Microsoft’s Q2 2026 Email Threat Landscape report, published this week, confirms a shift that’s been building all year: attackers are moving out of the inbox and onto Microsoft Teams and phone lines. Weekly malicious call attempts have surged roughly 80% since January and hit nearly ten times the mid-2025 baseline by late June. Teams-based phishing detections rose 19% between March and April alone, with another 10% jump in June.
The pivot makes sense. Microsoft’s successful takedown of the Tycoon2FA phishing-as-a-service platform has crushed that operation’s email volume by 92%. With email defences getting better, criminals are simply going around them. Security firm LevelBlue tracked over 5,000 “dual-channel” BEC attacks in 2025 — scams that pair a spoofed email with a follow-up phone call, SMS, or Teams message to make the payment request feel more legitimate. In 43% of cases, the initial email simply asked for the target’s mobile number — the real attack came later, on a channel the company’s email filter never sees.
Here’s the uncomfortable reality for most Australian SMBs: you’ve probably invested in email filtering, but Teams external access is wide open by default. We see this in nearly every Microsoft 365 environment we onboard — external users can message anyone in the organisation, and there’s no alerting when someone outside the tenant initiates a chat. That’s exactly the gap attackers are exploiting, and it’s a gap that email security products, no matter how good, simply can’t close.
Three things to check this week. First, review your Teams external access settings and restrict who can initiate conversations from outside your organisation. Second, extend your phishing awareness training beyond email — your team needs to know that a Teams message or phone call demanding an urgent payment is just as likely to be a scam. Third, verify any payment or account change request through an independent channel, regardless of how it arrives.
If you’re not sure whether your Microsoft 365 environment is locked down against these multi-channel attacks, get in touch. Our team training programme covers voice and messaging scams too, not just email.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
