Cybersecurity Research

Voice Phishing Scam Uses Microsoft Teams to Break Into Business Networks

Unit 42 · 31 Aug 2026
Key Takeaway Train staff to verify unexpected IT or support requests received via Teams calls or messages through a separate, trusted channel before taking any action.

Researchers at Unit 42 have detailed a phishing campaign called Spring Ring that uses voice phishing, or 'vishing', through Microsoft Teams to trick employees into giving attackers access to their systems. Rather than relying solely on suspicious emails, attackers impersonate trusted contacts or IT support staff on Teams calls, using social engineering to convince victims to install malware or run malicious commands.

Once inside, the attackers aim to escalate their access and ultimately target domain controllers—the core systems that manage user accounts and permissions across a company's network. Compromising a domain controller can give attackers sweeping control, potentially affecting every device and account tied to that network, making this a serious risk for businesses of any size that rely on Microsoft Teams for communication.

This campaign highlights how attackers are increasingly using legitimate collaboration tools to bypass traditional email security filters. Because Teams is a trusted platform many employees use daily, requests that arrive through it can seem more credible than a typical phishing email, making staff awareness and verification processes critical defences.

phishing Microsoft Teams vishing social engineering malware

Summarised by CISO AI from Unit 42. We link back to every original so you can read it yourself.