Teams Phishing and Vishing Calls Hit Small Firms
Attackers are expanding beyond email. They now strike through Microsoft Teams messages and phone calls. Here is how to protect your Outaouais small business.
Your staff learned to distrust shady emails. Attackers know this. So they are adding new doors.
On 23 July 2026, Microsoft published its email threat report for the second quarter. The message is plain. Some classic phishing tricks are dropping, but attackers are now using Microsoft Teams messages to manipulate people. Phishing means a fake message that pushes you to hand over a password or click a link.
Why Teams and the phone
Nobody trained your people to distrust Teams. A Teams message looks internal. It looks legitimate. That is exactly what attackers want.
The phone works the same way. In July, Microsoft described a group using voice phishing, also called vishing. Vishing is a fraud call where someone pretends to be tech support. These attackers target cloud applications and abuse approved access to accounts.
What it looks like in your shop
Picture a 12-person accounting firm. An assistant gets a Teams message. The sender shows as "IT Support." The message says an urgent update is needed. She is asked to approve a prompt on her phone.
She approves. The attacker is in.
Now a garage. The manager gets a call. The caller says they are from Microsoft. They ask him to run a command on screen to "fix a problem." That is voice phishing at work.
Attackers also use browser-based lures called ClickFix. A fake page or pop-up tells the user to click "Fix" and run a few steps. Microsoft saw a rise in this kind of attack between late April and mid-June 2026. The goal is to steal passwords saved in the browser and sign-in tokens.
Three simple habits
You do not need a full IT department to shut these frauds down. Three habits get you started.
- Doubt unexpected Teams messages. A real coworker can confirm another way. Call their desk or talk to them in person.
- Never follow a command dictated over the phone. No real support will have you type lines on screen during a surprise call.
- Reject approvals you did not start. If a prompt lands on your phone for no reason, say no.
What an owner can do this week
Start by reviewing Teams external access and guest access in the Teams admin centre. Disable external chats or allow only specific domains, and review shared channels and consumer chat settings. These are settings, not a big project.
Next, turn on a strong sign-in method. Microsoft now makes passkeys the default sign-in method in its identity service. A passkey replaces the password with proof tied to your device. It stands up well against phishing.
Finally, talk to your team. A 20-minute lunch with real examples beats a long policy nobody reads. Name the two new channels: Teams and the phone.
A clinic, a garage, or an accounting firm faces the same risk as a large company. The difference is that a small business feels the hit right away. One lost account, and payroll or client files are on the line.
We help Outaouais small businesses lock down Teams, turn on the right sign-in methods, and train staff. Book a meeting with us and we will look at your setup together.
Read next
August 2026 Patch Tuesday: What to Patch First
On August 11, 2026, the Canadian Centre for Cyber Security posted several advisories. Here is how to rank your security patches in 30 minutes a month.
What Does Managed IT Cost for a Small Business?
The real numbers, plan by plan, with what is included, what is not, and how to tell whether you are paying too much (or too little).
Quebec's Law 25, Explained for Small Businesses
What Quebec's privacy law actually requires from a 5-to-50-person company, without the legal jargon, and where to start without losing a quarter to it.
Not sure which tier fits?
A quick conversation will sort it out. We'll look at your team size, your tools, and what's actually breaking.