Fake IT Support Calls on Microsoft Teams Breached 150 Employees

IT support vishing voice phishing https://pixabay.com/illustrations/ai-generated-sound-wave-audio-8061338/

A recent publication from Palo Alto Networks’ Unit 42 research team offers insight into Microsoft Teams voice phishing (vishing) campaigns. This activity, dubbed Spring Ring, ran from January through April 2026 and was discovered based on alerts from a newly-released detection suite for Teams. Over 150 employees in at least 10 companies were targeted and approached by fake help desk identities abusing legitimate external chat features. This campaign did not require exploitation of any vulnerabilities in Microsoft Teams; rather, it turned a trusted platform into an entry point for threat actors.

How Unit 42 Spotted the Pattern

After monitoring the new Teams detection suite, Unit 42 looked into suspicious chat creation activity that was flagged across multiple Microsoft 365 tenants. The investigation traced the activity back to 26 distinct attacker identities mimicking legitimate internal support actors. The attackers contacted the targets through an external Teams chat request, relying on the deception of posing as IT support to entice victims to accept the request.

Through the investigation, certain behavioral patterns emerged, including rapid transitions from chatting to calling and source IP addresses masked by VPNs. The attackers were able to cycle through five or more targets within only minutes using a single spoofed identity.

The Illusion of Internal Support

The attacker identities were designed to appear like legitimate support, using authoritative names like “help desk” or “IT assistance” to deceive targets. Some of the personas built by the attackers borrowed real employee names to boost credibility further. The attacks showed a pattern of persistent calls with missed attempts, voicemails, and repeated redials. Successful calls lasted for an average of about 10 to 15 minutes, just enough time to guide a victim step by step through the attack.

The use of Microsoft Teams and the guise of legitimate support helped to bypass threat detection technology and give victims a false sense of security. “Phishing has escaped the inbox and spread across the entire corporate communications environment,” says Mika Aalto, Co-Founder and CEO at Hoxhunt, a Helsinki-based Human Risk Management Platform. “Attackers now move between email, Teams, Slack, text messages, phone calls, and remote-access tools, with each interaction making the next one feel more credible.”

Two Campaigns from the Same Lure

Using the same initial entry point of Microsoft Teams vishing, the Spring Ring attackers carried out two separate campaigns. The first campaign uncovered by Unit 42 used this vishing deception to guide victims to run legitimate remote monitoring and management (RMM) tools already on the target system. The attacker requested remote control of the target’s device and then pivoted to downloading an obfuscated PowerShell remote access Trojan (RAT) from an attacker-controlled domain.

The second campaign lured targets to a tailored cloud link disguised with their own company and username to increase trust. Clicking the link downloaded an executable file that triggered a chain from staging and persistence mechanisms all the way to browser hijacking and lateral movement. This second campaign escalated to an NTLM relay attempt against the organization’s domain controller and exploitation of PetitPotam to grant domain-level privileges to the threat actor. Both of these campaigns were blocked at different stages, but only after crossing over from social engineering into active intrusion.

The Gap in Training Confidence

Phishing variants and other social engineering tactics have pervaded the threat landscape for decades and continue to be significant vectors for attack. Even the most advanced technological solutions can only go so far in protecting against malicious activity that exploits human error and psychology. In research conducted by Darktrace, four out of five surveyed office workers stated that they felt confident spotting phishing, whereas only 32% were able to catch a realistic test attempt. Only 2% of security professionals say they see no limitations to conventional security awareness training.

Research from Fortinet shows that two thirds (67%) of organizations report fewer security incidents after security awareness training, but only a little more than half (53%) directly measure the connection. These statistics suggest that confidence is scaling faster than actual detection ability, especially for voice-based lures.

Identity is the New Perimeter

These Microsoft Teams campaigns reflect a broader shift from email phishing toward collaboration-platform social engineering. Maintaining effective defenses against these attacks demands behavioral and identity anomaly detection rather than simple detection of malware signatures. Employee training and education must extend beyond suspicious links in emails to explicitly cover unsolicited voice contact. As software-as-a-service (SaaS) platforms increasingly become both a target for attacks and a weapon used by attackers, it is essential to monitor places where employee trust is implicit.

Author
  • Contributing Writer, Security Buzz
    PJ Bradley is a writer from southeast Michigan with a Bachelor's degree in history from Oakland University. She has a background in school-age care and experience tutoring college history students.