Email threat landscape: Q2 2026 trends and insights
In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly automated and multi-stage attack chains. The post Email threat landscape: Q2 2026 trends and insights appeared first on Microsoft Security Blog .
Source: Microsoft Security Blog · July 25, 2026 at 11:33 PM · AI-assisted report
KUALA LUMPUR, 26 JULY 2026 —
Listen to this article
DomainFork Audio · read aloud
In the second quarter of 2026, the email threat landscape continued to evolve, with Microsoft's disruption of the Tycoon2FA phishing platform in March having a lasting impact on phishing techniques. The effects of this disruption contributed to sustained declines in several major phishing techniques, including QR code phishing and CAPTCHA-gated phishing, which fell by 92% from pre-disruption averages.
Market Impact
Meanwhile, threat actors expanded into Teams-based social engineering and employed increasingly automated and multi-stage attack chains, highlighting the adaptability of these actors in the face of disruption efforts.
The second quarter of 2026 was marked by a significant decline in phishing volume linked to the Tycoon2FA platform, with a 92% drop from pre-disruption averages. This decline was evident in the reduction of QR code phishing and CAPTCHA-gated phishing, which both fell from their March highs.
Despite ongoing efforts to rebuild operations, Tycoon2FA did not recover its previous scale or influence during the quarter, and no single service emerged to replace the platform at a comparable scale. This trend reflects the measurable impact that disruption operations can have on phishing ecosystems and the adaptability of threat actors as they diversify delivery channels.
Microsoft Threat Intelligence observed continued growth in Teams-based social engineering, particularly voice phishing (vishing), with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by the end of the quarter. This activity illustrates how threat actors continue to expand beyond email into trusted workplace communication platforms where communications may appear more trustworthy to users.
The growth of Teams-based threats is a significant concern, as these attacks can bypass traditional security measures and exploit the perceived legitimacy of colleague-initiated chats. Microsoft detected approximately 7.6 billion email-based phishing threats throughout the quarter, with monthly volumes declining modestly from 2.7 billion in April to 2.4 billion in June.
Credential phishing remained the dominant objective behind malicious payloads, accounting for 94-96% of all payload-based attacks each month. These credential phishing payloads either linked users to phishing pages or locally loaded spoofed sign-in screens on a user's device. Traditional malware delivery represented just 4-6% of payloads, consistent with its long-term decline.
Business email compromise (BEC) activity largely returned to historical norms after a brief, anomalous surge in April, which saw nearly 9 million attacks, a 121% increase from March. The composition of BEC attacks remained consistent throughout the quarter, with generic outreach messages accounting for 87-92% of initial contact emails each month.
The disruption operation that Microsoft's Digital Crimes Unit launched against Tycoon2FA infrastructure in early March continued to produce measurable results throughout the second quarter of 2026. After falling 15% in March and another 22% in April, Tycoon2FA-linked phishing volume dropped 74% in May to just 1.5 million messages, then fell another 20% in June to 1.2 million, the lowest monthly volumes observed in at least a year.
For reference, the average monthly volume of phishing messages linked to Tycoon2FA during the second half of 2025 was 15.1 million. By the end of the quarter, volumes were running at roughly 8% of that baseline, representing a 92% total decline since the disruption operation began.
The decline of Tycoon2FA has had a significant impact on the phishing ecosystem, with no single service emerging to replace the platform at a comparable scale. This has contributed to the sustained decline in CAPTCHA-gated phishing activity overall. CAPTCHA-gated phishing declined sharply throughout the quarter, with volume falling 32% in April to 8.2 million, then dropping another 65% in May and 24% in June, closing the quarter at just 2.2 million attacks.
Since the March peak, CAPTCHA-gated phishing has fallen more than 81%, reaching its lowest monthly volume in more than a year. The delivery methods used in QR code attacks also shifted during the quarter, with PDF attachments remaining the dominant vehicle throughout.
The growth of Teams-based social engineering and the increasing use of automated and multi-stage attack chains pose significant challenges for organizations seeking to protect themselves from email-based threats. As threat actors continue to evolve and adapt, it is essential for organizations to prioritize defensive measures and stay informed about the latest trends and insights in the email threat landscape.
Microsoft's recommendations and Defender detections can help organizations identify and mitigate evolving threats, but it is for organizations to remain vigilant and proactive in their security efforts. The email threat landscape will likely continue to evolve in the coming months, with new threats and challenges emerging as threat actors adapt to disruption efforts and develop new tactics, techniques, and procedures.
In the Malaysian context, the trends and insights from the second quarter of 2026 highlight the importance of being aware of the evolving email threat landscape and taking proactive measures to protect against phishing and other email-based threats. As the region's digital economy continues to grow, it is essential for organizations and individuals to prioritize cybersecurity and stay informed about the latest threats and trends.
By doing so, they can help protect themselves and their organizations from the increasingly sophisticated and automated threats that are emerging in the email threat landscape. Details not yet available on the specific impact of these trends on the Malaysian economy, but it is clear that the threat landscape will continue to evolve and pose significant challenges for organizations and individuals in the region.
Related: Microsoft