Back to all lessons
Awareness Lessons
last month

Vishing Attacks Exploit Human Trust to Hijack Microsoft Teams Sessions

The 'Spring Ring' threat actor is exploiting human psychology rather than technical vulnerabilities, using voice phishing (vishing) to manipulate Microsoft Teams users into voluntarily granting unauthorized access to their sessions. This attack succeeds because users are not trained to recognize social engineering delivered via voice calls, especially when the attacker impersonates trusted entities like IT support. Once access is granted, attackers can deploy malware and pivot laterally across entire organizational infrastructures. This campaign highlights that even robust technical controls can be bypassed when employees are not equipped to identify and respond to social engineering threats.

Tactical Insight

Immediate actions

  • Train all employees to recognize vishing tactics and establish a strict policy of never granting remote access in response to unsolicited calls or messages.
  • Enforce Multi-Factor Authentication (MFA) on all Microsoft Teams accounts and restrict remote-access permissions to verified IT personnel only.

Long-term improvements

  • Implement a formal callback verification procedure requiring users to independently confirm the identity of anyone requesting remote access via an official directory number.
  • Conduct regular simulated vishing exercises to assess and improve employee resilience against voice-based social engineering.
  • Apply the principle of least privilege to Teams configurations, limiting screen-sharing and remote control capabilities to roles that genuinely require them.

Detection measures

  • Enable and review Microsoft Teams audit logs to flag unusual session-sharing or remote access events in real time.
  • Deploy endpoint detection and response (EDR) tools to identify anomalous behavior such as unexpected remote access tools or lateral movement following a Teams session.