Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users

Published September 2, 2026

A criminal gang named Springs is calling Microsoft Teams users pretending to be support, then tricking them into installing malware or handing over their login. The calls let attackers steal messages, hijack meetings, and even take over company accounts.

Report priority
Medium
Targets
Microsoft

How it works

  • Attackers call Teams users claiming to be Microsoft support.
  • They ask for remote access to fix a fake problem, then trick the user into installing malware or sharing their login.
  • Once in, they can read messages, join meetings, and even control company accounts.

What to do

If you got a call from someone claiming to be Microsoft Teams support asking for remote access or your login, never share your login or install software from unsolicited calls. Microsoft Teams itself is not vulnerable, only users who trusted the fake callers are at risk.

If you did, change your password immediately via Microsoft's account security page and review recent activity for unauthorized access. Report the call to Microsoft via their support page.

Technical details

An attacker calls a user saying their Teams account is locked. They ask the user to download a fake 'support tool' or share their password to 'unlock' it. The tool actually installs malware that lets the attacker read messages and join meetings.

The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.