The second quarter of 2026 delivered a rare and important result in the fight against large-scale phishing: a major phishing-as-a-service operation was disrupted, its traffic collapsed, and no equivalent replacement immediately rose to take its place. Yet the broader lesson for Windows and Microsoft 365 organizations is not that email phishing is receding. It is that attackers are redistributing their effort across attachments, trusted cloud services, identity workflows, and Microsoft Teams—making the attack surface wider even as one notorious platform loses momentum.
Microsoft’s Q2 telemetry paints a threat landscape defined by two forces moving in parallel. Tycoon2FA, previously one of the most influential phishing-as-a-service platforms, was dramatically diminished following disruption activity launched in March. At the same time, credential theft remained the overwhelming purpose of malicious email campaigns, business email compromise continued at industrial scale, and Teams-based voice phishing grew at an alarming pace.
For IT administrators, security teams, and Windows users, the conclusion is clear: defending the inbox alone is no longer enough. Email security, identity protection, endpoint hardening, collaboration-platform controls, and user reporting workflows must function as a single defensive system.
The disruption of Tycoon2FA is one of the defining cybersecurity developments of the first half of 2026. The service had helped criminals deploy adversary-in-the-middle phishing kits capable of capturing credentials and, in certain scenarios, hijacking authentication sessions. Its infrastructure supported phishing pages designed to evade automated analysis through QR codes, CAPTCHA barriers, and delivery formats that obscured malicious intent.
During Q2, phishing traffic attributed to Tycoon2FA fell to a fraction of its previous level. Compared with its average monthly activity in the second half of 2025, Tycoon2FA-linked phishing volume had declined by roughly 92% by the end of June 2026.
That decline matters because the platform was not simply another phishing kit. It had become a major operational layer for actors who wanted ready-made credential theft infrastructure without building it themselves. Disrupting that layer reduced the scale and consistency of several phishing techniques at once.
The numbers are particularly striking:
However, organizations should not mistake the fall of one service for the end of sophisticated phishing. Criminal operators do not need to restore every previous capability to remain dangerous. They can shift to lower-volume campaigns, use alternative providers, or pursue channels that are less mature from a security-control perspective.
The design served two purposes. First, it gave the phishing page an appearance of legitimacy by copying a familiar human-verification mechanism. Second, it complicated automated inspection because many scanners and web crawlers do not complete CAPTCHA workflows.
This tactic peaked at nearly 12 million attacks in March 2026, then fell sharply during Q2. By June, CAPTCHA-gated phishing had declined to approximately 2.2 million attacks, an 81% reduction from the March high.
Tycoon2FA’s decline was central to that reduction. The service had been heavily associated with CAPTCHA-gated workflows, and its loss of scale appears to have created a vacuum that competitors were unable to fill immediately.
Still, the delivery methods behind CAPTCHA-gated campaigns changed repeatedly:
The decline is significant, but 8.3 million attacks in a single month is not a niche problem. QR code phishing remains a major threat because it is designed to move victims away from corporate protections. A QR code embedded in an email attachment can push a user to scan the image with a personal smartphone, where enterprise browser controls, endpoint sensors, and managed identity protections may be weaker or absent.
PDF files remained the most common vehicle for QR code lures, but their dominance weakened significantly after April. DOC and DOCX attachments gained share, reaching 40% of QR code payloads in June.
That swap is a reminder that attackers are testing user behavior, not merely file types. A fake voicemail notice, secure-document alert, invoice, policy update, or shared-file notification can be placed inside almost any attachment format. The format is only the wrapper.
Notably, email-embedded QR codes nearly disappeared after a sharp surge in March. This may indicate that attachment-based delivery was proving more reliable, better able to evade filtering, or more persuasive to recipients who expect documents to contain QR codes for “secure access.”
This reflects the continuing value of cloud identity. A stolen password, session token, or approved multifactor authentication prompt can give an attacker access to email, Teams chats, SharePoint files, OneDrive content, financial records, and internal communications. In many cases, that access is more valuable than immediately deploying malware.
Neither format should be treated as inherently suspicious. Both are deeply embedded in legitimate business processes. That is precisely why they are useful to attackers.
An HTML attachment can imitate a sign-in page locally, display a fake security notice, or redirect a browser to a credential theft site. A PDF can carry a QR code, a button, a deceptive document-sharing link, or a carefully staged request to “view protected content.”
The rise of ICS calendar invitations deserves special attention. Although calendar files represented only a small portion of overall payloads, they increased sharply in June. This matters because calendar invitations can create a different interaction model from a conventional email attachment. A malicious link may appear in the calendar experience and persist as an upcoming event, increasing the chance that a recipient revisits it later without remembering the original email context.
The temporary spike appears to have been driven by a small number of very large campaigns rather than a lasting expansion in all BEC activity. That distinction is important. It means defenders should not rely only on monthly averages; a short, high-volume campaign can still create enormous financial risk.
The attacker’s objective is often to establish engagement before making a request. Once a victim replies, the criminal can tailor the next message, use the recipient’s tone and signature style, and gradually introduce a financial or data-related request.
This approach creates several challenges:
The campaign used two classic BEC themes:
This is a critical evolution in BEC. Historically, the most damaging BEC attacks were associated with manually researched, highly targeted fraud. That model still exists. But automation now allows criminals to combine broad reach with enough personalization to produce a credible first contact.
For finance and HR teams, policy controls must therefore be as strong as email filtering. Payroll changes, bank-account modifications, payment requests, and customer-data disclosures should require out-of-band verification through a known contact method. A reply to the original email thread is not sufficient verification when the mailbox, sender identity, or conversation context may already be compromised.
A suspicious email can trigger skepticism. A call or chat that appears to come from a colleague, help desk, administrator, or software provider may not.
By the end of Q2, weekly malicious Teams call attempts were nearly ten times higher than the mid-2025 baseline.
The pattern is especially revealing:
On Windows, that can lead directly to execution of a malicious script or installer. The attacker does not need an exploit if a trusted employee can be persuaded to run the command themselves.
Organizations should establish a simple, unambiguous rule: IT support should never ask users to paste commands into Run, Command Prompt, PowerShell, Terminal, or a browser developer console as part of routine account verification or device repair.
That policy must be communicated repeatedly. It should also be backed by technical restrictions that limit unnecessary scripting, prevent untrusted application execution, and surface suspicious PowerShell activity to endpoint detection tools.
The chain is significant because no single step is uniquely suspicious to an ordinary user:
Security awareness training should evolve accordingly. Employees should be taught to evaluate the requested action rather than relying only on logos, recognizable services, or the apparent cleanliness of a sender’s authentication results.
At minimum, organizations should:
Defensive priorities include:
Organizations should review:
But the quarter also shows why defenders cannot celebrate too early. Attackers are not standing still. They are shifting toward automation, cloud infrastructure, trusted services, identity theft, calendar workflows, multi-stage delivery chains, and Teams voice calls.
The future of phishing defense will not be decided by whether organizations can block every suspicious email. It will be decided by whether they can prevent a malicious message, chat, call, or attachment from becoming a successful identity compromise, fraudulent payment, or Windows endpoint infection.
For Windows and Microsoft 365 environments, the most effective response is a mature security posture that connects email filtering, collaboration protection, endpoint detection, secure authentication, policy-based controls, and clear human verification procedures. Tycoon2FA’s decline created a valuable window for defenders. The organizations that use it to close operational gaps will be far better positioned when the next phishing platform—or the next trusted-channel social engineering campaign—inevitably arrives.
Microsoft’s Q2 telemetry paints a threat landscape defined by two forces moving in parallel. Tycoon2FA, previously one of the most influential phishing-as-a-service platforms, was dramatically diminished following disruption activity launched in March. At the same time, credential theft remained the overwhelming purpose of malicious email campaigns, business email compromise continued at industrial scale, and Teams-based voice phishing grew at an alarming pace.
For IT administrators, security teams, and Windows users, the conclusion is clear: defending the inbox alone is no longer enough. Email security, identity protection, endpoint hardening, collaboration-platform controls, and user reporting workflows must function as a single defensive system.
Overview: A Major Phishing Platform Falls, but the Threat Does Not
The disruption of Tycoon2FA is one of the defining cybersecurity developments of the first half of 2026. The service had helped criminals deploy adversary-in-the-middle phishing kits capable of capturing credentials and, in certain scenarios, hijacking authentication sessions. Its infrastructure supported phishing pages designed to evade automated analysis through QR codes, CAPTCHA barriers, and delivery formats that obscured malicious intent.During Q2, phishing traffic attributed to Tycoon2FA fell to a fraction of its previous level. Compared with its average monthly activity in the second half of 2025, Tycoon2FA-linked phishing volume had declined by roughly 92% by the end of June 2026.
That decline matters because the platform was not simply another phishing kit. It had become a major operational layer for actors who wanted ready-made credential theft infrastructure without building it themselves. Disrupting that layer reduced the scale and consistency of several phishing techniques at once.
The numbers are particularly striking:
- Tycoon2FA-linked messages fell from far higher 2025 levels to approximately 1.5 million in May and 1.2 million in June.
- The platform’s share of CAPTCHA-gated phishing pages dropped from 41% in March to 12% in June.
- Its share of QR code phishing campaigns fell from 20% in March to 14% in June.
- No new phishing-as-a-service platform visibly replaced Tycoon2FA at comparable scale during the quarter.
However, organizations should not mistake the fall of one service for the end of sophisticated phishing. Criminal operators do not need to restore every previous capability to remain dangerous. They can shift to lower-volume campaigns, use alternative providers, or pursue channels that are less mature from a security-control perspective.
The Downstream Effect of Tycoon2FA’s Decline
CAPTCHA-Gated Phishing Loses Its Biggest Contributor
CAPTCHA-gated phishing had grown into a highly effective way of frustrating security scanners and slowing down incident response. In a typical campaign, the victim would receive a link or attachment leading to a landing page that required a CAPTCHA challenge before revealing the credential-harvesting content.The design served two purposes. First, it gave the phishing page an appearance of legitimacy by copying a familiar human-verification mechanism. Second, it complicated automated inspection because many scanners and web crawlers do not complete CAPTCHA workflows.
This tactic peaked at nearly 12 million attacks in March 2026, then fell sharply during Q2. By June, CAPTCHA-gated phishing had declined to approximately 2.2 million attacks, an 81% reduction from the March high.
Tycoon2FA’s decline was central to that reduction. The service had been heavily associated with CAPTCHA-gated workflows, and its loss of scale appears to have created a vacuum that competitors were unable to fill immediately.
Still, the delivery methods behind CAPTCHA-gated campaigns changed repeatedly:
- PDF attachments briefly dominated in April, accounting for 63% of attacks.
- HTML attachments fell sharply from their earlier prominence.
- SVG files recovered from a low April share to account for 26% of attacks by June.
- Email-embedded URLs regained the largest percentage share in June, although their raw volume remained much lower than in prior months.
- DOC and DOCX files continued to appear, albeit at reduced proportions.
QR Code Phishing Retreats, but Remains Relevant
QR code phishing, often called quishing, also declined throughout Q2. After reaching approximately 18.7 million attacks in March, volume dropped for three consecutive months and closed June at around 8.3 million attacks.The decline is significant, but 8.3 million attacks in a single month is not a niche problem. QR code phishing remains a major threat because it is designed to move victims away from corporate protections. A QR code embedded in an email attachment can push a user to scan the image with a personal smartphone, where enterprise browser controls, endpoint sensors, and managed identity protections may be weaker or absent.
PDF files remained the most common vehicle for QR code lures, but their dominance weakened significantly after April. DOC and DOCX attachments gained share, reaching 40% of QR code payloads in June.
That swap is a reminder that attackers are testing user behavior, not merely file types. A fake voicemail notice, secure-document alert, invoice, policy update, or shared-file notification can be placed inside almost any attachment format. The format is only the wrapper.
Notably, email-embedded QR codes nearly disappeared after a sharp surge in March. This may indicate that attachment-based delivery was proving more reliable, better able to evade filtering, or more persuasive to recipients who expect documents to contain QR codes for “secure access.”
Credential Theft Still Defines the Email Threat Landscape
Despite the visibility of malware campaigns, the central goal of email attacks in Q2 was overwhelmingly credential phishing. Between 94% and 96% of payload-based attacks focused on getting users to disclose sign-in information or interact with spoofed authentication prompts.This reflects the continuing value of cloud identity. A stolen password, session token, or approved multifactor authentication prompt can give an attacker access to email, Teams chats, SharePoint files, OneDrive content, financial records, and internal communications. In many cases, that access is more valuable than immediately deploying malware.
Why Identity Is the Primary Prize
A compromised identity can enable an attacker to:- Search mailboxes for payment discussions, contracts, and customer data.
- Impersonate an employee in ongoing email threads.
- Register malicious OAuth applications or consent to risky permissions.
- Create forwarding rules to quietly monitor communications.
- Target colleagues using trusted internal accounts.
- Conduct business email compromise from a legitimate mailbox.
- Use cloud storage and collaboration tools to find additional targets.
- Escalate from one compromised account toward higher-value identities.
HTML and PDF Continue to Lead
HTML attachments held the top position among malicious payload types during Q2, accounting for roughly 35% to 41% of attacks. PDFs ranked second, representing approximately 24% to 31%.Neither format should be treated as inherently suspicious. Both are deeply embedded in legitimate business processes. That is precisely why they are useful to attackers.
An HTML attachment can imitate a sign-in page locally, display a fake security notice, or redirect a browser to a credential theft site. A PDF can carry a QR code, a button, a deceptive document-sharing link, or a carefully staged request to “view protected content.”
The rise of ICS calendar invitations deserves special attention. Although calendar files represented only a small portion of overall payloads, they increased sharply in June. This matters because calendar invitations can create a different interaction model from a conventional email attachment. A malicious link may appear in the calendar experience and persist as an upcoming event, increasing the chance that a recipient revisits it later without remembering the original email context.
Business Email Compromise: Less Malware, More Scale
Business email compromise remained a major component of the Q2 threat landscape, even though the overall volume returned to historical norms after an unusual April spike. Nearly 9 million BEC attacks were observed in April, a sudden increase that more than doubled the volume seen in previous months. By May and June, activity had returned to roughly 3.4 million and 3.9 million attacks respectively.The temporary spike appears to have been driven by a small number of very large campaigns rather than a lasting expansion in all BEC activity. That distinction is important. It means defenders should not rely only on monthly averages; a short, high-volume campaign can still create enormous financial risk.
The First Email Is Usually Not the Fraud
Most BEC messages were not direct invoice or wire-transfer demands. Instead, generic conversation starters accounted for the overwhelming majority of initial outreach. Messages such as “Are you available?” or “Are you at your desk?” remain popular because they are low-friction and difficult to classify based on words alone.The attacker’s objective is often to establish engagement before making a request. Once a victim replies, the criminal can tailor the next message, use the recipient’s tone and signature style, and gradually introduce a financial or data-related request.
This approach creates several challenges:
- There may be no malicious link to scan.
- There may be no attachment to detonate.
- The sender may use a newly created but technically authenticated domain.
- The language can be brief, natural, and free from obvious spelling errors.
- The final fraudulent request may arrive only after several exchanges.
Automation Has Changed the Economics of BEC
One June campaign illustrates how mature BEC operations have become. In less than three hours, an automated campaign reached more than 67,000 users across more than 42,000 organizations, with a strong focus on U.S. targets.The campaign used two classic BEC themes:
- A request for aging-report information and customer contact data.
- A payroll-diversion request impersonating a senior executive.
This is a critical evolution in BEC. Historically, the most damaging BEC attacks were associated with manually researched, highly targeted fraud. That model still exists. But automation now allows criminals to combine broad reach with enough personalization to produce a credible first contact.
For finance and HR teams, policy controls must therefore be as strong as email filtering. Payroll changes, bank-account modifications, payment requests, and customer-data disclosures should require out-of-band verification through a known contact method. A reply to the original email thread is not sufficient verification when the mailbox, sender identity, or conversation context may already be compromised.
Microsoft Teams Is Becoming a Primary Social Engineering Surface
The most consequential shift in Q2 may be the continued growth of threats delivered through Microsoft Teams. Attackers increasingly recognize that Teams messages, chats, and calls benefit from an implicit trust advantage. Employees are accustomed to receiving urgent requests, technical support messages, meeting invites, shared links, and internal updates through the platform.A suspicious email can trigger skepticism. A call or chat that appears to come from a colleague, help desk, administrator, or software provider may not.
Vishing Through Teams Surges
Teams-based voice phishing, or vishing, rose sharply during Q2. Average weekly malicious call attempts increased through the quarter, and the final weeks of June recorded the highest weekly volumes observed in the period covered.By the end of Q2, weekly malicious Teams call attempts were nearly ten times higher than the mid-2025 baseline.
The pattern is especially revealing:
- Activity was concentrated on weekdays.
- Calls peaked during business hours, especially between 14:00 and 20:00 UTC.
- The campaigns frequently used technical-support pretexts.
- Attackers often warned of impending account lockouts, security issues, or required updates.
- Many calls went unanswered, ended rapidly, or were rejected, suggesting that platform hardening and user awareness are having some effect.
ClickFix Themes Are Likely to Influence Teams Lures
The increasing use of update-related, scan-related, and software-as-a-service terminology aligns with the broader rise of ClickFix-style social engineering. These attacks often convince a user to copy a command, open the Run dialog, paste content into PowerShell, or complete a supposed security-recovery step.On Windows, that can lead directly to execution of a malicious script or installer. The attacker does not need an exploit if a trusted employee can be persuaded to run the command themselves.
Organizations should establish a simple, unambiguous rule: IT support should never ask users to paste commands into Run, Command Prompt, PowerShell, Terminal, or a browser developer console as part of routine account verification or device repair.
That policy must be communicated repeatedly. It should also be backed by technical restrictions that limit unnecessary scripting, prevent untrusted application execution, and surface suspicious PowerShell activity to endpoint detection tools.
A Multi-Stage Campaign Shows How Trusted Services Can Be Abused
A separate June campaign demonstrated how attackers can combine multiple trusted technologies into a delivery chain that looks safer than it is. The campaign used email, nested EML attachments, calendar invitations, a Microsoft authentication redirect, a public attachment host, a batch file, PowerShell, and a final executable payload.The chain is significant because no single step is uniquely suspicious to an ordinary user:
- The victim receives an internal-looking email referencing financial or staff updates.
- The email contains a nested EML file presented as a Teams archive or voicemail recording.
- The message directs the recipient toward a link associated with a Microsoft sign-in endpoint.
- The authentication flow redirects to an attacker-controlled destination.
- A batch file downloads and runs a final executable through PowerShell.
Security awareness training should evolve accordingly. Employees should be taught to evaluate the requested action rather than relying only on logos, recognizable services, or the apparent cleanliness of a sender’s authentication results.
What Windows and Microsoft 365 Organizations Should Do Now
The Q2 trends point to a defense strategy built around layered controls rather than a single “best” phishing protection.Strengthen Identity Before the Next Credential Campaign
Password-based authentication remains a central weakness because phishing kits are built to collect, relay, and reuse credentials. Organizations should prioritize phishing-resistant methods where possible, including passkeys, FIDO2 security keys, Windows Hello for Business, and certificate-based approaches suited to their environment.At minimum, organizations should:
- Require multifactor authentication for all users.
- Apply stronger controls to administrators, finance staff, HR personnel, and executives.
- Review conditional access policies for risky sign-ins, unmanaged devices, unfamiliar locations, and impossible-travel patterns.
- Disable legacy authentication paths that cannot enforce modern controls.
- Monitor for new inbox rules, unusual OAuth consent activity, and suspicious session behavior.
- Establish rapid account-revocation and session-reset procedures for suspected phishing incidents.
Treat Attachments as Active Content
HTML, PDF, DOCX, SVG, EML, ICS, ZIP, and BAT files each appeared in the Q2 landscape for different reasons. Organizations should not assume that a safe-looking extension means the message is safe.Defensive priorities include:
- Enable attachment detonation and analysis capabilities.
- Block or quarantine executable attachments and scripts where business requirements allow.
- Review whether
.bat,.cmd,.js,.vbs,.iso,.img, and similar high-risk formats are accepted through email. - Use endpoint controls to prevent untrusted scripts and applications from running.
- Maintain application-control policies for Windows devices, especially privileged workstations.
- Restrict users from bypassing browser or operating-system security warnings.
Secure Teams as Seriously as Email
Teams should be governed as a security-sensitive collaboration platform, not merely a messaging client.Organizations should review:
- External access and federation settings.
- Whether users can receive chats or calls from unknown external tenants.
- Guest access policies and lifecycle controls.
- Teams link-scanning protections.
- The process used for IT help desk outreach.
- Procedures for validating unexpected support calls.
- Reporting paths for suspicious Teams messages and calls.
The Strategic Lesson from Q2 2026
The collapse in Tycoon2FA-linked phishing volume is proof that disruption operations can materially affect the criminal services economy. Removing infrastructure, forcing migrations, and increasing the cost of operations can reduce phishing at scale. The sustained Q2 decline in both QR code and CAPTCHA-gated phishing shows that such actions can have effects beyond a single domain or campaign.But the quarter also shows why defenders cannot celebrate too early. Attackers are not standing still. They are shifting toward automation, cloud infrastructure, trusted services, identity theft, calendar workflows, multi-stage delivery chains, and Teams voice calls.
The future of phishing defense will not be decided by whether organizations can block every suspicious email. It will be decided by whether they can prevent a malicious message, chat, call, or attachment from becoming a successful identity compromise, fraudulent payment, or Windows endpoint infection.
For Windows and Microsoft 365 environments, the most effective response is a mature security posture that connects email filtering, collaboration protection, endpoint detection, secure authentication, policy-based controls, and clear human verification procedures. Tycoon2FA’s decline created a valuable window for defenders. The organizations that use it to close operational gaps will be far better positioned when the next phishing platform—or the next trusted-channel social engineering campaign—inevitably arrives.
References
- Primary source: Microsoft
Published: 2026-07-23T15:00:00+00:00
Loading…
www.microsoft.com