Neat Digest  ·  Archive  ·  Open in app ↗

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Score 3.6/10 · Standard · Technology · 1 sources · July 30, 2026
Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Threat actors are conducting vishing (voice phishing) attacks by impersonating IT support staff in Microsoft Teams calls to trick employees into granting remote access to their corporate devices. Once access is gained, the attackers deploy Chaos ransomware, a relatively new and destructive strain that encrypts files and demands payment. These attacks are targeting North American organizations, with the campaign reportedly active in recent weeks. The attackers use social engineering tactics, leveraging the trust employees place in internal communication tools like Teams, to bypass traditional security measures. Microsoft has acknowledged the trend and advises organizations to enforce multi-factor authentication and educate staff on verifying support requests. The Chaos ransomware is notable for its aggressive encryption and lack of a reliable decryption tool, making recovery difficult without backups. This incident highlights the growing convergence of social engineering and ransomware, posing a significant threat to corporate cybersecurity.

Global Impact

Economically, the rise of Chaos ransomware attacks adds to the growing cost of cybercrime, which is projected to reach trillions annually, affecting corporate budgets for security and insurance. Politically, this may prompt increased government action on ransomware, including sanctions on ransomware operators and international cooperation on cybercrime enforcement.

Why this score

Neat Digest rated this story 3.6/10 — Standard tier.

This is a significant cybersecurity campaign targeting North American organizations with a destructive ransomware strain, but it is not yet at the scale of a major global disruption; it fits the Significant tier due to its potential for widespread corporate impact and industry-wide implications.

Sources on this story

Reported by 1 sources, including:

  • BleepingComputer