Email threat landscape: Q2 2026 trends and insights
During Q2 2026, Microsoft detected approximately 7.6 billion email-based phishing threats, with monthly volumes declining from 2.7 billion in April to 2.4 billion in June. The quarter was significantly shaped by the downstream effects of Microsoft's Digital Crimes Unit disruption of the Tycoon2FA phishing-as-a-service platform in March, resulting in a 92% decline in associated phishing volume. QR code phishing attacks peaked at 18.7 monthly attacks in March before declining 48% by June, while CAPTCHA-gated phishing fell 81% from its March high. Credential phishing remained the dominant objective, accounting for 94-96% of all payload-based attacks. Business email compromise activity returned to historical norms after an anomalous April surge. Microsoft Teams-based threats grew substantially, with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by quarter end.
AI Analysis
Technical Summary
This campaign report details the email threat landscape in Q2 2026, highlighting a large volume of phishing threats detected by Microsoft. The takedown of the Tycoon2FA phishing-as-a-service platform led to a substantial reduction in phishing volume associated with that service. Other phishing techniques such as QR code phishing and CAPTCHA-gated phishing also declined significantly during the quarter. Credential theft remains the dominant attack objective in payload-based phishing. Business email compromise activity returned to baseline levels after an unusual surge in April. Notably, threats leveraging Microsoft Teams increased markedly, with malicious call attempts rising to nearly tenfold the baseline established in mid-2025. Indicators include multiple malicious domains, file hashes, and URLs linked to phishing campaigns.
Potential Impact
The threat landscape involves massive volumes of phishing attacks primarily aimed at credential theft, posing risks to user account security and organizational data integrity. The disruption of a major phishing-as-a-service platform significantly reduced related phishing activity, indicating the impact of law enforcement actions. The rise in Microsoft Teams-based threats suggests an evolving attack surface targeting collaboration platforms, potentially increasing risk of social engineering and vishing attacks. Business email compromise remains a concern but has stabilized to historical norms after a temporary spike.
Mitigation Recommendations
No official patch or fix applies as this is a threat landscape report rather than a software vulnerability. Organizations should remain vigilant against credential phishing and evolving phishing techniques, particularly those targeting Microsoft Teams. Monitoring for indicators of compromise such as the listed malicious domains and hashes can aid detection. The takedown of Tycoon2FA demonstrates the effectiveness of disrupting phishing infrastructure. Continued user education on phishing risks and cautious handling of unexpected communications are recommended.
Indicators of Compromise
- domain: x2mails.com
- hash: 11420d6d693bf8b19195e6b98fedd03b9bcbc770b6988bc64cb788bfabe1a49d
- hash: 5db1ecbbb2c90c51d81bda138d4300b90ea5eb2885cce1bd921d692214aecbc6
- hash: b5a3346082ac566b4494e6175f1cd9873b64abe6c902db49bd4e8088876c9ead
- domain: acceptable-use-policy-calendly.de
- domain: cocinternal.com
- domain: compliance-protectionoutlook.de
- domain: na.businesshellosign.de
- domain: gadellinet.com
- domain: harteprn.com
- hash: 467f4c566f8a49fa9bc5d36f50f89568
- hash: 99ce8ecb93b9a43c5697bfa9cbd13b7b
- hash: 7d509d135292020a317b0f7a2f444b665396e891
- hash: f5d0ee4f6eb348d10ccaa4f24cae392782b9bfa3
- url: https://t90141296286.p.clickup-attachments.com/t90141296286/fb39c3a9-3161-40ad-847b-0683e0409d6f/Financial_report.bat
- domain: 9i6pokerdepot.com
- domain: ecajovna.sk
- domain: ilyff.com
- domain: j-gmails.com
- domain: cocinternal.cm
- domain: t90141296286.p.clickup-attachments.com
Email threat landscape: Q2 2026 trends and insights
Description
During Q2 2026, Microsoft detected approximately 7.6 billion email-based phishing threats, with monthly volumes declining from 2.7 billion in April to 2.4 billion in June. The quarter was significantly shaped by the downstream effects of Microsoft's Digital Crimes Unit disruption of the Tycoon2FA phishing-as-a-service platform in March, resulting in a 92% decline in associated phishing volume. QR code phishing attacks peaked at 18.7 monthly attacks in March before declining 48% by June, while CAPTCHA-gated phishing fell 81% from its March high. Credential phishing remained the dominant objective, accounting for 94-96% of all payload-based attacks. Business email compromise activity returned to historical norms after an anomalous April surge. Microsoft Teams-based threats grew substantially, with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by quarter end.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign report details the email threat landscape in Q2 2026, highlighting a large volume of phishing threats detected by Microsoft. The takedown of the Tycoon2FA phishing-as-a-service platform led to a substantial reduction in phishing volume associated with that service. Other phishing techniques such as QR code phishing and CAPTCHA-gated phishing also declined significantly during the quarter. Credential theft remains the dominant attack objective in payload-based phishing. Business email compromise activity returned to baseline levels after an unusual surge in April. Notably, threats leveraging Microsoft Teams increased markedly, with malicious call attempts rising to nearly tenfold the baseline established in mid-2025. Indicators include multiple malicious domains, file hashes, and URLs linked to phishing campaigns.
Potential Impact
The threat landscape involves massive volumes of phishing attacks primarily aimed at credential theft, posing risks to user account security and organizational data integrity. The disruption of a major phishing-as-a-service platform significantly reduced related phishing activity, indicating the impact of law enforcement actions. The rise in Microsoft Teams-based threats suggests an evolving attack surface targeting collaboration platforms, potentially increasing risk of social engineering and vishing attacks. Business email compromise remains a concern but has stabilized to historical norms after a temporary spike.
Defensive Guidance
No official patch or fix applies as this is a threat landscape report rather than a software vulnerability. Organizations should remain vigilant against credential phishing and evolving phishing techniques, particularly those targeting Microsoft Teams. Monitoring for indicators of compromise such as the listed malicious domains and hashes can aid detection. The takedown of Tycoon2FA demonstrates the effectiveness of disrupting phishing infrastructure. Continued user education on phishing risks and cautious handling of unexpected communications are recommended.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/"]
- Adversary
- null
- Pulse Id
- 6a6241aa79fc3235d84045f9
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainx2mails.com | — | |
domainacceptable-use-policy-calendly.de | — | |
domaincocinternal.com | — | |
domaincompliance-protectionoutlook.de | — | |
domainna.businesshellosign.de | — | |
domaingadellinet.com | — | |
domainharteprn.com | — | |
domain9i6pokerdepot.com | — | |
domainecajovna.sk | — | |
domainilyff.com | — | |
domainj-gmails.com | — | |
domaincocinternal.cm | — | |
domaint90141296286.p.clickup-attachments.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash11420d6d693bf8b19195e6b98fedd03b9bcbc770b6988bc64cb788bfabe1a49d | — | |
hash5db1ecbbb2c90c51d81bda138d4300b90ea5eb2885cce1bd921d692214aecbc6 | — | |
hashb5a3346082ac566b4494e6175f1cd9873b64abe6c902db49bd4e8088876c9ead | — | |
hash467f4c566f8a49fa9bc5d36f50f89568 | — | |
hash99ce8ecb93b9a43c5697bfa9cbd13b7b | — | |
hash7d509d135292020a317b0f7a2f444b665396e891 | — | |
hashf5d0ee4f6eb348d10ccaa4f24cae392782b9bfa3 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://t90141296286.p.clickup-attachments.com/t90141296286/fb39c3a9-3161-40ad-847b-0683e0409d6f/Financial_report.bat | — |
Threat ID: 6a62a5a29c2644c7f8e9860c
Added to database: 07/23/2026, 23:37:06 UTC
Last enriched: 07/23/2026, 23:56:03 UTC
Last updated: 09/05/2026, 04:42:18 UTC
Views: 187
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.