Spring Ring: Voice Phishing Campaigns Target Microsoft Teams Users

Spring Ring: Voice Phishing Campaigns Target Microsoft Teams Users

First seen 31 Aug 2026, 16:30 UTC Unit42.Paloaltonetworksdocs.cyberark.comBlog.Knowbe4unit42.paloaltonetworks.com 69.0

Article Content

Browse articles
ThreatCluster

Between January and April 2026, a coordinated voice phishing campaign named 'Spring Ring' targeted over 150 employees across 10 companies, using Microsoft Teams to impersonate IT help desk personnel. Attackers employed social engineering tactics to convince victims to install remote monitoring tools or malware. The campaign transitioned to NTLM relay attacks against domain controllers in some instances. The rise of such attacks reflects a broader trend where 42% of phishing alerts in collaboration tools were reported in early 2026, up from 30% previously. This shift highlights the exploitation of trust in SaaS platforms for malicious activities. Palo Alto Networks has recommended various security products to mitigate these threats. The campaign underscores the importance of user awareness and security training against social engineering tactics.

Key Points: • Over 150 employees targeted in a voice phishing campaign using Microsoft Teams. • Attackers impersonated IT personnel to deliver malware and conduct NTLM relay attacks. • Phishing alerts from collaboration tools rose to 42% of all alerts in early 2026.

Timeline

2026-01-01
Spring Ring campaign begins
A coordinated voice phishing operation targeting Microsoft Teams users starts, affecting multiple organizations.
Unit42.Paloaltonetworks
2026-04-30
Campaign ends
The Spring Ring campaign concludes after targeting over 150 employees across 10 companies.
Unit42.Paloaltonetworks
2026-08-31
Reporting on Spring Ring
Palo Alto Networks publishes findings on the Spring Ring campaign, highlighting the rise of collaboration tool phishing.
Unit42.Paloaltonetworks