaign emails
Email address m365premiumcommunications[@]cocinternal[.]com Email address used to send campaign emails
Email address documentviewer[@]na[.]businesshellosign[.]de Email address used to send campaign emails
SHA-256 5DB1ECBBB2C90C51D81BDA138D4300B90EA5EB2885CCE1BD921D692214AECBC6 File hash of campaign PDF attachment
SHA-256 B5A3346082AC566B4494E6175F1CD9873B64ABE6C902DB49BD4E8088876C9EAD File hash of campaign PDF attachment
SHA-256 11420D6D693BF8B19195E6B98FEDD03B9BCBC770B6988BC64CB788BFABE1A49D File hash of campaign PDF attachment

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

The post Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold appeared first on Cyber Security News.






Tushar Subhra Dutta





Go to cyber-security-news





Posted

in

, ,

by