
Palo Alto Networks researchers have found that hackers are posing as IT support on Microsoft Teams to target employees.
Attackers are turning Microsoft Teams help desk calls into an entry point for malware and network compromise. A campaign tracked as Spring Ring used external accounts that resembled internal IT support to chat with employees, then call them and press for remote access or software execution. The activity ran from January through April 2026 and approached more than 150 employees at no less than 10 organizations.
Its danger lies in the human element: a familiar sounding technician and a live conversation can make an unexpected request feel urgent and legitimate. Analysts at Unit 42 identified the operation after detecting suspicious chat creation across multiple Microsoft 365 tenants, uncovering 26 distinct attacker identities.
Palo Alto Networks said in their report that the group did not exploit a flaw in Teams. Instead, it abused external communication features, and the trust users place in workplace collaboration tools.
Spring Ring began with a one-to-one Teams chat from attacker-controlled onmicrosoft.com tenants. The accounts carried authoritative display names such as help desk, IT assistance, or support staff, while some used names of real people to make the contact appear more credible. After a chat request, the operator placed unsolicited voice calls, sometimes leaving voicemails and repeatedly trying different targets.
Successful conversations commonly lasted 10 to 15 minutes, giving the caller time to guide an employee through steps that would normally trigger suspicion in a written message.
Recently, 79 percent of U.S. office workers surveyed by Darktrace say they are confident they could spot a phishing email in their day-to-day work, in a test of realistic messages only 32 percent confidently identified an actual phishing attack. The findings suggest that established training approaches may be building confidence faster than real-world phishing readiness.
The challenge is not limited to employees. Darktrace’s research suggests security professionals are not strongly convinced that conventional security awareness training is keeping pace with modern phishing and vishing. While 58 percent of security professionals surveyed agree it is effective at preparing employees to identify these attempts, only six percent strongly agree, and just three percent say they see no limitations in conventional training.
Industry stakeholder offered the following thoughts following the release of these findings.
Mika Aalto, Co-Founder and CEO at Hoxhunt
"Phishing has escaped the inbox and spread across the entire corporate communications environment. Attackers now move between email, Teams, Slack, text messages, phone calls, and remote-access tools, with each interaction making the next one feel more credible.
"I’ve heard many CISOs voice growing concern that their help desks are being exposed to vishing calls and my concern is that they’re facing this new generation of attack without having practiced how to recognize or report them. Technology is evolving for malicious purposes, but attackers continue to target people because manipulating trust remains extraordinarily effective and profitable.
"I would not describe this as attackers choosing trust instead of technology. They are using trust to activate the technology for them. Spring Ring did not exploit a vulnerability in Microsoft Teams. The attackers persuaded employees to launch legitimate remote-support tools or execute software and then transitioned into malware delivery and an attempted identity attack.
"That fusion of social engineering and technical methods is what makes these campaigns dangerous. Organizations must treat collaboration platforms, remote-support workflows, and help-desk interactions as part of the attack surface. A familiar logo, an internal-sounding display name or a professional voice cannot be treated as proof of identity.
"The unit of detection must be the sequence, not the individual event. An external Teams chat, a voice call and the launch of Quick Assist might each look harmless in isolation. Together—especially when followed by PowerShell, an unfamiliar remote-management tool or unusual identity activity—they tell a very different story.
"There is, fortunately, a new generation of AI-enabled defense with Human Risk Management programs that consolidate human behavior signals to find and respond to risky patterns. On collaboration platforms, organizations should monitor new external identities, internal-sounding support names, repeated call attempts, and rapid movement from a chat request to a voice call.
"On endpoints, they should pay particular attention to unexpected launches of Quick Assist or other remote-management tools, PowerShell downloads, and unusual SMB or NTLM activity. Identity teams should treat password resets, MFA changes, device enrollment, and privileged-access requests made during unsolicited support interactions as high-risk events. Those signals need to be correlated rather than managed in separate queues.
"You cannot teach someone to handle vishing by showing them a slide about suspicious phone calls; at some point, the phone needs to ring. We need to rethink the entire concept and approach to awareness and evolve from explaining threats for compliance to safely rehearsing the behaviors that stop them."
Aviv Nahum, Co-founder and CEO at Above Security
"With AI, an attacker no longer needs to simply spoof a phone number or write a convincing email. They can increasingly reproduce someone’s voice, writing style and conversational patterns, and maintain that deception across multiple channels.
"That makes this fundamentally a trust problem. We’ve spent decades teaching people to recognize suspicious messages, but the traditional signals are disappearing. A message can sound like your boss, come with the right context, and even use a familiar voice. The security model therefore must shift from ‘does this look real?’ to ‘can I independently verify that this person is who they claim to be?’
"AI isn’t eliminating the human element of cybersecurity. It’s making it much easier to exploit it. The next generation of social engineering will be less about obviously fake phishing and vishing, and more about convincingly impersonating people we already trust – especially those in positions of authority like administrative officials or business executives.
Louis Eichenbaum, Federal CTO at ColorTokens
"Security awareness training helps; however, it will never eliminate a tactic that is designed around urgency, authority and trust. The more durable defense is a mandatory verification process: any unexpected approach, particularly from a new number or account, should be authenticated through a previously established channel before the conversation continues.
"Repeated incidents suggest the problem is not simply that individuals have failed to recognize a scam. Organizations have not yet made strong identity verification sufficiently routine and frictionless."





















