Microsoft’s Q2 2026 email threat report reveals a phishing ecosystem in transition: the takedown of the notorious Tycoon2FA phishing-as-a-service platform triggered a 92% collapse in its attack volume, even as threat actors pivoted hard into Microsoft Teams-based voice phishing, which surged nearly tenfold from mid-2025 levels.
Following the Digital Crimes Unit’s March disruption of Tycoon2FA’s adversary-in-the-middle (AiTM) infrastructure, the platform’s monthly phishing volume cratered from a 15.1 million baseline to just 1.2 million messages by June, an 8% residual of its former scale.
Attempts to rebuild on Russian.RU domains after being ejected from Cloudflare’s anti-analysis shielding failed to restore its former dominance, with its share of CAPTCHA-gated phishing sinking from 76% in December 2025 to just 12% by June.
Tycoon2FA Takedown Reshapes Q2 2026 Email Threats
Notably, no single successor service has emerged to fill the vacuum, suggesting the takedown fractured rather than merely displaced the PhaaS customer base

QR code phishing, which had peaked at 18.7 million attacks in March, fell for three straight months to close Q2 at 8.3 million, reverting to mid-2025 levels.
Delivery methods rotated meaningfully: PDF attachments slid from 79% to 58% of QR attacks between April and June, while DOC/DOCX payloads climbed to 40%, continuing a recurring swap pattern seen throughout the past year.
CAPTCHA-gated phishing saw an even steeper 81% decline from its March peak, with payload types churning rapidly, PDFs, SVGs, HTML, and embedded URLs each briefly claiming top billing without any format holding dominance for more than a month or two.
“Disruption operations like the Tycoon2FA takedown prove that targeting phishing infrastructure at scale genuinely works, but the real story of Q2 is displacement, not elimination. Attackers didn’t disappear; they simply found Teams calls and calendar invites don’t get scanned the same way email does.”

Credential phishing dominated 94-96% of all payload-based attacks each month, dwarfing traditional malware delivery at just 4-6%. HTML and PDF attachments together made up 60-70% of malicious payloads, while ICS calendar-invite attacks nearly quadrupled in June, exploiting the fact that calendar files inject malicious links without requiring a click.
Business email compromise spiked to nearly 9 million attacks in April, a 121% jump driven by a handful of high-volume campaigns, before settling back to the roughly 3.5-4 million baseline seen throughout the prior year.
Generic conversational lures like “Are you at your desk?” accounted for 87-92% of initial BEC contacts, while fake invoice requests nearly vanished, dropping to under 0.4% of attacks by June.
The most dramatic trend, however, was Microsoft Teams abuse. Vishing call attempts grew 31% from April to May and another 27% into June, hitting record weekly volumes and running at roughly ten times mid-2025 levels.
Attackers increasingly ditched obvious “IT support” branding, with 52% of June’s Teams phishing using generic display names instead, timing calls for 14:00-20:00 UTC on weekdays when targets are most active.
Two campaigns illustrate the sophistication of Q2 threat actors. On June 1, a single actor used Python-scripted emails routed through Amazon SES to hit 67,000 users across 42,000 organizations in under three hours, running aging-report and payroll-diversion lures with tracking pixels to prioritize follow-up.
A separate mid-June campaign targeting 107,000 users nested an EML file and calendar invite inside a “staff updates” phish, abusing a Microsoft OAuth silent sign-in redirect to ultimately deliver a PowerShell-triggered malware dropper via ClickUp’s attachment infrastructure.
Organizations should prioritize Safe Links/Safe Attachments, zero-hour auto purge, phishing-resistant MFA for privileged accounts, and Teams-specific attack simulation training given the vishing surge.
Automatic attack disruption in Defender XDR and Security Copilot’s Phishing Triage agent offer additional layers against these increasingly automated, multi-channel campaigns.