Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Font size: +
7 minutes reading time (1461 words)

AI Phishing Attacks Are Changing Fast: What Businesses Need to Know in 2026

AI phishing attacks are making familiar cyber scams faster, more convincing, and harder for employees to recognize. Recent 2026 threat intelligence shows attackers expanding beyond email into Microsoft Teams, voice calls, trusted cloud services, and highly personalized messages. For businesses, protecting Microsoft 365 identities and training employees to verify unusual requests has become increasingly important.

TL;DR

  • Microsoft detected approximately 7.6 billion email phishing threats during Q2 2026.
  • Malicious Microsoft Teams calls are rising sharply.
  • Generative AI can help criminals create convincing, personalized phishing messages.
  • MFA remains important, but some attacks are specifically designed to abuse authentication workflows.
  • Employees should independently verify unexpected login, payment, payroll, and IT-support requests.

A strange email used to be relatively easy to spot. Maybe the grammar was bad. Maybe the logo looked wrong. Maybe the sender's story simply didn't make sense.

That comfort is disappearing.

Today's attackers can use AI, automation, legitimate cloud services, and familiar workplace tools to create attacks that look much more like normal business communication.

And the latest numbers deserve attention.

How serious are phishing attacks in 2026?

Phishing remains one of the most persistent ways criminals try to gain access to business accounts, and attackers are changing how those messages reach employees.

Microsoft reported approximately 7.6 billion email-based phishing threats during Q2 2026 alone. Credential phishing remained the dominant objective behind malicious payloads.

But email is only part of the story.

Microsoft also observed continued growth in social engineering through Microsoft Teams. By the end of Q2, weekly malicious Teams call attempts were running at nearly 10 times the mid-2025 baseline.

That matters because an employee may naturally be more suspicious of an unknown email than a Teams message or call that appears to come from IT support.

The attack has moved into the workplace.

How is AI making phishing more convincing?

Generative AI gives criminals a practical advantage: speed and personalization.

Instead of sending the same awkward message to thousands of people, attackers can use publicly available information to make a lure fit someone's role, industry, or responsibilities.

Microsoft documented an AI-enabled device-code phishing campaign in April 2026 in which generative AI was used to create targeted messages based on victims' job roles. Themes included invoices, RFPs, and manufacturing workflows.

The technical side is evolving too.

In that campaign, attackers abused Microsoft's legitimate device-code authentication process. A victim could be directed to a real Microsoft sign-in page and still unknowingly authorize an attacker's session.

That's an important distinction.

Seeing a legitimate Microsoft page does not automatically mean the request that sent you there was legitimate.

Why should businesses pay attention to Microsoft Teams?

Employees have been trained for years to be suspicious of email. Attackers know that.

Microsoft's Q2 2026 research found growing abuse of Teams for phishing, social engineering, malware delivery, and especially voice phishing or vishing.

A common scenario looks ordinary:

An employee receives a Teams message or call from someone claiming to be technical support. There is supposedly an account problem, security issue, or urgent update.

The employee is then asked to take an action.

Maybe it's entering a code. Maybe it's visiting a site. Maybe it's installing something.

The important part isn't the exact script. It's the psychology behind it: trust + urgency + a familiar workplace tool.

Microsoft reported that weekly Teams vishing attempts increased roughly 80% from the beginning of 2026 through the end of Q2.

Businesses should therefore treat Teams, chat, text messages, and phone calls as part of phishing awareness not just email.

What does a modern AI-assisted phishing attack look like?

There isn't one universal template.

A modern attack might involve:

What the employee sees What could actually be happening
"IT support" contacting them in TeamsSocial engineering or vishing
A Microsoft device-login requestAttempted token or session compromise
An executive requesting payroll informationBusiness email compromise
An AI product account warningBrand impersonation
An unexpected QR codeRedirect to credential phishing
A familiar cloud-service linkMulti-stage attack using legitimate infrastructure

In June 2026, Microsoft observed an automated business email compromise campaign that reached more than 67,000 users across more than 42,000 organizations in under three hours.

One lure sought accounts-receivable information. Another impersonated a CEO or president in an attempt to redirect payroll payments.

The messages didn't even need a malicious attachment or link.

The attackers wanted a reply.

That's why simply teaching employees "don't click suspicious links" isn't enough anymore.

What can your business do about AI phishing attacks?

Technology matters, but the best defense is layered.

1. Verify unusual requests outside the original conversation

If someone requests a payment change, password action, payroll update, sensitive document, or unusual login, verify it using a known contact method.

Don't rely on the phone number, link, or contact information supplied in the suspicious message.

2. Strengthen Microsoft 365 identity protection

MFA is still important, but businesses should evaluate phishing-resistant authentication and Conditional Access where appropriate.

Microsoft specifically recommends passwordless authentication options such as Windows Hello, FIDO security keys, and Microsoft Authenticator for supported accounts.

3. Protect more than the inbox

Email security alone doesn't address attacks arriving through Teams, voice calls, cloud applications, and other communication channels.

Your security program should account for how employees actually communicate.

4. Train people using current attack scenarios

An annual presentation about misspelled emails isn't enough.

Employees should recognize modern scenarios involving:

  • Teams support impersonation
  • QR-code phishing
  • fake Microsoft authentication requests
  • payroll or banking changes
  • unexpected MFA/device-code requests
  • AI-service impersonation
  • voice-based social engineering
5. Have a response plan before someone clicks

A mistake does not automatically have to become a major incident.

Businesses should know who to call, how to revoke suspicious sessions, how to investigate compromised accounts, how to preserve business continuity, and how to recover.

Speed matters.

What should an employee do when something feels wrong?

Use a simple rule:

Stop. Verify. Then act.

A message becoming urgent does not make it authentic.

If "IT" suddenly needs you to authenticate something, verify with your actual IT provider. If an executive requests a financial change, confirm through an established process. If a Microsoft prompt appears unexpectedly, don't approve it just because the page looks genuine.

Attackers are counting on people moving faster than they think.

Slow that process down.

 What does this mean for your business?

AI isn't replacing cybercriminals. It's giving them better tools.

At the same time, automation and trusted workplace platforms are allowing some attacks to move at a scale that would have been difficult to achieve manually.

That doesn't mean businesses are powerless.

Strong identity controls, properly configured Microsoft 365 security, realistic employee training, monitoring, backup and recovery planning, and a clear incident-response process can substantially improve resilience.

LBT Technology Group helps organizations reduce cyber risk, protect Microsoft 365 environments, recover from disruption, and build practical managed IT and cybersecurity programs around the way their businesses actually operate.

Frequently Asked Questions

QR codes bypass browser isolation for malicious C2...

Related Posts

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024