Phishing Series 2026: Teams Vishing — External Helpdesk Impersonation Before MFA Reset

This rule detects potential social engineering attacks where an external or federated user impersonates an IT or helpdesk entity within Microsoft Teams (via chats, messages, or calls) followed shortly by an MFA registration or password reset event for the targeted user. This sequence is indicative of a vishing or phishing attack aimed at account takeover.