Email Threat Landscape Q2 2026: Key Security Trends
Summary
Microsoft’s Q2 2026 email threat report shows a major 92% drop in Tycoon2FA-linked phishing following disruption efforts, alongside declines in QR code and CAPTCHA-gated phishing. However, defenders should note that attackers are shifting tactics, with Teams-based social engineering, credential phishing, and fast-moving business email compromise campaigns continuing to pose significant risk.
Introduction
Microsoft’s latest Q2 2026 threat intelligence report highlights an important shift in the phishing landscape. While disruption of the Tycoon2FA phishing-as-a-service platform significantly reduced some large-scale email threats, attackers are adapting by rotating delivery methods and expanding into collaboration tools like Microsoft Teams.
For IT and security teams, the takeaway is clear: targeted disruption works, but phishing and social engineering risk remain high across Microsoft 365 environments.
What’s new in Q2 2026
Tycoon2FA activity dropped sharply
- Microsoft reports a 92% decline in Tycoon2FA-linked phishing volume compared with pre-disruption levels.
- Monthly phishing messages tied to the platform fell to 1.2 million in June, down from an average of 15.1 million in late 2025.
- No replacement phishing service emerged at a similar scale during the quarter.
QR code phishing declined
- QR code phishing fell from 18.7 million attacks in March to 8.3 million in June.
- PDF attachments remained the main delivery method, but DOC/DOCX files gained share during the quarter.
- Email-embedded QR codes, which spiked in March, nearly disappeared in Q2.
CAPTCHA-gated phishing also fell
- CAPTCHA-gated phishing dropped more than 81% from its March peak.
- Attackers continued rotating payload types, including PDFs and HTML attachments, to evade detection.
Teams-based threats increased
- Microsoft observed continued growth in Teams social engineering, especially voice phishing.
- Weekly malicious call attempts reached nearly 10 times the mid-2025 baseline by the end of Q2.
Why this matters for administrators
Security teams should view the Tycoon2FA disruption as proof that ecosystem-level enforcement can reduce phishing at scale. But the broader threat picture remains active: Microsoft still detected about 7.6 billion email-based phishing threats during the quarter, and credential theft remains the primary objective.
The rise in Teams-based attacks is especially important for Microsoft 365 admins, since users may trust collaboration tools more than email. Attackers are also combining automation, trusted services, and multi-stage delivery chains to improve success rates.
Recommended next steps
- Review Microsoft Defender for Office 365 protections for phishing, malicious attachments, and impersonation.
- Strengthen user awareness training for QR code phishing, CAPTCHA-gated lures, and Teams vishing.
- Audit policies for Safe Links, Safe Attachments, and anti-phishing coverage.
- Monitor for business email compromise and suspicious authentication flows.
- Expand detection and response playbooks beyond email to include Teams and collaboration platforms.
Organizations that adapt controls across both email and workplace messaging will be better positioned to respond as attackers shift channels.
Need help with Security?
Our experts can help you implement and optimize your Microsoft solutions.
Talk to an ExpertStay updated on Microsoft technologies