Teams Vishing Rose 502% in a Year. Here Is the Simulation That Tests It.

Categories: Deepfake,Published On: October 9th, 2026,
  • Breacher.ai banner reading Teams Vishing, showing an incoming external Teams call from IT Service Desk whose voice waveform stops at a green verification boundary.
Threat Research

Teams Vishing Rose 502% in a Year. Here Is the Simulation That Tests It.

Microsoft’s 2026 Digital Defense Report puts confirmed malicious Teams vishing up 502% year over year. We checked the numbers, broke down the call, and walk through a sample Teams vishing simulation that tests the one thing that matters: whether your verification step fires.

The message came from inside Teams. The verification has to come from outside it.

See a Teams vishing simulation run against your own help desk procedure.

Book Your Demo

What is Teams vishing?

Definition

Teams vishing is voice phishing delivered through Microsoft Teams. An adversary contacts an employee from an external tenant, usually as IT support or the help desk, opens with a chat, then moves to a Teams voice call to talk the target into a consequential action such as a remote support session, an MFA reset or a code read back.

We run this exact scenario as an authorized simulation for enterprise clients, with AI voice agents that hold a live two-way conversation. So when Microsoft published its 2026 Digital Defense Report on October 1 and a summary of it started circulating with a headline number for Teams vishing, we did what we would want any vendor to do before building an argument on a statistic. We went to the source.

The number holds. What it measures matters more than how big it is.

What the Microsoft Digital Defense Report 2026 found on Teams vishing

The report covers July 2025 to June 2026 and draws on what Microsoft describes as more than 165 trillion security signals a day. Three figures frame the Teams vishing picture, and they come from two different Microsoft publications, which is worth keeping straight.

502%

Year-over-year rise in confirmed malicious voice phishing over cross-tenant Microsoft Teams calls.

Microsoft Digital Defense Report 2026, July 2025 to June 2026
93%

Share of the voice phishing attacks Microsoft observed that kept the target on the line long enough for social engineering to begin.

Microsoft Digital Defense Report 2026, key figures
~10x

Weekly malicious Teams call attempts by the end of June 2026, measured against the mid-2025 baseline.

Microsoft email threat landscape, Q2 2026

The 502% and the roughly tenfold figure are not the same measurement. One is confirmed malicious activity year over year in the annual report. The other is weekly call attempts in a quarterly report. Both point the same direction, and neither should be added to the other. Microsoft also does not publish the absolute count behind the 502%, so it describes growth in what Microsoft’s telemetry confirmed, not a count of victims or a success rate.

That last point is not a weakness of the finding. It is the reason to test. A global growth rate tells you the channel is moving. It cannot tell you whether your help desk procedure holds when the call arrives.

We checked the summary that went viral

A community summary of the report shared widely on r/cybersecurity listed five headline findings. Here is how each one stands against Microsoft’s own published material.

Fact check

Five claims from the circulating summary, checked against Microsoft’s published report page, blog and quarterly data.

Claim in the summaryWhat Microsoft publishedStatus
Teams vishing up 502% YoYConfirmed malicious voice phishing over cross-tenant Teams calls rose 502% year over year.Verified
ClickFix grew 8x in four monthsReported as more than 1.1 million unique devices between February and early May 2026, roughly an eightfold rise.Supported
Sessions over malwareBetween 89% and 95% of email phishing attachments led to a credential theft effort. Some summaries round the top of that range to 96%.Verified, use 89 to 95
AI agents bring identity and trust problemsAgent identity, scoped credentials, least privilege and revocation are a full section of the report.Verified
Patch velocity matters moreThe report says the median time from vulnerability discovery to weaponization has fallen below 24 hours.Verified

Green: matches Microsoft’s published figures. Amber: accurate, with a rounding difference worth correcting before you quote it.

The summary’s closing takeaway also holds up: AI is accelerating the adversary, but the intrusions still run through familiar weaknesses. Microsoft’s own framing is that the underlying methods often remain familiar while speed and scale change. Teams vishing is the clearest example in the whole report. Nothing about it is technically novel. It is a help desk phone call, moved onto a channel people trust more than email.

Why Teams vishing works: the channel feels internal

Email took thirty years to harden. Secure email gateways, external sender banners, sandboxed attachments and a well-drilled report button all sit between an unexpected email and an employee. A Teams call from an external tenant passes through none of them, and it lands in the tool employees use to talk to their own colleagues.

Microsoft’s Q2 2026 data adds a detail that changes how defenders should think about the call. The share of Teams phishing attacks using a help desk persona rose from 22% in April to 31% in June 2026, and by June more than half of Teams phishing attacks used generic display names rather than any branding at all. Financial and executive impersonation, the staple of email fraud, has been largely absent from Teams.

In other words, the adversary is not investing in a perfect disguise. A plain name and a routine help desk request are enough, because the request fits a workflow the employee already trusts. That is exactly the pattern we described as synthetic normalization: plausibility beats fidelity. The call does not need to sound perfect. It only needs to make sense.

Anatomy of a Teams vishing call

Microsoft’s Detection and Response Team published a full case in March 2026 in which a compromise began with a Teams voice phishing interaction from an adversary impersonating IT support. Combined with the report data, the sequence looks like this.

01

Pressure first

The effective version opens with a visible, annoying problem, often a mailbox flooded with sign-up confirmations, so that help arriving a few minutes later feels like relief rather than an interruption.

02

A chat from outside the tenant

Contact arrives from an external Microsoft 365 tenant the adversary controls, under a display name such as IT Service Desk. The display name is a string the sender chose. Nothing about it was verified.

04

The consequential action

The ask is routine for a real help desk: open Quick Assist or another remote support tool, approve an MFA prompt, read back a code, or install a utility. Microsoft’s incident responders traced a full compromise to exactly this kind of support call.

05

Foothold to persistence

Once a remote session is open, the adversary typically installs an unsanctioned remote management agent and begins reconnaissance. Microsoft describes that agent as one of the most reliable mid-stage signs of a human-operated intrusion.

Stage four is the one to design around. Every stage before it is the adversary building pressure. Stage four is the moment your procedure is supposed to fire, and it is the moment a simulation should measure.

A sample Teams vishing simulation

This is the part we can show rather than describe. Our public Teams phishing simulation sample lets you experience the channel mechanics directly: a message arrives in Teams from a familiar-looking persona, escalates to a call, and a failed interaction triggers a short targeted training module on the spot. The sample uses an executive persona because it makes the channel easy to see in a few seconds.

Microsoft’s data says the persona adversaries are actually leaning on in Teams is the help desk. So that is the scenario we recommend running first, and it is the one we run as a standalone Microsoft Teams impersonation simulation against a client’s real tenant. Here is a sample run.

Sample run · IT Service Desk over Teams

Every line below is simulated. The run stops at the dashed line, before any session exists.

IT Service DeskEXTERNAL

Chat · 09:41Hi, this is the Service Desk. We can see your mailbox is being flooded with sign-up emails. We are applying a filter now.

Chat · 09:42I will give you a quick call on Teams to finish it. Two minutes.

Teams voice call · AI voice agent, live two-wayThanks for picking up. I just need to apply the filter on your machine. Can you open Quick Assist and read me the code?

The consequential actionRemote support session requested by an inbound, unverified external contact.

VERIFICATION BOUNDARY · SIMULATION STOPS
Recorded outcomeWhat it meansFinding
Verified out of bandProcedure held: confirmed through the real ticket portal or the published service desk numberHolds
Verified inside TeamsA check ran, but on a channel the caller supplied, such as a number dropped in the chatDefeated check
SkippedThe action was agreed without any verificationException
No step writtenNo verification requirement exists for a support request arriving over TeamsCoverage gap

Each outcome is resolved against the client’s ticketing and call records and named against the procedure, never against the person.

The second row is why we deliberately offer the target a way to check us. If the only possible outcomes are comply or refuse, a simulation cannot see a procedure that ran and was defeated, which is one of the most common real-world failures there is. Out-of-band verification means a channel the requester did not supply. Inside Teams, every channel the employee reaches for first was supplied by the caller.

Want to see this sample run against your own tenant and your own written procedure? That is the engagement.

Book Your Demo

Why spotting the fake is not the control

The instinctive response to a 502% headline is more awareness training: teach people to recognize a suspicious Teams call. Awareness of the threat matters, and Microsoft’s own guidance is to change behavior. The question is which behavior.

Asking people to detect a fake caller by ear is a decaying control. Voice generation improves on the adversary’s schedule, and as the Q2 data shows, the adversary on Teams does not even need a convincing voice. A verification procedure does not have that problem. A callback to the published service desk number returns the same answer whether the caller is a person, a crude bot or a flawless clone. It does not evaluate the voice at all.

That is also why technical controls belong in the same plan, not in opposition to it. Narrowing external access, keeping external warnings on, allowlisting remote tools and turning on Teams protection in Defender for Office 365 all reduce how often the call reaches anyone. The procedure is what holds when one does. A good Teams vishing simulation tests both layers in one run: whether the call could reach your people, and whether the step fired when it did.

Precise about the claim. A convincing call does not break a verification step, but it does raise the pressure to wave the step through. That is why we measure how often a required check is skipped or satisfied on the wrong channel, rather than claiming any procedure is unbreakable.

What to measure after a Teams vishing simulation

Click rate does not exist in this channel. There is no link. These are the three numbers that tell a security leader whether the Teams path is covered.

COVERAGE

Does a written step exist for Teams?

Most organizations verify outbound wires and nothing that arrives over Teams. Coverage can be assessed before a single call is placed.

PROCESS HOLD RATE

Did the step fire under pressure?

Verification executed through an independent channel, over verification required. This replaces click rate as the headline.

EXCEPTION RATE

How often was it waived or rerouted?

Checks skipped, or satisfied inside Teams on a channel the caller supplied. This is the number that moves as the calls get better.

What to do about Teams vishing this week

Every step below is free to start and works whether the next Microsoft report shows the curve flattening or doubling again.

01

Narrow Teams external access

Move external access from open to an allowlist of the partner domains you actually work with, and block unmanaged and consumer accounts separately. Microsoft’s own incident responders lead with this recommendation. It shrinks who can reach your people before any human judgment is involved.

02

Publish the help desk never-list

Tell every employee, in one sentence, what your service desk will never do: start a remote session from an unsolicited Teams chat or call, ask for an MFA approval, or ask for a code read back. A short never-list turns a judgment call into a boundary.

04

Allow remote tools only through endpoint policy

Permit only the remote support and management tools your IT team actually uses, enforced by endpoint policy rather than user discretion. If the phone leg succeeds, this is the control that stops the session from becoming a foothold.

05

Simulate the voice leg, not only the message

A Teams message test tells you who reads a suspicious chat. A Teams vishing simulation tells you whether the verification step fires when a live voice is applying pressure. Test the call, and test the inbound callback.

How Breacher.ai runs Teams vishing simulations

Breacher.ai was built for the channel shift this report describes. The OSES™ engine runs authorized, fully automated, orchestrated simulations across email, voice, Teams and video, with AI voice agents that hold a live two-way conversation and handle the inbound callback. Orchestration means the second stage changes based on what the target did in the first, which is exactly how the Teams sequence above unfolds in the wild. Few platforms can run that sequence end to end.

For teams that want a single scoped test, the Teams impersonation simulation runs as a one-off engagement with no platform commitment. For ongoing programs, the simulation platform covers voice through AI vishing simulation and help desk impersonation, and the add-on for Microsoft Attack Simulation Training layers AI voice and deepfake video on top of the Teams message simulations you may already run, currently as a free beta.

Every finding is named against the procedure that failed. The Secure Behavior Management platform then generates training on that exact procedure in minutes, from your own policies and in any language, and the re-test runs against the same control so you can show it holds better than last quarter. For what these calls look like at scale, see our AI vishing field findings and the remote support simulation breakdown.

Your people are not the weak point in this story. They are being helpful on a platform built for collaboration. Give them a procedure that holds no matter who appears to be calling.

The caller keeps getting better.
The callback does not have to.

Thirty minutes. We will show you the Teams vishing sequence, the outcomes it records, and the training it generates from what it finds.

Book Your Demo

Frequently asked questions

Teams vishing is voice phishing delivered through Microsoft Teams. An adversary contacts an employee from an external tenant, usually as IT support or the help desk, opens with a chat, then moves to a Teams voice call to talk the target into a consequential action such as starting a remote support session, resetting MFA or reading back a code.

Sources

JT

Jason ThatcherFounder and CEO of Breacher.ai and creator of OSES™. Fifteen years in security operations and offensive testing, previously at ZeroFox, Deepwatch, and GuidePoint Security. He builds and runs orchestrated social engineering simulations against enterprise organizations.

Find Out If Your Help Desk Procedure Holds on Teams

Bring the request you worry about most, a remote session, an MFA reset or a password change arriving over Teams, and we will show you how we would test it and how the re-test proves the procedure holds.

Book Your Demo

Latest Posts

  • Teams Vishing Rose 502% in a Year. Here Is the Simulation That Tests It.

  • Synthetic Normalization: When Sounding Like AI Stops Being a Warning Sign

  • Top 3 Emerging AI Social Engineering Risks for 2027: Voice Phishing, AI Voice Agents and Deepfakes

Table Of Contents

About the Author: Jason Thatcher

Jason Thatcher is the Founder of Breacher.ai and comes from a long career of working in the Cybersecurity Industry. His past accomplishments include winning Splunk Solution of the Year in 2022 for Security Operations.

Share this post