Kaspersky documented 4,781,846 attack attempts between July 2025 and June 2026 that used everyday work platforms as bait: Zoom invitations, Outlook emails and files shared on OneDrive. The report, released on August 20, sizes up a pattern that points straight at the heart of hybrid work.

El Sol de México picked up the finding in Mexico on September 17, describing how attackers no longer need eye-catching messages: it is enough to imitate a meeting, a file or an access request for an employee to hand over corporate credentials. Infobae documented the same report on August 23, with the breakdown by platform and a description of the campaign built on fake job interview invitations. El Sol de México highlights the risk for organizations in the region that concentrate email, documents and meetings in a handful of corporate accounts. Kaspersky adds a calendar factor: risk rises during periods of peak business activity, when emails, meetings and shared files multiply.

The breakdown by platform:

By threat type, Kaspersky recorded 2,733,204 downloaders, 989,377 trojans and 341,165 exploits. One of the documented techniques is device code phishing: the victim enters a code generated by the attackers on Microsoft's official website and, without handing over a password, authorizes an application that receives an access token for email, files and messages. Lisandro Ubiedo, a researcher on Kaspersky's GReAT team, noted in the firm's statement that criminals only need to imitate routine actions from the work environment.

The report recommends confirming unexpected requests for access, files or meetings through another channel, distrusting unsolicited login codes and reviewing permissions before authorizing an application. With 4.7 million attempts in a year, the pattern suggests that verifying the domain is no longer enough.

This piece was written with the assistance of artificial intelligence from verified sources and reviewed by a human editor before publication.