Microsoft’s Q2 2026 Email Threat Landscape report, published July 23, delivered a striking pair of numbers: phishing tied to the Tycoon2FA platform collapsed 92% after a takedown operation, while weekly malicious Microsoft Teams call attempts are now running at nearly ten times their mid-2025 baseline. Weekly Teams vishing rose 31% from April to May, another 27% into June — up roughly 80% since the start of 2026.
The channel your clients spent fifteen years hardening got quieter. The one they never hardened just became attackers’ preferred front door.
Why Teams is the perfect vishing surface
Voice phishing isn’t new. Voice phishing inside a trusted collaboration platform is. When an employee sees a Teams call from “IT Support,” the interface itself implies trust — even though Teams external access and federation are often still whatever the tenant shipped with, meaning outside organizations can initiate calls by default.
Attackers have industrialized the tactic. In June 2026, 52% of Teams-based phishing attacks used generic display names — not the obvious “IT Support” your training taught users to spot. The employee who would never click a suspicious link is materially more likely to answer a call and act on what the caller says. Wire authorization, account changes, loan file access, password resets — all one persuasive conversation away. And voice calls bypass Defender for Office 365, Safe Links, and every email filter you’ve bought. There is no automated protection against a convincing voice.
The playbook: from Teams call to full compromise
Microsoft’s Detection and Response Team (DART) documented the canonical attack chain in March: attacker impersonates IT support over Teams, calls multiple employees until one grants remote access through Quick Assist, then pivots to a spoofed credential page and MSI-based DLL sideloading — all using legitimate Windows mechanisms that don’t trip antivirus.
The tactic isn’t confined to one actor. Since Microsoft first documented Storm-1811 (initial-access broker for Black Basta ransomware) abusing Teams and Quick Assist in mid-2024, the playbook has spread: Sophos tracked STAC4749 hitting dozens of North American orgs with .top-domain helpdesk personas that ended in Chaos ransomware; Zscaler ThreatLabz documented a GoGRPC backdoor cluster running Teams-vishing initial access January–June 2026; and Rapid7 traced Iran-linked MuddyWater using external Teams chats and screen-sharing before deploying DWAgent and AnyDesk.
The pattern rhymes every time: one voice call, one Quick Assist session, one credential capture — and the attacker is inside your client’s tenant with a legitimate identity, blending into normal activity.
Why this matters extra for MSPs
You know the multi-tenant argument from our recent alerts on Warlock’s Zoho Assist abuse and the Arista VeloCloud zero-day. Teams vishing hits MSPs harder for three specific reasons: client tenants are usually shipped with external access, federation, and Quick Assist enabled by default; the lure impersonates the exact interaction pattern MSPs train users to trust (“IT is calling about a ticket”) — your brand of legitimacy is the attack vector; and the FBI’s IC3 recorded $3.05 billion in BEC losses across 24,768 complaints in 2025, part of $20.88 billion in total reported cyber losses (up 26% YoY). Vishing shortens the path from “someone answered” to “wire sent.”
Regulated clients — banks, credit unions, mortgage, healthcare, defense contractors — will face examiner questions this cycle on whether collaboration-platform threats are in their monitoring scope. That’s a productizable engagement waiting to be sold.
What to do this quarter
Three buckets. Sell them together.
Lock down the front door. In Teams Admin Center → External Access, restrict which domains can initiate chats and calls — move from open federation to an explicit partner allowlist. Block Quick Assist for standard users via Intune (use Remote Help instead, which authenticates and audits). Enforce phishing-resistant MFA — passkeys, FIDO2, Windows Hello — via Conditional Access on every privileged and finance-adjacent account. Push-based MFA won’t survive an adversary-in-the-middle site.
Instrument the aftermath. The call itself may leave no signal, but the Quick Assist session, unusual sign-in, and PowerShell staging in AppData\Roaming all do. Correlate Defender for Endpoint and Entra ID signals in one place. When Entra flags a risky sign-in, automate revocation via the Microsoft Graph API — kill sessions, invalidate refresh tokens, pair with continuous access evaluation. A BEC campaign that reached 67,000 users in under three hours won’t wait for a human analyst. Put Purview data-loss policies on any document or message that changes payment instructions.
Retrain against the current lure. Update awareness to cover unexpected internal-looking calls and generic display names — not just “IT Support” spoofs. Add a Teams vishing scenario to the next simulation. Publish one blunt client-side rule: no remote-support tool gets launched from a call the user didn’t initiate. Ever.
None of this is exotic. It’s Teams hygiene, identity governance, and monitoring scope — mapped cleanly to CIS Controls, NIST CSF 2.0, and the identity requirements inside CMMC, HIPAA, GLBA, and PCI. Frame it that way when you price it.
Bottom line
Email got measurably safer this quarter. That is not a reason to reallocate budget away from it — it’s the reason attackers moved. Teams vishing is a machine-generated, ransomware-adjacent, examiner-visible threat your email stack cannot see, and your clients’ users are pre-trained to trust it.
MSPs that pitch a Teams & Collaboration Hardening Assessment before the first client wire disappears own the next twelve months of this conversation. The ones who don’t will explain to a board why the call came from inside the tenant.
FAQ
Q: What is Teams vishing?
A: Teams vishing is voice phishing conducted through Microsoft Teams calls, typically by an attacker impersonating IT support, a helpdesk agent, or a colleague. Because the call arrives inside a trusted collaboration platform — and Teams external access is often open by default — users are far more likely to answer and act on it than they would a suspicious email.
Q: Why is Teams vishing rising so fast in 2026?
A: Two reasons. First, a coordinated takedown of the Tycoon2FA phishing-as-a-service platform in March 2026 knocked email phishing down 92%, pushing threat actors toward the next-easiest channel. Second, Teams calls bypass every email security control an organization owns — Defender for Office 365, Safe Links, secure email gateways — so they scale cheaply against modern defenses.
Q: Which threat actors use Teams vishing?
A: Documented actors include Storm-1811 (Black Basta ransomware initial access), STAC4749 (Chaos ransomware), a GoGRPC-linked initial-access-broker cluster tracked by Zscaler, and Iran-linked MuddyWater. The tactic has become a shared playbook across ransomware affiliates and state-sponsored groups.
Q: How do attackers get in through a Teams call?
A: The dominant pattern: attacker calls a user posing as IT support, convinces them to launch Microsoft Quick Assist (or an alternative RMM tool like RemSupp, DWAgent, or AnyDesk), captures credentials on a spoofed login page, and drops PowerShell-staged malware from a user-writable directory like AppData\Roaming. From there they pivot to lateral movement, data exfiltration, and often ransomware.
Q: What’s the fastest way for an MSP to reduce a client’s Teams vishing risk?
A: Three moves close most of the gap: (1) restrict Teams external access to an explicit partner allowlist, (2) block Quick Assist for standard users via Intune and adopt Remote Help instead, and (3) enforce phishing-resistant MFA (passkeys or FIDO2) on all privileged and finance-adjacent accounts via Conditional Access. Then add Teams voice scenarios to security awareness training.
Q: Does compliance require action on Teams vishing?
A: Not by name in most frameworks yet, but the underlying controls already do. NIST CSF 2.0, CIS Controls v8.1, CMMC Level 2, GLBA Safeguards Rule, HIPAA Security Rule, and PCI DSS 4.0 all require documented external-access controls, identity threat monitoring, and security awareness that reflects current attacker technique. Examiners are asking about collaboration-platform monitoring scope this cycle.