Weekly malicious call attempts through Microsoft Teams have grown roughly 80% since January, while email phishing volume declined over the same quarter.

 

What happened

Microsoft detected roughly 7.6 billion email-based phishing threats between April and June 2026, with monthly volume easing from 2.7 billion in April to 2.4 billion in June, according to its quarterly threat report published July 23. Voice phishing through Microsoft Teams moved the other way. Weekly malicious call attempts climbed 31% from April to May and another 27% into June, with the final two weeks of June producing the two highest weekly volumes on record. Attempts now run at nearly ten times the mid-2025 baseline. Teams-based phishing messages rose 19% from March to April and a further 10% into June.

 

Going deeper

More than half of Teams-based phishing attacks in June used generic display names rather than IT support branding, the second consecutive month above that threshold. The email addresses behind those chats have moved away from support-themed domains toward software-as-a-service terminology, scan and update language, and infrastructure keywords. The pretext itself has not changed, with callers still warning of an impending account lockout that only the help desk can resolve. Call activity concentrates between 14:00 and 20:00 UTC on weekdays and drops to almost nothing at weekends, which puts the calls in front of people who are logged in and working. Financial and executive impersonation, the staple of email fraud, barely appears in Teams attacks at all.

 

What was said

Teams traffic "typically bypasses secure email gateways," Microsoft Threat Intelligence and the Microsoft Defender Security Research Team wrote in the report, adding that a chat appearing to come from a colleague carries a legitimacy an unexpected email does not. The company recommended enabling zero-hour auto purge to retroactively remove messages already delivered, turning on Safe Links and Safe Attachments, scoping conditional access policies to require phishing-resistant multifactor authentication for privileged accounts, and running phishing simulations that include Teams messages rather than email alone.

 

In the know

Monthly message volume tied to the Tycoon2FA phishing service fell to 1.2 million by June, against a second-half 2025 average of 15.1 million. Microsoft's Digital Crimes Unit disrupted the operation in March, and the platform it detailed at the time has not recovered. Its share of CAPTCHA-gated phishing sites dropped from a December peak of 76% to 12%, and its share of QR code campaigns fell from 33% to 14%. Pushed off Cloudflare, the operators shifted more than 40% of newly observed domains to .RU registrations without regaining scale. No replacement service has emerged at comparable size, and QR code phishing overall fell from a March peak of 18.7 million attacks to 8.3 million in June.

 

The big picture

Attackers phoned a health system help desk from a local area code, posed as an employee in a revenue cycle role, and supplied the last four digits of that person's Social Security number and corporate ID to pass identity verification. Claiming a broken phone, they persuaded staff to enroll a new multifactor authentication device, then used the access to alter ACH details on payer accounts and redirect payments. The HHS Health Sector Cybersecurity Coordination Center documented that sequence in a sector alert on help desk social engineering, warning that AI voice impersonation makes remote identity verification harder and recommending callbacks to the number on record, supervisor confirmation, and in some hospitals an in-person visit for reset requests. Microsoft's data shows the same relationship being worked from the other direction, with attackers impersonating the help desk rather than calling it.

 

FAQs

Why does Teams traffic avoid email security controls?

Secure email gateways inspect messages traversing SMTP, while Teams chats and calls move over separate protocols inside the collaboration platform. Protection for Teams comes from different tooling, and organizations that assume their email security covers all internal communication often find the coverage gap only after an incident.

 

What is external Teams access and how is it restricted?

External access lets people outside the organization initiate chats and calls with internal users, which is what these attackers rely on. Administrators can disable it entirely, restrict it to an allowlist of partner domains, or block unmanaged consumer accounts, all configured in the Teams admin center.

 

Why are attackers moving toward generic display names?

Awareness training has taught staff to distrust anyone claiming to be IT support, so a name that makes no explicit claim avoids triggering that association while still allowing the caller to introduce themselves as support once the conversation starts.

 

What makes calendar invitations a growing delivery method?

Calendar files are processed differently from ordinary attachments and can place a link directly into a user's calendar without requiring them to open anything. Microsoft recorded these payloads nearly quadrupling in June, and the interaction model gives users less opportunity to assess the item before it appears.

 

Does disrupting one phishing platform reduce overall phishing?

In this case, it did, at least temporarily. QR code and CAPTCHA-gated phishing both fell alongside the disrupted platform's volume, and no competitor absorbed its customer base at similar scale. The effect is not permanent, since operators rebuild, but the data shows takedowns produce measurable reductions rather than only displacement.