Cybercriminals exploit trusted workplace platforms with nearly 4.8 million attacks in a year

As companies return to busy autumn routines, Kaspersky warns that cybercriminals are increasingly disguising malicious files as trusted business communications, with nearly five million attacks detected in the past year leveraging familiar platforms like Zoom, Outlook, and OneDrive.

As companies move back into a busier autumn work cycle, Kaspersky says attackers are taking advantage of the return to routine by disguising malicious files and links as ordinary business communications. In a report covering the past 12 months, the security firm said it detected 4.7 million attacks that used the names and branding of widely used workplace platforms, including Zoom, Outlook and OneDrive.

The figures suggest that familiar software remains one of the most effective disguises for cybercrime. Between July 2025 and June 2026, Kaspersky recorded 4,781,846 attack attempts linked to popular business tools. Zoom was the most abused name, with 2,658,283 detections, followed by Outlook with 1,546,122. The company also logged 197,030 attempts involving OneDrive, 151,948 involving Microsoft Excel and 111,402 involving Microsoft Teams.

Kaspersky said the largest threat class in this period was downloader malware, with 2,733,204 detections. Such programmes can fetch and install extra software on an infected device, often opening the door to further malicious components. Trojans accounted for 989,377 detections, while exploit attempts, which take advantage of software or operating system flaws, totalled 341,165.

The most notable phishing method described in the report relied on Microsoft’s device authorisation process. Rather than asking victims to type passwords into a fake login page, attackers used a legitimate Microsoft authorisation flow to generate a code, then tricked users into entering that code on an authentic Microsoft page. Kaspersky said this could give attackers a token that granted access to mail, files or Teams messages without exposing the victim’s password directly. The firm also described fake job interview invitations that impersonated Google recruiters and were sent through Google AppSheet, a legitimate service, making the messages appear more credible.

Kaspersky said the pattern fits a wider trend in which criminals increasingly hide behind trusted platforms and cloud services to make fraudulent messages harder to spot. In separate warnings, the company has recently described malware campaigns delivered through imitation software sites and phishing activity that abused cloud email infrastructure, underlining how attackers continue to use familiar tools to lower suspicion and increase the chances of compromise.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.