Select a theme from the list.
Insights

From our experts

Latest
OpenAI Test Models Escaped Their Sandbox and Attacked Hugging Face to WinRefluXFS Breaks Through Linux Defenses to Deliver Persistent Root AccessPhishing Leaves the Inbox as Microsoft Sees Teams Attacks SurgeMicrosoft Commits $60 Million to Build a Secure AI Engine for American ScienceGitHub Reprices Security Research as Public Bug Bounties FallStolen Customer Data Becomes a $13 Million Fraud Engine at UpboundUS Defense Supply-Chain Order Pushes Software Provenance Far Beyond the SBOMBit2Watt Research Turns Ordinary GPU Workloads Into a Potential Grid ThreatWindows LegacyHive Flaw Leaves Administrators Weighing Unofficial ProtectionHijacked Security Cameras Become Eyes on NATO Military Supply RoutesEstée Lauder Breach Shows the Long Tail of Oracle Enterprise ExploitationMicrosoft and AMD Build a More Specialized Azure Engine for Enterprise AIOpenAI Test Models Escaped Their Sandbox and Attacked Hugging Face to WinRefluXFS Breaks Through Linux Defenses to Deliver Persistent Root AccessPhishing Leaves the Inbox as Microsoft Sees Teams Attacks SurgeMicrosoft Commits $60 Million to Build a Secure AI Engine for American ScienceGitHub Reprices Security Research as Public Bug Bounties FallStolen Customer Data Becomes a $13 Million Fraud Engine at UpboundUS Defense Supply-Chain Order Pushes Software Provenance Far Beyond the SBOMBit2Watt Research Turns Ordinary GPU Workloads Into a Potential Grid ThreatWindows LegacyHive Flaw Leaves Administrators Weighing Unofficial ProtectionHijacked Security Cameras Become Eyes on NATO Military Supply RoutesEstée Lauder Breach Shows the Long Tail of Oracle Enterprise ExploitationMicrosoft and AMD Build a More Specialized Azure Engine for Enterprise AI
Security Insight

Phishing Leaves the Inbox as Microsoft Sees Teams Attacks Surge

Phishing Leaves the Inbox as Microsoft Sees Teams Attacks Surge
Photo by Pixabay on Pexels

Microsoft's latest threat analysis shows that disruption efforts sharply reduced activity linked to the Tycoon2FA phishing service, but attackers are rapidly shifting toward Microsoft Teams and voice-based social engineering. The findings suggest that email defenses alone cannot protect organizations when criminals can approach employees through calls, chats, calendar invitations, and trusted collaboration platforms.

Microsoft's review of the second-quarter 2026 email threat landscape delivers both encouraging and uncomfortable news. Activity connected to the Tycoon2FA phishing-as-a-service platform fell dramatically after a Microsoft-led disruption operation, but criminals responded by diversifying their methods and moving deeper into workplace communication channels.

Disruption produced measurable results

Microsoft reported that phishing volume associated with Tycoon2FA dropped 92 percent from its previous baseline. QR-code phishing and campaigns that placed CAPTCHA challenges in front of malicious pages also declined from earlier peaks. This is important evidence that coordinated infrastructure disruption can impose lasting costs on a large criminal service rather than merely forcing a temporary outage.

The wider threat remains enormous, however. Microsoft detected approximately 7.6 billion email-based phishing attempts during the quarter. One automated business email compromise campaign reportedly reached more than 67,000 users at 42,000 organizations in less than three hours, demonstrating how rapidly modern criminal infrastructure can scale.

The attack surface is moving into Teams

The most significant development is the continued growth of Teams-based social engineering, particularly voice phishing. By the end of the quarter, weekly malicious call attempts were nearly ten times the baseline observed in mid-2025. Attackers understand that employees may be more suspicious of an unexpected email than a call or chat apparently coming from a colleague, help desk technician, or business partner.

In my view, organizations must stop treating phishing as an email-only category. Security controls should correlate activity across email, identity, endpoints, Teams, and cloud applications. Help desk procedures should require independent verification before password resets, multifactor authentication changes, remote-access sessions, or device enrollment approvals.

Practical defensive priorities

  • Deploy phishing-resistant authentication wherever possible.
  • Review external Teams communication and federation policies.
  • Require secondary verification for sensitive support requests.
  • Monitor unusual calls, chats, authentication prompts, and device registrations as one incident chain.
  • Train employees to challenge urgent requests arriving through every communication channel.

The decline of Tycoon2FA proves that takedowns can work. The migration toward Teams proves that defenders cannot rely on a single victory. Criminal services may disappear, but the demand for stolen identities remains, and attackers will follow employees into whichever platform currently earns their trust.

Talk to our team →

Latest

OpenAI Test Models Escaped Their Sandbox and Attacked Hugging Face to WinJul 24, 2026RefluXFS Breaks Through Linux Defenses to Deliver Persistent Root AccessJul 24, 2026Phishing Leaves the Inbox as Microsoft Sees Teams Attacks SurgeJul 24, 2026Microsoft Commits $60 Million to Build a Secure AI Engine for American ScienceJul 23, 2026GitHub Reprices Security Research as Public Bug Bounties FallJul 23, 2026Stolen Customer Data Becomes a $13 Million Fraud Engine at UpboundJul 23, 2026

Most read

1Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System2Global CMS Exploitation Wave Plants Webshells on Business Websites3Microsoft Prepares Windows Customers for a Faster Era of AI-Driven Patching4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards