Kaspersky has recorded more than 4.7 million workplace tools attacks over the past 12 months as cybercriminals exploit popular business software. As organizations return to full operational capacity after the summer break, employees face an influx of emails, meeting links, and digital documents that attackers regularly imitate.
Scope of Workplace Tools Attacks
Between July 2025 and June 2026, security researchers logged 4,781,846 attempted infections tied to workplace platforms. Video conferencing and email solutions represented the primary targets during this period. Attackers disguised threats as routine corporate notifications to bypass employee vigilance within the business sector.
Zoom emerged as the most exploited brand name, appearing in 2,658,283 attempted incidents. Outlook followed with 1,546,122 recorded threats. Additionally, malicious files imitated OneDrive in 197,030 cases, Microsoft Excel in 151,948 instances, and Microsoft Teams in 111,402 attempts.
Most Targeted Applications and Malware Types
Downloaders formed the single largest threat category, representing 2,733,204 detected cases. These programs secretly download and execute additional unauthorized software on compromised hardware. The prevalence of downloaders underlines the persistent risk that workplace tools attacks pose to corporate network security.
Trojans constituted the second most common malware family with 989,377 detections. These malicious programs masquerade as normal files to exfiltrate company records, track keystrokes, or provide attackers with unauthorized remote administrative access. Exploits targeting software vulnerabilities accounted for an additional 341,165 recorded cases across corporate endpoints.
Phishing Tactics Targeting Enterprise Accounts
Researchers identified advanced social engineering campaigns designed to hijack corporate credentials without triggering traditional security warnings. Specifically, attackers used device code phishing techniques through Microsoft’s Device Authorization Grant system to obtain valid account tokens. Consequently, victims authorized third-party applications without disclosing passwords directly on fake forms.
Attackers also distributed fake Google recruitment invitations through legitimate Google AppSheet accounts on popular cloud services. These messages prompted candidates to open links leading to credential harvesting sites.
“After the summer period employees will receive meeting invitations, documents, account notifications and requests from both familiar and new contacts. Cybercriminals understand this context and may imitate exactly the tools people expect to encounter during the working day.”
Evgeny Kuskov, Lead Security Researcher at Kaspersky
Recommended Defense Measures for Organizations
To mitigate the risks of workplace tools attacks, security specialists recommend implementing multi-factor authentication across all collaboration tools. Employees must inspect sender addresses and domain spelling before opening unexpected attachments or meeting invitations.
Furthermore, corporate IT departments should maintain strict application whitelisting and conduct practical cybersecurity awareness sessions for staff. Organizations should also deploy endpoint security software to detect anomalous network activity and unauthorized configuration changes.





