In the second quarter of 2026, Microsoft identified a significant escalation in phishing and vishing attacks targeting business accounts. Between April and June, the company detected approximately 7.6 billion email-based phishing threats, with credential theft being the primary objective. These campaigns often direct victims to counterfeit login pages or deploy malicious attachments to harvest sensitive information.
Notably, there was a marked increase in the use of collaboration tools like Microsoft Teams for vishing attacks. Attackers impersonated technical support staff, contacting employees directly to coerce them into sharing access credentials, executing harmful software, or visiting fraudulent websites. This tactic exploits the inherent trust in internal communication platforms, making it challenging for organizations to detect and prevent such intrusions.
The scale and sophistication of these attacks underscore the evolving nature of cyber threats. Organizations must adopt a multi-faceted approach to cybersecurity, combining advanced technological defenses with comprehensive employee training programs. By fostering a culture of vigilance and equipping staff with the knowledge to recognize and respond to phishing and vishing attempts, businesses can enhance their resilience against these pervasive threats.