Attackers Exploit Microsoft Teams Trust Through Voice Phishing Scheme
A cybercriminal operation known as 'Spring Ring' is targeting organisations that rely on Microsoft Teams, using voice phishing—or 'vishing'—to trick employees into granting attackers remote access to their sessions. Because Teams is widely trusted as an internal collaboration tool, victims may be more likely to let their guard down when contacted by someone posing as IT support or a colleague.
Once attackers gain a foothold, the campaign is designed to spread malware and potentially take over broader network infrastructure, not just individual accounts. This makes the threat particularly concerning for small and medium businesses that use Teams for day-to-day operations but may lack dedicated security teams to spot unusual remote access requests quickly.
The campaign highlights a growing trend of attackers combining social engineering with legitimate business software to bypass technical defences. Rather than relying solely on malicious links or attachments, these attacks exploit human trust in familiar platforms and voice communication, making staff awareness training as important as technical controls.