Intel Node
Email threat landscape: Q2 2026 trends and insights
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly automated and multi-stage attack chains. The post Email threat landscape: Q2 2026 trends and insights appeared first on Microsoft Security Blog .
In this article Tycoon2FA Q2 disruption impact QR code phishing attacks CAPTCHA-gated phishing tactics Malicious payloads Business email compromise Microsoft Teams threats Notable phishing campaigns Mitigation and protection guidance Indicators of compromise (IOCs) The second quarter of 2026 (April–June) was largely defined by the continuing downstream effects following Microsoft’s Digital Crimes Unit-led disruption efforts against the Tycoon2FA phishing-as-a-service (PhaaS) platform in March.
Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs. Despite ongoing efforts to rebuild operations, Tycoon2FA did not recover its previous scale or influence during Q2, and no single service emerged to replace the platform at comparable scale.