Skip to content

Security Advisory: Phishing Is No Longer Just Email

Listen: Security Advisory: Phishing Is No Longer Just Email
3:22

What's Happening

As part of our ongoing threat landscape monitoring, ISI is seeing a clear shift in how phishing and social engineering attacks are carried out. Attackers are moving beyond a single phishing email. They are combining email, text messages, phone calls, and collaboration tools like Microsoft Teams, often with AI-generated content, to make a malicious request feel more legitimate.

Recent research from KnowBe4 found that a large majority of observed phishing attacks now involve AI, and that attacks using Microsoft Teams have risen sharply in just a few months. The same research points to a growing focus on stealing Microsoft 365 credentials and active login sessions, not just passwords.

What This can Look Like

Here's a pattern that's become increasingly common:

  • An urgent email arrives, appearing to come from an executive, asking you to make a payment, share sensitive information, or take some other unusual action
  • A few minutes later, a text follows: "I just sent you an urgent email. Please take care of it."
  • The second message is designed to make the first one feel real

Both messages can be controlled by the same attacker. A second communication channel is not independent verification.

Why it Matters Now

  • AI is making it cheap and fast to research specific employees and write convincing, personalized messages
  • A message can reference real details about you or your organization and still be malicious
  • Familiar tools like Teams are increasingly used as an attack surface, not just email

The technology behind the message isn't the point: the goal is to get you to act quickly, before you stop and verify.

Don't Blindly Trust MFA

  • If you receive a multifactor authentication (MFA) prompt you did not initiate, do not approve it
  • If someone calls or messages you claiming to be IT, Microsoft, a vendor, or a coworker and asks for your MFA code or asks you to approve a notification, do not do it

What to Do Now

Pause on Unexpected Requests

  • Be cautious with anything involving money, credentials, MFA, sensitive information, or urgency
  • Urgency and pressure are the tactic, not a sign of legitimacy

Don't Treat a Second Channel as Verification

  • An email followed by a text, Teams message, or phone call is not confirmation that a request is real
  • Treat it as one attacker potentially using two channels

Verify Independently

  • Use contact information you already have on file, not the number or link included in the message itself
  • Call or message the person directly through a known, trusted channel before acting

Report It

  • Report suspicious emails, calls, texts, and Teams messages, even if you did not click anything or respond
  • Reporting early helps identify patterns before they spread

If You Suspect Suspicious Activity

Treat these as urgent and escalate quickly:

  • You entered credentials on a suspicious page or link
  • You approved an MFA prompt you did not request
  • You shared sensitive information or made a payment based on an unverified request

Immediate Actions

  • Contact your IT or security support right away
  • Do not delete messages, emails, or call logs related to the incident
  • Change your password and review recent account activity if you believe credentials were exposed

Stay safe, stay secure.
-ISI Cybersecurity Team


Reference Resources

Related Posts