VYPR
trendPublished Jul 23, 2026· 1 source

Microsoft Q2 2026 Report: Tycoon2FA Disruption Slashes Phishing, Teams Vishing Surges

Microsoft's latest email threat report reveals a 92% drop in Tycoon2FA phishing after a March disruption, but warns of a tenfold increase in Microsoft Teams vishing attempts.

Microsoft's Q2 2026 Email Threat Landscape report highlights significant shifts in the threat environment, largely influenced by the ongoing impact of a March disruption operation against the Tycoon2FA phishing-as-a-service (PhaaS) platform. The report details a dramatic 92% decrease in phishing volume linked to Tycoon2FA, with specific declines observed in QR code and CAPTCHA-gated phishing tactics, which had previously been prominent. Despite efforts by threat actors to rebuild, Tycoon2FA failed to regain its former scale or influence during the second quarter, and no single replacement service emerged to fill the void.

This reduction in Tycoon2FA's activity underscores the effectiveness of targeted disruption operations against phishing ecosystems. However, the report also points to the adaptability of threat actors, who are increasingly diversifying their delivery channels. A notable trend observed is the substantial growth in social engineering attacks targeting Microsoft Teams, particularly voice phishing (vishing). Weekly malicious call attempts on the platform surged to nearly ten times their mid-2025 baseline by the end of Q2, indicating a move by attackers into trusted workplace communication channels where users may be less vigilant.

Overall, Microsoft Threat Intelligence detected approximately 7.6 billion email-based phishing threats during the quarter, with monthly volumes showing a modest decline from 2.7 billion in April to 2.4 billion in June. Credential phishing remained the primary objective for malicious payloads. Business email compromise (BEC) activity, after an anomalous surge in April, largely returned to historical norms. The report also flagged sophisticated campaigns that combined automation, trusted services, and multi-stage delivery chains, including a rapid BEC attack that impacted over 42,000 organizations in under three hours, and a complex phishing campaign utilizing nested EML files and calendar invitations.

The impact of the March disruption on Tycoon2FA's infrastructure and tradecraft was profound. Monthly phishing message volumes linked to the platform plummeted from an average of 15.1 million in the latter half of 2025 to just 1.2 million by June 2026, representing an 8% baseline of its previous operational scale. This decline was mirrored in Tycoon2FA's share of CAPTCHA-gated phishing sites, which fell from a peak of 76% in December 2025 to 12% by June 2026. Similarly, its involvement in QR code phishing campaigns decreased significantly.

Following its removal from Cloudflare, Tycoon2FA increasingly relied on infrastructure hosted on the .RU top-level domain, with over 40% of new domains registered there throughout Q2. While this indicates continued efforts to find alternative hosting, the platform's overall influence in the phishing landscape has been substantially diminished, with a slow pace of recovery.

QR code phishing attacks, which peaked at 18.7 million in March, also saw a decline throughout Q2, falling to 8.3 million by June, returning to mid-2025 levels. The methods used for QR code delivery shifted, with PDF attachments, though still dominant, weakening in their share of attacks after April.

The report emphasizes the need for organizations to stay vigilant against evolving threats, recommending the use of Microsoft Defender detections and prioritizing defensive measures. The insights provided aim to help security teams identify and mitigate emerging risks across email and collaboration platforms.

Synthesized by Vypr AI