Kaspersky detects 4.7 million attacks disguised as workplace tools ahead biz season

While many people are still making the most of the international summer season and exploring new destinations through guides such as the Kaspersky Safe Travel Insights, businesses are preparing for the return to a more active working rhythm.

Cybercriminals may take advantage of this increased digital activity by disguising malicious files and links as legitimate workplace communications. Kaspersky’s analysis of the past 12-months shows how attackers continue to exploit trusted business tools: specifically, Kaspersky detected 4.7 million attempted attacks involving content mimicking popular workplace services, including Zoom, Outlook, OneDrive and others.

After the international summer period, employees often return to a more active working rhythm: projects resume, teams reconnect, and the number of emails, meetings and shared files increases. This transition creates conditions that cybercriminals can exploit.

A fake video-call invitation may appear among legitimate meetings, a malicious attachment may be disguised as a business document, and a phishing page may imitate a familiar cloud storage or email service. When employees are processing a high volume of routine communications, a fraudulent message may be more difficult to distinguish from a genuine one.

From July 2025 to June 2026, Kaspersky detected 4,781,846 attempted attacks involving content associated with widely used workplace platforms. Zoom was the most frequently abused name, accounting for 2,658,283 attempted attacks.

Outlook ranked second with 1,546,122 detections. Cybercriminals also used content associated with OneDrive, which accounted for 197,030 attempted attacks, Microsoft Excel with 151,948 and Microsoft Teams with 111,402.

The largest threat category detected during the period was Downloader, with 2,733,204 cases. Such programs may download and install additional software on a device, potentially introducing further unwanted or malicious components.

Trojans were the second-largest category, accounting for 989,377 detections. These malicious programs disguise themselves as legitimate files or applications and may steal data, monitor user activity, provide attackers with remote access to a device or install additional malware. Exploits, which may take advantage of vulnerabilities in software or operating systems to compromise a device, followed with 341,165 cases.

Many of the phishing schemes identified by Kaspersky were designed to compromise corporate accounts. Some of the schemes used a more sophisticated device code phishing technique. Instead of asking the victim to enter a password directly on a fake login page, the phishing site displayed a one-time code and instructed the user to copy it.

The code was generated as part of Microsoft’s legitimate Device Authorisation Grant flow, which allows users to authenticate on devices with limited input capabilities. The attackers initiated this authorisation process for their own application and tricked the victim into entering the code on a genuine Microsoft login page.

Leave a Reply

Your email address will not be published. Required fields are marked *