Fake Voicemail Notifications: Microsoft as Bait

In late June BACS flagged a wave of fake voicemail notifications landing in inboxes via email. The message looks like an automatic notification from Microsoft 365 or another phone system: “You have received a new voice message, click here to listen.” Click the link and you land on a fake login page, with the goal being your Microsoft 365 credentials.

It sounds like a simple trick, and it is. But honestly, who would not click on a voicemail notification that looks perfectly normal? That is exactly why it works, because it blends right into the daily work routine and barely raises an eyebrow.

Why voicemail phishing works

In many companies voicemail notifications genuinely arrive by email, because Microsoft Teams, Cisco and Swisscom Business automatically send you an email with a link or an audio player when someone leaves a voice message. Normal office life, nothing to see here, and that is precisely what makes the fake version so dangerous.

The phishing email fits the expected pattern: short, factual, one link, just like every real voicemail notification. No urgent call to action, no flashy subject line, no typos, just a routine notification that invites a click (it is like a burglar walking through the front door in a maintenance uniform, looking like they belong).

The link leads to a login page that mimics Microsoft 365 with striking accuracy, and often the recipients email address is already pre-filled, which is a clever detail that builds trust because the real Microsoft page does exactly the same thing. Enter your password, click “Sign in”, and your credentials are now with the attacker.

Microsoft as the target

That Microsoft specifically serves as the bait is no coincidence, because Microsoft 365 is the dominant office software in Europe and Switzerland. According to various phishing reports Microsoft was by far the most imitated brand in 2025, ahead of Google, Apple and DHL. And whoever steals Microsoft 365 credentials potentially gets access to email, Teams, SharePoint, OneDrive and all associated company data; one key that opens practically every door.

But the value of these credentials goes far beyond the individual account. With a compromised Microsoft 365 account an attacker can read internal emails, identify business contacts, insert themselves into ongoing conversations and send further phishing emails from a trusted sender. This is called Business Email Compromise, and it ranks among the most damaging attack forms worldwide; the FBI put BEC losses in 2024 at over 2.9 billion dollars in the US alone.

From voicemail to corporate access

What looks like an annoying but harmless phishing attempt can escalate remarkably fast. In our assessments we see the same attack chain again and again, and it is disturbingly efficient.

It starts innocuously: the voicemail email lures someone to the fake login page and they enter their Microsoft 365 credentials. Then the attacker logs in and first thing sets up a forwarding rule that silently copies every incoming email to an external address, which often goes unnoticed for weeks because nothing changes in the inbox itself. Next the attacker analyses the email conversations, spots open invoices and payment flows, intercepts a legitimate invoice, swaps the bank details and sends it from the employees compromised account to the client or to internal accounting. The payment goes to the attackers account, and by the time someone notices the money is gone.

This is not a theoretical scenario, we have seen it play out in several Swiss SMEs where the initial access came through exactly this kind of voicemail phishing email.

Protective measures

MFA on all Microsoft 365 accounts is the single most effective measure, because it makes stolen passwords useless in most cases. Microsoft offers MFA free of charge for all Business plans and there is no acceptable reason not to turn it on.

Next: set up Conditional Access Policies, meaning allow logins only from certain locations or devices and automatically block suspicious login patterns. This is available in Microsoft 365 Business Premium and Enterprise and pays for itself immediately.

And here is something many companies overlook: monitor email forwarding rules. Many attackers set up forwarding right after getting initial access, and a regular check or an automated alert on new forwarding rules catches exactly that step. Frankly in many organisations nobody ever looks at this.

For your next awareness session it is worth showing employees what a real voicemail notification looks like and what the fake one looks like. The difference is in the details: the sender address, the URL behind the link, small inconsistencies in the layout. Anyone who has seen the side-by-side comparison once will look more carefully next time.

Conclusion

Voicemail phishing is not new, but it benefits from the unstoppable trend towards cloud telephony. The more companies move their phone systems to the cloud and receive voice messages via email, the larger the attack surface becomes.

The BACS warning is a good prompt to check two things: is MFA active on all your Microsoft 365 accounts? And when did you last check whether there are unknown forwarding rules sitting in the mailboxes? If the answer is “not sure”, well, that tells you where to start…

Questions about your Microsoft 365 security? We review environments for vulnerabilities, test your teams phishing resilience and help with hardening. Drop us a line.

Sources: BACS Weekly Review KW 25, FBI IC3 Report 2024, Microsoft MFA Documentation