Kaspersky, a global cybersecurity company, says it detected 4.7 million attempted cyberattacks involving content disguised as popular workplace services between July 2025 and June 2026.
The cybersecurity firm said the attacks exploited the names and identities of widely used workplace platforms, including Zoom, Outlook, OneDrive, Microsoft Excel and Microsoft Teams.
According to its analysis, 4,781,846 attempted attacks involving content associated with workplace platforms were detected during the 12-month period.
Zoom was the most frequently abused platform, accounting for 2,658,283 attempted attacks, while Outlook ranked second with 1,546,122 detections.
OneDrive accounted for 197,030 attempted attacks, followed by Microsoft Excel with 151,948 and Microsoft Teams with 111,402.
Kaspersky said the increased volume of workplace communication following the international summer period could create opportunities for cybercriminals to disguise malicious files and links as legitimate business communications.
It said attackers could use fake video-call invitations, malicious attachments disguised as business documents and phishing pages designed to imitate familiar cloud storage and email services.
The company said the largest threat category detected during the period was Downloader, with 2,733,204 cases.
It explained that such programmes could download and install additional software on compromised devices, potentially introducing other unwanted or malicious components.
Trojans ranked second with 989,377 detections, while exploits accounted for 341,165 cases.
Kaspersky said Trojans could disguise themselves as legitimate files or applications and be used to steal data, monitor activities, provide remote access or install additional malware.
It added that exploits could take advantage of vulnerabilities in software or operating systems to compromise devices.
Phishing targets corporate accounts
Kaspersky said many of the phishing campaigns identified during the period were designed to compromise corporate accounts using familiar workplace scenarios.
One technique highlighted by the company was device-code phishing, in which victims were instructed to enter a one-time code displayed on a fraudulent website.
According to Kaspersky, the code could be generated through Microsoft’s legitimate Device Authorisation Grant process, which is designed to allow users to authenticate on devices with limited input capabilities.
The attackers allegedly initiated the authorisation process for applications they controlled and tricked victims into entering the codes on a genuine Microsoft login page.
Kaspersky said victims could unknowingly authorise an attacker-controlled application, potentially even after completing multi-factor authentication.
Rather than directly stealing Microsoft passwords, the attackers could obtain an authorisation token issued after the user approves the request.
The token could then potentially provide access to corporate emails, OneDrive files or Teams messages.
The cybersecurity firm said the use of a legitimate Microsoft authentication page could make the scheme particularly difficult to detect.
Another campaign identified by Kaspersky involved fake interview invitations impersonating Google’s recruitment team.
The messages claimed that recipients’ professional profiles had attracted the company’s attention and invited them to schedule introductory calls through embedded links.
Kaspersky said the phishing emails were distributed through Google AppSheet, a legitimate Google-owned platform, and sent from a genuine AppSheet address.
However, the embedded links redirected recipients to phishing websites designed to harvest personal information and account credentials.
Kaspersky said the campaign could be particularly effective during periods of increased recruitment activity, when professionals may be more likely to receive messages from recruiters.
Evgeny Kuskov, Lead Security Researcher at Kaspersky, said cybercriminals understood the normal flow of workplace communications and could exploit it to make malicious messages appear legitimate.
“Cybercriminals understand this context and may imitate exactly the tools people expect to encounter during the working day,” he said.
Kuskov said the biggest danger was not necessarily an obviously suspicious message but one that appeared ordinary enough to be opened without a second thought.
He advised organisations and employees to remain vigilant when handling meeting invitations, documents, account notifications and requests from unfamiliar or new contacts.
![]()























































