Threat actors are reportedly using Microsoft Teams vishing attacks to target businesses in North America. The tactic relies on voice-based social engineering, with attackers posing as internal IT support staff during Teams calls to convince employees to trust them.
Once contact is established, the goal is to obtain remote access to corporate devices. That access can then be used to deploy Chaos ransomware, turning what looks like a routine support interaction into the starting point of a serious security incident.
The reported activity highlights how collaboration tools such as Microsoft Teams can be abused as part of ransomware operations. By impersonating help desk personnel instead of using only email lures, attackers may be able to appear more credible and pressure staff into acting quickly.
For organizations, the campaign is another reminder that ransomware risk often begins with social engineering rather than software exploitation alone. Security teams in North America may need to pay closer attention to unexpected IT support calls, remote access requests, and unusual activity inside workplace communication platforms.