ReliaQuest researchers observed Black Basta affiliates relying on Microsoft Teams to gain initial access to target networks.Black Basta ransomware affiliates switched to Microsoft Teams, posing as IT support to deceive employees into granting access.Threat actors flood employee inboxes with emails, then impersonate IT support on Microsoft Teams to offer help.Attackers send QR codes in chats as part of Quishing attempts.