Most email security tools are built to catch a malicious link or attachment. But many of today's most effective phishing attacks skip that entirely. They arrive through trusted Microsoft 365 workflows: SharePoint notifications, Teams messages and sign-in pages that are, to both scanners and users, indistinguishable from the real thing.
MFA no longer stops the sign-in
Multi-factor authentication was supposed to close this gap. A phishing-as-a-service kit called Tycoon2FA has made that assumption obsolete for organisations that haven't deployed phishing-resistant MFA. It sits between the victim and the real Microsoft sign-in page as a reverse proxy: the user enters their password, completes the MFA prompt exactly as they would on a genuine login, and never notices that the session token issued at the end of that process has just been captured and handed to an attacker.
Microsoft has described Tycoon2FA as one of the leading phishing-as-a-service platforms, with campaigns reaching more than 500,000 organisations a month[1]. Once that token is stolen, a password reset alone does not fix it: the session stays valid until it is explicitly revoked.
Trusted platforms make the lure invisible
Microsoft's own Defender research team documented exactly how this plays out in a live campaign against energy-sector organisations in January 2026. It started with a phishing email from a genuine, but already compromised, vendor account, using a SharePoint file-sharing notification that matched the subject-line conventions of a real one. Clicking through led to a credential prompt sitting in front of the real Microsoft sign-in flow.
Once inside, the attacker created an inbox rule to delete and mark as read anything from the platform, then used the compromised account to send more than 600 further phishing emails to the victim's own contacts, both inside and outside the organisation, drawn from their recent email threads.
When recipients replied asking whether the email was genuine, the attacker read those replies, answered to falsely confirm it was legitimate, then deleted the exchange[2].
Every step in that attack chain used a legitimate Microsoft service, a real, if compromised, sender, and a document-sharing workflow employees are trained to trust. This is not a spam-filter problem: a shared document that looks normal, sent from a name the recipient recognises, is far harder to question than an email from an unfamiliar address.
Teams carries the same trust
Email is not even the primary channel for a lot of this activity anymore. Teams carries the same institutional trust as an internal phone extension, so a message that appears to come from a colleague or from IT support gets far less scrutiny than an email would.
Anyone who knows a target's email address can message them directly on Teams without ever going near an email gateway. Once an account is compromised, as in the SharePoint campaign above, Teams gives attackers an internal messaging channel that employees rarely question.
A request to review a document or approve an invoice can arrive from what appears to be a trusted colleague, with none of the visual cues users associate with suspicious email. Organisations that allow external Teams communication are opening a channel most email security tools were never built to monitor.
QR codes defeat the tools built to catch everything else
QR codes extend the same principle beyond the inbox. Rather than persuading someone to click a suspicious link, they move the interaction onto a mobile device, outside many of the controls organisations rely on to inspect email traffic.
Microsoft recorded QR code phishing volumes rising 146% in the first quarter of 2026 alone, with PDF attachments overtaking every other format as the delivery method of choice, growing from 65% to 70% of QR-based attacks over the quarter[3]. A QR code embedded in a PDF has no readable link for a scanner to flag, and it can pass cleanly through sandboxing because nothing in the file itself is malicious.
The malicious step only happens after the file is opened, on a personal phone, off the network any sandbox was ever watching.
Why the last line of defence is a trained person
None of this makes email gateways, sandboxing or MFA wasted effort. They stop most attacks and remain necessary.
What they cannot do is catch a technique built to be indistinguishable from a legitimate part of the Microsoft 365 experience: a real sign-in page, a real SharePoint link, a real colleague's name in Teams. When an attack is engineered to look like normal platform use, the only thing left that can catch it is someone who knows what to check and where.
That's why security awareness training must evolve alongside the attacks it prepares people for. The challenge isn't recognising suspicious emails anymore. It's recognising when a trusted Microsoft 365 workflow is being abused. Practice from Pistachio prepares employees for attacks that abuse trusted Microsoft 365 workflows, not just traditional phishing emails.
Simulations across email and Microsoft Teams. Training covers the channel attackers are shifting toward, not just the inbox.
Role-based personalisation. Finance teams see invoice fraud and payment-request scenarios, IT teams see credential and vulnerability-themed attacks, matching how real attackers already tailor messages by role.
Adaptive difficulty and frequency. Training intensity adjusts automatically to individual performance, so lean IT teams are not manually managing who needs more exposure.
Reporting built for compliance. Evidence is collected automatically for NIS2, ISO 27001 and Cyber Essentials audits, without extra admin work.
As Microsoft 365 becomes the attack surface, employees need to recognise abuse of the platform itself, not just suspicious emails.
See how Practice prepares employees for modern Microsoft 365 phishing attacks. Email contact@pistachioapp.com to book your 15-minute demo.

