CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Email threat landscape: Q2 2026 trends and insights

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3123

As cited

Copy frozen at (site build).

threat intel

Email threat landscape: Q2 2026 trends and insights

Microsoft's disruption of the Tycoon2FA phishing-as-a-service platform in March 2026 produced sustained impact through Q2, reducing associated phishing volume by 92% overall with no comparable replacement service emerging. Microsoft Threat Intelligence detected approximately 7.6 billion email phishing threats in Q2 2026, though monthly volumes declined modestly from April to June, with credential phishing remaining the primary payload objective. Threat actors expanded beyond email into Microsoft Teams-based social engineering and voice phishing, with malicious call attempts reaching nearly ten times mid-2025 baselines by quarter end.

Why it matters: Security teams should track that major platform disruptions can significantly reduce phishing at scale, but monitor the shift of threat actor activity toward voice and Teams-based channels where user trust may be higher and detection gaps wider.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Email threat landscape: Q2 2026 trends and insights

Microsoft's disruption of the Tycoon2FA phishing-as-a-service platform in March 2026 produced sustained impact through Q2, reducing associated phishing volume by 92% overall with no comparable replacement service emerging. Microsoft Threat Intelligence detected approximately 7.6 billion email phishing threats in Q2 2026, though monthly volumes declined modestly from April to June, with credential phishing remaining the primary payload objective. Threat actors expanded beyond email into Microsoft Teams-based social engineering and voice phishing, with malicious call attempts reaching nearly ten times mid-2025 baselines by quarter end.

Why it matters: Security teams should track that major platform disruptions can significantly reduce phishing at scale, but monitor the shift of threat actor activity toward voice and Teams-based channels where user trust may be higher and detection gaps wider.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary