Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Email threat landscape: Q2 2026 trends and insights

0
Medium
Published: 07/23/2026 (07/23/2026, 16:30:34 UTC)
Source: AlienVault OTX General

Description

In Q2 2026, Microsoft observed approximately 7.6 billion email-based phishing threats, with a decline in monthly volumes from April to June. The disruption of the Tycoon2FA phishing-as-a-service platform by Microsoft's Digital Crimes Unit caused a 92% drop in related phishing activity. QR code phishing and CAPTCHA-gated phishing attacks also saw significant decreases. Credential phishing remained the primary goal, comprising 94-96% of payload-based attacks. Business email compromise activity normalized after a spike in April. Meanwhile, Microsoft Teams-based threats increased sharply, with malicious call attempts nearly ten times higher than mid-2025 levels by the end of the quarter.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/23/2026, 23:56:03 UTC

Technical Analysis

This campaign report details the email threat landscape in Q2 2026, highlighting a large volume of phishing threats detected by Microsoft. The takedown of the Tycoon2FA phishing-as-a-service platform led to a substantial reduction in phishing volume associated with that service. Other phishing techniques such as QR code phishing and CAPTCHA-gated phishing also declined significantly during the quarter. Credential theft remains the dominant attack objective in payload-based phishing. Business email compromise activity returned to baseline levels after an unusual surge in April. Notably, threats leveraging Microsoft Teams increased markedly, with malicious call attempts rising to nearly tenfold the baseline established in mid-2025. Indicators include multiple malicious domains, file hashes, and URLs linked to phishing campaigns.

Potential Impact

The threat landscape involves massive volumes of phishing attacks primarily aimed at credential theft, posing risks to user account security and organizational data integrity. The disruption of a major phishing-as-a-service platform significantly reduced related phishing activity, indicating the impact of law enforcement actions. The rise in Microsoft Teams-based threats suggests an evolving attack surface targeting collaboration platforms, potentially increasing risk of social engineering and vishing attacks. Business email compromise remains a concern but has stabilized to historical norms after a temporary spike.

Mitigation Recommendations

No official patch or fix applies as this is a threat landscape report rather than a software vulnerability. Organizations should remain vigilant against credential phishing and evolving phishing techniques, particularly those targeting Microsoft Teams. Monitoring for indicators of compromise such as the listed malicious domains and hashes can aid detection. The takedown of Tycoon2FA demonstrates the effectiveness of disrupting phishing infrastructure. Continued user education on phishing risks and cautious handling of unexpected communications are recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/"]
Adversary
null
Pulse Id
6a6241aa79fc3235d84045f9
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainx2mails.com
domainacceptable-use-policy-calendly.de
domaincocinternal.com
domaincompliance-protectionoutlook.de
domainna.businesshellosign.de
domaingadellinet.com
domainharteprn.com
domain9i6pokerdepot.com
domainecajovna.sk
domainilyff.com
domainj-gmails.com
domaincocinternal.cm
domaint90141296286.p.clickup-attachments.com

Hash

ValueDescriptionCopy
hash11420d6d693bf8b19195e6b98fedd03b9bcbc770b6988bc64cb788bfabe1a49d
hash5db1ecbbb2c90c51d81bda138d4300b90ea5eb2885cce1bd921d692214aecbc6
hashb5a3346082ac566b4494e6175f1cd9873b64abe6c902db49bd4e8088876c9ead
hash467f4c566f8a49fa9bc5d36f50f89568
hash99ce8ecb93b9a43c5697bfa9cbd13b7b
hash7d509d135292020a317b0f7a2f444b665396e891
hashf5d0ee4f6eb348d10ccaa4f24cae392782b9bfa3

Url

ValueDescriptionCopy
urlhttps://t90141296286.p.clickup-attachments.com/t90141296286/fb39c3a9-3161-40ad-847b-0683e0409d6f/Financial_report.bat

Threat ID: 6a62a5a29c2644c7f8e9860c

Added to database: 07/23/2026, 23:37:06 UTC

Last enriched: 07/23/2026, 23:56:03 UTC

Last updated: 07/24/2026, 03:45:07 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses