Security

Email Threat Landscape Q2 2026: Key Security Trends

3 min read

Summary

Microsoft’s Q2 2026 email threat report shows a major 92% drop in Tycoon2FA-linked phishing following disruption efforts, alongside declines in QR code and CAPTCHA-gated phishing. However, defenders should note that attackers are shifting tactics, with Teams-based social engineering, credential phishing, and fast-moving business email compromise campaigns continuing to pose significant risk.

Need help with Security?Talk to an Expert

Introduction

Microsoft’s latest Q2 2026 threat intelligence report highlights an important shift in the phishing landscape. While disruption of the Tycoon2FA phishing-as-a-service platform significantly reduced some large-scale email threats, attackers are adapting by rotating delivery methods and expanding into collaboration tools like Microsoft Teams.

For IT and security teams, the takeaway is clear: targeted disruption works, but phishing and social engineering risk remain high across Microsoft 365 environments.

What’s new in Q2 2026

Tycoon2FA activity dropped sharply

  • Microsoft reports a 92% decline in Tycoon2FA-linked phishing volume compared with pre-disruption levels.
  • Monthly phishing messages tied to the platform fell to 1.2 million in June, down from an average of 15.1 million in late 2025.
  • No replacement phishing service emerged at a similar scale during the quarter.

QR code phishing declined

  • QR code phishing fell from 18.7 million attacks in March to 8.3 million in June.
  • PDF attachments remained the main delivery method, but DOC/DOCX files gained share during the quarter.
  • Email-embedded QR codes, which spiked in March, nearly disappeared in Q2.

CAPTCHA-gated phishing also fell

  • CAPTCHA-gated phishing dropped more than 81% from its March peak.
  • Attackers continued rotating payload types, including PDFs and HTML attachments, to evade detection.

Teams-based threats increased

  • Microsoft observed continued growth in Teams social engineering, especially voice phishing.
  • Weekly malicious call attempts reached nearly 10 times the mid-2025 baseline by the end of Q2.

Why this matters for administrators

Security teams should view the Tycoon2FA disruption as proof that ecosystem-level enforcement can reduce phishing at scale. But the broader threat picture remains active: Microsoft still detected about 7.6 billion email-based phishing threats during the quarter, and credential theft remains the primary objective.

The rise in Teams-based attacks is especially important for Microsoft 365 admins, since users may trust collaboration tools more than email. Attackers are also combining automation, trusted services, and multi-stage delivery chains to improve success rates.

  • Review Microsoft Defender for Office 365 protections for phishing, malicious attachments, and impersonation.
  • Strengthen user awareness training for QR code phishing, CAPTCHA-gated lures, and Teams vishing.
  • Audit policies for Safe Links, Safe Attachments, and anti-phishing coverage.
  • Monitor for business email compromise and suspicious authentication flows.
  • Expand detection and response playbooks beyond email to include Teams and collaboration platforms.

Organizations that adapt controls across both email and workplace messaging will be better positioned to respond as attackers shift channels.

Need help with Security?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

SecurityphishingMicrosoft DefenderMicrosoft Teamsbusiness email compromise

Related Posts

Security

Microsoft and AXA XL Expand Cyber Incident Response

Microsoft has partnered with AXA XL to bring Microsoft Defender Experts Cybersecurity Incident Response directly to cyber insurance policyholders. The move aims to speed up containment and recovery by aligning security, legal, executive, and insurance workflows before an incident occurs.

Security

Microsoft Black Hat 2026: AI and Supply Chain Defense

Microsoft used Black Hat USA 2026 to spotlight how attackers are abusing trusted software, identities, cloud services, and AI systems to scale attacks. The company also highlighted ongoing npm supply chain investigations, new Microsoft Defender Experts capabilities, and research sessions that give security teams practical guidance for defending trust paths.

Security

ACR Stealer Campaigns: ClickFix Threats Rise

Microsoft reports increased ACR Stealer activity targeting enterprises through ClickFix social engineering, with two intrusion chains using WebDAV, Python loaders, MSHTA, obfuscated PowerShell, and steganography. The campaigns focus on stealing browser credentials, session tokens, and sensitive documents, making early detection and user awareness critical for defenders.

Security

AI Agent Least Privilege: Identity and RBAC Guide

Microsoft is urging organizations to treat AI agents as first-class identities with tightly scoped access, explicit role assignments, and controlled tool bindings. The guidance matters because agentic workflows can span multiple systems, increasing the blast radius of misconfigured permissions, weak audit trails, and unclear accountability.

Security

AsyncAPI npm Supply Chain Attack: Import-Time Malware

Microsoft Threat Intelligence uncovered a coordinated compromise of the AsyncAPI npm organization that republished five package versions with malicious code that runs when packages are imported, not just installed. The incident matters because common mitigations like npm install --ignore-scripts do not stop this technique, putting developer workstations, CI/CD pipelines, and production services at risk if they resolved the affected versions.

Security

Defender Experts Adds Threat Intelligence and MDR

Microsoft has launched Defender Experts Threat Intelligence and expanded Defender Experts MDR with third-party and multi-cloud coverage powered by Microsoft Sentinel. The update helps security teams turn threat intelligence into action faster by combining expert-led guidance, unified Defender portal workflows, and broader cross-platform incident response.