Microsoft's review of the second-quarter 2026 email threat landscape delivers both encouraging and uncomfortable news. Activity connected to the Tycoon2FA phishing-as-a-service platform fell dramatically after a Microsoft-led disruption operation, but criminals responded by diversifying their methods and moving deeper into workplace communication channels.
Disruption produced measurable results
Microsoft reported that phishing volume associated with Tycoon2FA dropped 92 percent from its previous baseline. QR-code phishing and campaigns that placed CAPTCHA challenges in front of malicious pages also declined from earlier peaks. This is important evidence that coordinated infrastructure disruption can impose lasting costs on a large criminal service rather than merely forcing a temporary outage.
The wider threat remains enormous, however. Microsoft detected approximately 7.6 billion email-based phishing attempts during the quarter. One automated business email compromise campaign reportedly reached more than 67,000 users at 42,000 organizations in less than three hours, demonstrating how rapidly modern criminal infrastructure can scale.
The attack surface is moving into Teams
The most significant development is the continued growth of Teams-based social engineering, particularly voice phishing. By the end of the quarter, weekly malicious call attempts were nearly ten times the baseline observed in mid-2025. Attackers understand that employees may be more suspicious of an unexpected email than a call or chat apparently coming from a colleague, help desk technician, or business partner.
In my view, organizations must stop treating phishing as an email-only category. Security controls should correlate activity across email, identity, endpoints, Teams, and cloud applications. Help desk procedures should require independent verification before password resets, multifactor authentication changes, remote-access sessions, or device enrollment approvals.
Practical defensive priorities
- Deploy phishing-resistant authentication wherever possible.
- Review external Teams communication and federation policies.
- Require secondary verification for sensitive support requests.
- Monitor unusual calls, chats, authentication prompts, and device registrations as one incident chain.
- Train employees to challenge urgent requests arriving through every communication channel.
The decline of Tycoon2FA proves that takedowns can work. The migration toward Teams proves that defenders cannot rely on a single victory. Criminal services may disappear, but the demand for stolen identities remains, and attackers will follow employees into whichever platform currently earns their trust.
