As cited
Copy frozen at (site build).
threat intel
Email threat landscape: Q2 2026 trends and insights
Microsoft's disruption of the Tycoon2FA phishing-as-a-service platform in March 2026 produced sustained impact through Q2, reducing associated phishing volume by 92% overall with no comparable replacement service emerging. Microsoft Threat Intelligence detected approximately 7.6 billion email phishing threats in Q2 2026, though monthly volumes declined modestly from April to June, with credential phishing remaining the primary payload objective. Threat actors expanded beyond email into Microsoft Teams-based social engineering and voice phishing, with malicious call attempts reaching nearly ten times mid-2025 baselines by quarter end.
Why it matters: Security teams should track that major platform disruptions can significantly reduce phishing at scale, but monitor the shift of threat actor activity toward voice and Teams-based channels where user trust may be higher and detection gaps wider.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Email threat landscape: Q2 2026 trends and insights
Microsoft's disruption of the Tycoon2FA phishing-as-a-service platform in March 2026 produced sustained impact through Q2, reducing associated phishing volume by 92% overall with no comparable replacement service emerging. Microsoft Threat Intelligence detected approximately 7.6 billion email phishing threats in Q2 2026, though monthly volumes declined modestly from April to June, with credential phishing remaining the primary payload objective. Threat actors expanded beyond email into Microsoft Teams-based social engineering and voice phishing, with malicious call attempts reaching nearly ten times mid-2025 baselines by quarter end.
Why it matters: Security teams should track that major platform disruptions can significantly reduce phishing at scale, but monitor the shift of threat actor activity toward voice and Teams-based channels where user trust may be higher and detection gaps wider.
- Source published
- First seen by Cybersecurity Tracker