Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

Phishing Leaves the Inbox as Microsoft Sees Teams Attacks Surge

Phishing Leaves the Inbox as Microsoft Sees Teams Attacks Surge
Photo by Pixabay on Pexels

Microsoft's latest threat analysis shows that disruption efforts sharply reduced activity linked to the Tycoon2FA phishing service, but attackers are rapidly shifting toward Microsoft Teams and voice-based social engineering. The findings suggest that email defenses alone cannot protect organizations when criminals can approach employees through calls, chats, calendar invitations, and trusted collaboration platforms.

Microsoft's review of the second-quarter 2026 email threat landscape delivers both encouraging and uncomfortable news. Activity connected to the Tycoon2FA phishing-as-a-service platform fell dramatically after a Microsoft-led disruption operation, but criminals responded by diversifying their methods and moving deeper into workplace communication channels.

Disruption produced measurable results

Microsoft reported that phishing volume associated with Tycoon2FA dropped 92 percent from its previous baseline. QR-code phishing and campaigns that placed CAPTCHA challenges in front of malicious pages also declined from earlier peaks. This is important evidence that coordinated infrastructure disruption can impose lasting costs on a large criminal service rather than merely forcing a temporary outage.

The wider threat remains enormous, however. Microsoft detected approximately 7.6 billion email-based phishing attempts during the quarter. One automated business email compromise campaign reportedly reached more than 67,000 users at 42,000 organizations in less than three hours, demonstrating how rapidly modern criminal infrastructure can scale.

The attack surface is moving into Teams

The most significant development is the continued growth of Teams-based social engineering, particularly voice phishing. By the end of the quarter, weekly malicious call attempts were nearly ten times the baseline observed in mid-2025. Attackers understand that employees may be more suspicious of an unexpected email than a call or chat apparently coming from a colleague, help desk technician, or business partner.

In my view, organizations must stop treating phishing as an email-only category. Security controls should correlate activity across email, identity, endpoints, Teams, and cloud applications. Help desk procedures should require independent verification before password resets, multifactor authentication changes, remote-access sessions, or device enrollment approvals.

Practical defensive priorities

  • Deploy phishing-resistant authentication wherever possible.
  • Review external Teams communication and federation policies.
  • Require secondary verification for sensitive support requests.
  • Monitor unusual calls, chats, authentication prompts, and device registrations as one incident chain.
  • Train employees to challenge urgent requests arriving through every communication channel.

The decline of Tycoon2FA proves that takedowns can work. The migration toward Teams proves that defenders cannot rely on a single victory. Criminal services may disappear, but the demand for stolen identities remains, and attackers will follow employees into whichever platform currently earns their trust.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path