Intel Node
Email threat landscape: Q1 2026 trends and insights
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
In early 2026, email threats increased with a rise in credential phishing, QR code phishing, and CAPTCHA-gated campaigns, highlighted by Microsoft’s disruption of the Tycoon2FA phishing platform which led to a 15% volume decrease and shifts in threat actor tactics. The post Email threat landscape: Q1 2026 trends and insights appeared first on Microsoft Security Blog .
In this article Tycoon2FA disruption impact QR code phishing attacks CAPTCHA tactics Malicious payloads Business email compromise Defending against email threats Microsoft Defender detections During the first quarter of 2026 (January-March), Microsoft Threat Intelligence detected approximately 8. 3 billion email-based phishing threats, with monthly volumes declining slightly from 2. 9 billion in January to 2. 6 billion in March. By the end of the quarter, QR code phishing emerged as the fastest-growing attack vector, more than doubling over the period, while CAPTCHA-gated phishing evolved rapidly across payload types.
Overall, 78% of email threats were link-based, while malicious payloads accounted for 19% of attacks in January—boosted by large HTML and ZIP campaigns—before settling at 13% in both February and March.