What's Happening
As part of our ongoing threat landscape monitoring, ISI is seeing a clear shift in how phishing and social engineering attacks are carried out. Attackers are moving beyond a single phishing email. They are combining email, text messages, phone calls, and collaboration tools like Microsoft Teams, often with AI-generated content, to make a malicious request feel more legitimate.
Recent research from KnowBe4 found that a large majority of observed phishing attacks now involve AI, and that attacks using Microsoft Teams have risen sharply in just a few months. The same research points to a growing focus on stealing Microsoft 365 credentials and active login sessions, not just passwords.
What This can Look Like
Here's a pattern that's become increasingly common:
- An urgent email arrives, appearing to come from an executive, asking you to make a payment, share sensitive information, or take some other unusual action
- A few minutes later, a text follows: "I just sent you an urgent email. Please take care of it."
- The second message is designed to make the first one feel real
Both messages can be controlled by the same attacker. A second communication channel is not independent verification.
Why it Matters Now
- AI is making it cheap and fast to research specific employees and write convincing, personalized messages
- A message can reference real details about you or your organization and still be malicious
- Familiar tools like Teams are increasingly used as an attack surface, not just email
The technology behind the message isn't the point: the goal is to get you to act quickly, before you stop and verify.
Don't Blindly Trust MFA
- If you receive a multifactor authentication (MFA) prompt you did not initiate, do not approve it
- If someone calls or messages you claiming to be IT, Microsoft, a vendor, or a coworker and asks for your MFA code or asks you to approve a notification, do not do it
What to Do Now
Pause on Unexpected Requests
- Be cautious with anything involving money, credentials, MFA, sensitive information, or urgency
- Urgency and pressure are the tactic, not a sign of legitimacy
Don't Treat a Second Channel as Verification
- An email followed by a text, Teams message, or phone call is not confirmation that a request is real
- Treat it as one attacker potentially using two channels
Verify Independently
- Use contact information you already have on file, not the number or link included in the message itself
- Call or message the person directly through a known, trusted channel before acting
Report It
- Report suspicious emails, calls, texts, and Teams messages, even if you did not click anything or respond
- Reporting early helps identify patterns before they spread
If You Suspect Suspicious Activity
Treat these as urgent and escalate quickly:
- You entered credentials on a suspicious page or link
- You approved an MFA prompt you did not request
- You shared sensitive information or made a payment based on an unverified request
Immediate Actions
- Contact your IT or security support right away
- Do not delete messages, emails, or call logs related to the incident
- Change your password and review recent account activity if you believe credentials were exposed
Stay safe, stay secure.
-ISI Cybersecurity Team
Reference Resources