Email threat landscape: Q2 2026 trends and insights

Source: www.microsoft.com/en-us/sec… (Microsoft Security Blog, 23 Jul 2026)

Q2 2026 email threats were dominated by the lingering effects of Microsoft’s March disruption of the Tycoon2FA phishing-as-a-service platform. Phishing volume linked to Tycoon2FA fell 92 % from pre-disruption baselines; both QR-code and CAPTCHA-gated campaigns that previously relied on the service declined sharply and no comparable replacement service emerged at scale. Overall, Microsoft detected ~7.6 billion email-based phishing threats in the quarter (declining modestly from 2.7 B in April to 2.4 B in June). Credential phishing remained the overwhelming payload objective (94–96 %), while traditional malware delivery stayed in the low single digits.

Threat actors continued shifting into Microsoft Teams, with weekly malicious vishing call attempts reaching nearly 10× the mid-2025 baseline by quarter-end. Notable high-velocity campaigns included an automated BEC operation that hit >67 000 users across 42 000 organizations in under three hours and a multi-stage phishing chain that nested EML files inside calendar invitations before abusing a Microsoft authentication redirect. The data illustrate both the measurable impact of infrastructure disruption and the continued migration of social-engineering activity into trusted workplace collaboration tools.

Edward Kiledjian @ekiledjian