Phishing is moving from email into Teams
Microsoft detected 7.6 billion email phishing threats in the second quarter of 2026. Tycoon2FA activity dropped 92 percent following a March disruption, but credential theft remains the primary objective, and HTML and PDF files were the most common malicious attachments. Business email compromise rose briefly in April, and attackers increasingly shifted to Microsoft Teams, where malicious voice-call attempts reached nearly ten times mid-2025 levels.
What this means for you if your staff use Teams
You have probably spent years teaching your staff to treat email with suspicion. Teams has not had the same attention. Our impression is that a call from an apparent colleague feels far more legitimate than a link in the inbox.
When attackers change channel, the risk follows them. The objective is still the same, namely credentials and access to finance functions. What differs is that your training and your technical controls have not kept pace. We would argue that the key point here is that the channel has moved faster than your defences.
Berigo recommends
- Restrict who outside the organisation can call and chat with staff in Teams, and disable external contact where there is no genuine need.
- Extend phishing training to cover voice calls and chat, not just email.
- Require phishing-resistant multi-factor authentication for all users and monitor changes to sign-in methods closely.
- Establish a fixed verification routine for payment changes that cannot be completed in the channel the request arrived through.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch