Key Takeaways
- Microsoft Teams emerged as a prominent social‑engineering channel in Q2, with attackers using it to build trust before stealing credentials or delivering malware.
- Teams‑based phishing volume rose steadily, increasing 19% from March to April, holding flat in May (+1%), and climbing another 10% in June.
- A highly automated Business Email Compromise (BEC) campaign reached over 67,000 users, leveraging scripted emails, Amazon Simple Email Service (SES), and engagement tracking.
- A separate phishing effort targeted 107,000 users by abusing Microsoft’s authentication flow and trusted cloud services—including Teams archive recordings and iCalendar (ICS) invites—to disguise malicious payloads.
- QR‑code and captcha‑based phishing attacks dropped sharply in the same period, while BEC activity spiked 121% between March and April before receding in May.
- The data illustrate that while phishing tactics evolve, core defensive principles—verification, least‑privilege access, and user awareness—remain critical.
Overview of Q2 Threat Landscape
During the second quarter of the year, threat actors continued to refine their social‑engineering techniques, shifting focus toward platforms that users perceive as trustworthy. Microsoft’s threat‑intelligence team observed a noticeable migration from traditional email‑only lures to collaborative tools such as Microsoft Teams, which many organizations have embedded deeply into daily workflows. This shift reflects attackers’ recognition that compromising a trusted collaboration channel can yield higher success rates than classic phishing, especially when victims are less suspicious of messages arriving inside a familiar interface.
Rise of Microsoft Teams as a Phishing Vector
Attackers began using Teams not merely as a conduit for malicious links but as a full‑blown social‑engineering channel. By initiating seemingly innocuous chats or meeting invitations, they cultivated rapport with targets, often posing as colleagues, IT support, or external partners. Once trust was established, the adversaries introduced credential‑harvesting pages, malicious file attachments, or links to compromised SharePoint sites. This approach leverages the inherent trust users place in Teams notifications, reducing the friction typically associated with suspicious email headers.
Quantitative Trends in Teams‑Based Phishing
Microsoft’s detection metrics showed a clear upward trajectory for Teams‑based phishing throughout Q2. In March, the baseline volume served as a reference point; by April, detected attacks had risen 19%, indicating a rapid adoption of the tactic by threat actors. The trend stabilized in May, with only a marginal 1% increase, suggesting a temporary plateau as attackers possibly refined their infrastructure or waited for optimal targeting windows. June saw another 10% climb, bringing the quarter‑over‑quarter growth to roughly 30% from the March baseline, underscoring the persistence and effectiveness of this channel.
Automated BEC Campaign at Scale
Parallel to the Teams phishing surge, Microsoft identified a highly automated Business Email Compromise (BEC) operation that contacted more than 67,000 distinct users. The campaign relied on pre‑written email templates that were dispatched via Amazon Simple Email Service (SES), allowing the attackers to send large volumes of messages with minimal manual intervention. Engagement tracking—such as open‑rate and click‑through monitoring—enabled the threat actors to refine their lures in near real‑time, focusing resources on the most responsive recipients.
Techniques Behind the Large‑Scale BEC Effort
The BEC campaign’s automation stemmed from a combination of off‑the‑shelf mailing services and custom scripts that personalized each message with the recipient’s name, department, or recent project references. By leveraging SES’s reputable sending infrastructure, the attackers bypassed many reputation‑based filters that traditionally block bulk spam. Additionally, the use of engagement tracking pixels let the operators gauge which subject lines or spoofed sender addresses yielded the highest interaction, allowing them to iteratively improve the campaign’s efficacy without exposing their core infrastructure.
Parallel Phishing Campaign Exploiting Microsoft Authentication Flow
A second, distinct phishing initiative targeted approximately 107,000 users by manipulating Microsoft’s authentication mechanisms. Rather than relying solely on credential‑harvesting pages, the attackers crafted requests that appeared to originate from legitimate Microsoft services, such as Office 365 login prompts or conditional access prompts. These messages often included spoofed security alerts or invitation to review documents, prompting users to re‑authenticate through attacker‑controlled proxies that captured session tokens or passwords.
Use of Trusted Cloud Services to Mask Malware
To further evade detection, the phishing campaign abused trusted cloud components embedded within the Microsoft ecosystem. Attackers embedded malicious payloads within Teams archive recordings or disguised them as iCalendar (ICS) meeting invites—both of which are routinely exchanged and considered low‑risk by security gateways. By hosting the malicious content on legitimate Microsoft domains (e.g., sharepoint.com, teams.microsoft.com) or leveraging trusted third‑party storage, the attackers reduced the likelihood that URL scanners or attachment sandboxes would flag the content as suspicious.
Decline of QR Code and Captcha‑Based Phishing
In contrast to the rise of Teams‑focused and BEC tactics, QR‑code and captcha‑based phishing schemes experienced a pronounced decline during Q2. Microsoft’s telemetry indicated a sharp drop in detections for these vectors, likely due to improved user awareness and the deployment of anti‑QR‑code scanning controls in mobile email clients. Captcha‑based attacks, which previously relied on presenting users with seemingly legitimate verification challenges, also fell as attackers shifted toward methods that required less user interaction and offered higher conversion rates.
Fluctuations in BEC Activity Across Q2
Business Email Compromise activity displayed a volatile pattern over the quarter. Between March and April, BEC incidents surged by 121%, reflecting the rapid rollout of the automated SES‑driven campaign described earlier. However, the metric dipped again in May, suggesting that either the attackers paused to reassess their targets, defenders successfully blocked a portion of the infrastructure, or the campaign’s initial burst exhausted its most vulnerable victim pool. This ebb and flow highlights the importance of continuous monitoring and adaptive defenses rather than relying on static threat assessments.
Implications for Defenders and Recommendations
The Q2 observations reinforce that while phishing techniques evolve, the fundamental defenders’ toolkit remains applicable. Organizations should:
- Enforce multi‑factor authentication (MFA) and conditional access policies that reject sign‑ins from untrusted locations or devices, even when the request appears to come from a trusted service like Teams.
- Deploy advanced threat‑protection capabilities that inspect collaboration platform traffic—such as Teams chat files, meeting recordings, and calendar attachments—for malicious content.
- Implement robust email authentication‑flow monitoring to detect anomalous token requests or impossible travel patterns indicative of credential‑theft proxies.
- Conduct regular user‑awareness training that covers emerging vectors, emphasizing that trust within internal collaboration tools does not guarantee message legitimacy.
- Leverage engagement‑tracking defenses—such as blocking known tracking pixels and disabling automatic image loading in email clients—to reduce attackers’ ability to refine campaigns in real time.
By aligning defenses with the observed trends—particularly the abuse of trusted services and the exploitation of familiar communication platforms—organizations can better mitigate the evolving risk posed by sophisticated, socially engineered attacks.

