For years, security teams trained employees to distrust suspicious emails: strange sender addresses, sloppy grammar, a link that doesn't quite match the domain it claims to come from. A new campaign uncovered by Palo Alto Networks' Unit 42 shows how thoroughly that playbook has been outflanked. Attackers didn't need to break into Microsoft Teams; they just needed someone to pick up the phone.
Unit 42 has disclosed a coordinated social engineering operation it calls Spring Ring, active from January through April 2026. The campaign used Microsoft Teams accounts external to the victim organizations to impersonate IT help desk staff, and it approached more than 150 employees across at least 10 companies spanning multiple industries. Analysts identified 26 distinct attacker identities behind the operation after spotting a pattern of suspicious chat creation across multiple Microsoft 365 tenants.
Critically, Palo Alto Networks was clear that this wasn't a Teams vulnerability. The attackers abused a legitimate feature—Teams' default "Chat with Anyone" setting, which permits direct messages from users outside an organization—combined with the baseline trust employees place in workplace collaboration tools.
The attack chain looked like this:
-
The chat – An attacker-controlled .onmicrosoft.com tenant, carrying a display name like "help desk," "IT assistance," or "support staff" (and in some cases the name of a real employee), opens a one-to-one Teams chat with a target.
-
The call – After the chat, the operator places an unsolicited voice call—sometimes leaving voicemails, sometimes trying multiple employees before finding someone who picks up. Successful conversations ran 10 to 15 minutes, long enough for a "technician" to talk a victim through steps that would raise red flags in writing.
-
The ask – The caller pushes for remote access or execution of software framed as urgent IT troubleshooting.
From there, Unit 42 tracked two distinct follow-on paths. In one, victims were coerced into launching legitimate remote monitoring and management (RMM) tools, such as Windows Quick Assist, or an obfuscated PowerShell-based remote access trojan (RAT) that disabled anti-malware scanning and beaconed out to attacker infrastructure.
In the other, victims were directed to tailored, cloud-hosted executables that hijacked Microsoft Edge and used Python-based lateral movement, ultimately attempting a PetitPotam-style NTLM relay attack against a domain controller—a technique aimed at full domain compromise. Both intrusion attempts were caught and blocked before the attackers reached their objective, according to Unit 42.
This is a meaningfully different animal from earlier Teams-based campaigns. Prior operations attributed to groups like Cloaked Ursa (APT29) leaned on credential harvesting through malicious links and spoofed Entra ID tenants. Spring Ring skips the fake login page almost entirely; the external Teams identity and the live voice call are the lure. As Unit 42 put it, the operation represents the weaponization of communication platforms as identity becomes a primary attack vector.
The scale of the shift shows up in Palo Alto Networks' own telemetry: phishing alerts originating from collaboration tools accounted for 42% of all phishing alerts detected in Cortex during the first four months of 2026, up from 30% in the preceding four months. Separate reporting from KnowBe4 found Teams-based attacks specifically rose 41% between October 2025 and March 2026, a trend also tied to abuse of that same external-chat default.
[RELATED: Collaboration Catastrophe: Teams Flaws Expose the Crisis of Trust]
Why a phone call beats an email
Email phishing defenses have matured around a specific set of tells: sender domain, embedded links, banner warnings, grammar. Vishing sidesteps nearly all of it. There's no link to hover over, no header to inspect, no static artifact for a filter to catch. It's a real-time, unrecorded, undocumented conversation with a person who sounds confident and knows enough workplace jargon to seem legitimate.
That gap between how confident people feel about spotting phishing and how well they actually perform is exactly what recent Darktrace research measured. In a survey of U.S. office workers, 79% said they were confident they could spot a phishing email in their day-to-day work. But when tested against a set of realistic messages, only 32% correctly and confidently identified the actual phishing attempt. The gap extends to the people running security programs, too: while 58% of security professionals surveyed agreed that conventional security awareness training effectively prepares employees for phishing and vishing, only 6% strongly agreed, and just 3% said they saw no limitations in how that training is currently working.
Fortinet's Security Awareness and Training Global Research Report adds useful context on where organizations are putting their attention and how they're measuring results. Respondents ranked data security as the most important training topic (51%), followed by data privacy (43%) and AI-based tools and threats (41%).
On outcomes, 67% of organizations reported moderate or significant reductions in intrusions, incidents, and breaches since implementing awareness training, and 53% said they measure that effectiveness by tracking reduced security incidents specifically (employee feedback and security audits were the next most common measures, at 52% and 50% respectively). Confidence in the underlying premise runs high: 95% of decision-makers said more security awareness would help reduce cyberattacks.
Put those two data sets side by side and a tension emerges. Organizations broadly believe training works and are investing accordingly, yet the same populations behind that investment aren't confident it's kept pace with a threat that now happens over a live phone call rather than a static message sitting in an inbox.
What security leaders are saying
We asked several vishing and security awareness experts to weigh in on the Unit 42 findings.
Mika Aalto, Co-Founder and CEO at Hoxhunt, framed Spring Ring as evidence that phishing has outgrown the inbox entirely: "Phishing has escaped the inbox and spread across the entire corporate communications environment," Aalto said. "Attackers now move between email, Teams, Slack, text messages, phone calls, and remote-access tools, with each interaction making the next one feel more credible." He pushed back on the idea that attackers are choosing trust over technical exploitation; in his view, they're using trust to activate the technical attack. "Spring Ring did not exploit a vulnerability in Microsoft Teams. The attackers persuaded employees to launch legitimate remote-support tools or execute software and then transitioned into malware delivery and an attempted identity attack. That fusion of social engineering and technical methods is what makes these campaigns dangerous."
Aalto's core recommendation is about correlation, not any single control: "The unit of detection must be the sequence, not the individual event." An external chat, a phone call, and a Quick Assist launch each look unremarkable on their own; together, especially when followed by PowerShell activity or unusual identity behavior, they tell a very different story. He also cited Gartner's Richard Addiscott, who has argued that traditional "security awareness" is effectively dead, and said the field needs to move from explaining threats for compliance purposes to rehearsing the specific behaviors—ending an unsolicited call, verifying through a known channel, refusing unexpected remote access—that actually stop these attacks.
Aviv Nahum, Co-founder and CEO at Above Security, pointed to AI as the accelerant reshaping the trust problem. "With AI, an attacker no longer needs to simply spoof a phone number or write a convincing email. They can increasingly reproduce someone's voice, writing style and conversational patterns, and maintain that deception across multiple channels," Nahum said. His prescription is a shift in the underlying security question organizations ask: "The security model therefore must shift from 'does this look real?' to 'can I independently verify that this person is who they claim to be?'" He expects the next wave of social engineering to lean less on obviously fake lures and more on convincing impersonation of people victims already trust, including executives and administrators.
Kern Smith, Vice President of Global Solutions at Zimperium, focused on the MFA angle. "Phishing has evolved into real-time, interactive deception designed to defeat MFA—especially on mobile devices," Kern said. His recommendation is layered defense that pairs identity platforms with on-device mobile threat detection to intercept these attacks before credentials or sessions are exposed.
Louis Eichenbaum, Federal CTO at ColorTokens, was blunt about the limits of training alone. "Security awareness training helps; however, it will never eliminate a tactic that is designed around urgency, authority, and trust," Eichenbaum said. He argued the more durable fix is procedural—mandatory verification through a previously established channel for any unexpected contact—and framed the repeated success of these campaigns as an organizational failure to make that verification routine. "Repeated incidents suggest the problem is not simply that individuals have failed to recognize a scam. Organizations have not yet made strong identity verification sufficiently routine and frictionless," Eichenbaum concluded.
Across the commentary, a few concrete, overlapping recommendations stand out.
-
Treat collaboration and remote-support workflows as attack surface. Monitor for new external identities on Teams, internal-sounding display names from unfamiliar tenants, repeated call attempts, and rapid escalation from chat to voice call.
-
Watch the endpoint for the second-stage signals. Unexpected launches of Quick Assist or other RMM tools, PowerShell downloads, and unusual SMB or NTLM activity are the technical fingerprints that follow a successful vishing call.
-
Flag high-risk identity actions during unsolicited contact. Password resets, MFA changes, device enrollments, or privileged access requests that occur during or immediately after an unsolicited support interaction should be treated as high-risk events, correlated with the communications signals above rather than triaged in a separate queue.
-
Require verification through a known channel. Sensitive requests, new phone numbers, or a sudden move to a different messaging platform should trigger independent verification before anyone proceeds.
-
Limit external collaboration and remote-support capabilities by business need. Require an approved support ticket before remote access is granted, rather than accepting an unsolicited claim of urgency at face value.
-
Rehearse the behavior, not just the awareness. Employees need practice ending an unsolicited interaction, verifying a request, declining remote access, and reporting the attempt—and leadership needs to make clear that doing so is good security practice, not poor customer service.
Unit 42 noted that subsequent Spring Ring-style campaigns may resurface under different role names or modified tenant-naming conventions, and cautioned that public information isn't yet sufficient to determine how far the technique will spread. What is clear is that the newest generation of social engineering isn't trying to fool a spam filter. It's trying to fool a person, in real time, using the exact tools organizations already trust.
[RELATED: 5 Emotions Used in Social Engineering Attacks, with Examples]

