Call or Text - 
Orlando & Central Florida:
407-554-5534
Naples & Southwest Florida:
239-653-0252
cybernetic_logo_white
Schedule a Free Consultation

Phishing Is Moving Into Teams Calls and Chats. Here’s What Small Businesses Should Watch For.

07/29/2026
2149445127(1)

Phishing Is No Longer Just an Email Problem

Most business owners know to warn employees about suspicious emails. But attackers are changing where they show up.

Microsoft’s Q2 2026 email threat report found that while some major phishing techniques declined after law enforcement and industry disruption efforts, attackers continued shifting into trusted work tools, including Microsoft Teams. Microsoft reported continued growth in Teams-based social engineering, especially voice phishing, where attackers try to trick employees through calls instead of traditional email.

For a small business, that matters because Teams feels familiar. If a message or call appears inside a work app, an employee may assume it is safer than a random email.

That assumption is exactly what attackers are counting on.

What Teams-Based Phishing Looks Like

Teams-based phishing does not always look dramatic. It may look like a normal work interruption.

An employee may receive a chat or call from someone pretending to be IT support. The message may claim the person’s account is about to be locked, a device needs to be fixed, or a software update must be completed right away.

The goal is usually simple: get the employee to share login information, approve a sign-in request, install remote access software, or follow instructions that give the attacker a way into the business.

This is especially risky for small businesses because one compromised Microsoft 365 account can expose email, files, calendars, customer data, invoices, and internal conversations.

Why This Is Harder for Employees to Spot

Traditional phishing training often focuses on email red flags: strange sender addresses, bad spelling, suspicious links, and unexpected attachments.

But Teams calls and chats feel more personal. They happen in the middle of the workday, inside a tool employees already use. A fake “support” call can create pressure quickly, especially if the attacker sounds confident.

Microsoft also noted that attackers are using more generic display names instead of obvious “IT Help Desk” labels. That makes the situation less obvious for employees who are trying to move fast.

For busy offices in Orlando and Central Florida, this kind of interruption can easily blend into the normal rhythm of the day.

Practical Steps Small Businesses Should Take

Start by updating your employee guidance. Staff should know that IT support will never pressure them to share passwords, approve unexpected sign-ins, or install tools without a known process.

Create a simple verification rule: if a Teams message or call asks for account access, payment details, remote control, or urgent action, employees should verify through a separate trusted method before doing anything.

Review external Teams communication settings. Some businesses need outside collaboration, but many have broader access than they realize. Limiting who can message or call employees can reduce unnecessary exposure.

Strengthen sign-in security. Multi-factor authentication is important, but businesses should also review whether users still rely on weaker methods such as SMS codes. Microsoft has been pushing businesses toward stronger sign-in methods like passkeys because attackers are getting better at tricking people around older protections.

Monitor for unusual account activity. A compromised Microsoft 365 account may create hidden inbox rules, send messages to customers, access files, or trigger unusual sign-ins. These warning signs are easier to catch when monitoring is in place before something goes wrong.

What Owners Should Ask Their IT Provider

Ask whether your Microsoft 365 tenant allows outside Teams users to contact staff.

Ask how employees should verify a real IT support request.

Ask whether your business uses phishing-resistant sign-in methods.

Ask whether Microsoft 365 alerts are being reviewed by someone who knows what to look for.

Ask whether your team has a written response plan if an employee accidentally follows a fake support request.

These are not just security questions. They are business continuity questions

Attackers go where employees already work. If your team uses Microsoft Teams every day, it should be included in your security planning, not treated as separate from email protection.

Cybernetic Networks helps small businesses in Orlando and surrounding areas secure Microsoft 365, review Teams settings, improve employee verification habits, and monitor for suspicious account activity. If your business depends on Microsoft 365, we can help make sure your staff can collaborate confidently without leaving the door open to avoidable account compromise.

Source Links

Quotes from our Customers