Email threat landscape: Q2 2026 trends and insights
In Q2 2026, Microsoft observed approximately 7.6 billion email-based phishing threats, with a decline in monthly volumes from April to June. The disruption of the Tycoon2FA phishing-as-a-service platform by Microsoft's Digital Crimes Unit caused a 92% drop in related phishing activity. QR code phishing and CAPTCHA-gated phishing attacks also saw significant decreases. Credential phishing remained the primary goal, comprising 94-96% of payload-based attacks. Business email compromise activity normalized after a spike in April. Meanwhile, Microsoft Teams-based threats increased sharply, with malicious call attempts nearly ten times higher than mid-2025 levels by the end of the quarter.
AI Analysis
Technical Summary
This campaign report details the email threat landscape in Q2 2026, highlighting a large volume of phishing threats detected by Microsoft. The takedown of the Tycoon2FA phishing-as-a-service platform led to a substantial reduction in phishing volume associated with that service. Other phishing techniques such as QR code phishing and CAPTCHA-gated phishing also declined significantly during the quarter. Credential theft remains the dominant attack objective in payload-based phishing. Business email compromise activity returned to baseline levels after an unusual surge in April. Notably, threats leveraging Microsoft Teams increased markedly, with malicious call attempts rising to nearly tenfold the baseline established in mid-2025. Indicators include multiple malicious domains, file hashes, and URLs linked to phishing campaigns.
Potential Impact
The threat landscape involves massive volumes of phishing attacks primarily aimed at credential theft, posing risks to user account security and organizational data integrity. The disruption of a major phishing-as-a-service platform significantly reduced related phishing activity, indicating the impact of law enforcement actions. The rise in Microsoft Teams-based threats suggests an evolving attack surface targeting collaboration platforms, potentially increasing risk of social engineering and vishing attacks. Business email compromise remains a concern but has stabilized to historical norms after a temporary spike.
Mitigation Recommendations
No official patch or fix applies as this is a threat landscape report rather than a software vulnerability. Organizations should remain vigilant against credential phishing and evolving phishing techniques, particularly those targeting Microsoft Teams. Monitoring for indicators of compromise such as the listed malicious domains and hashes can aid detection. The takedown of Tycoon2FA demonstrates the effectiveness of disrupting phishing infrastructure. Continued user education on phishing risks and cautious handling of unexpected communications are recommended.
Indicators of Compromise
- domain: x2mails.com
- hash: 11420d6d693bf8b19195e6b98fedd03b9bcbc770b6988bc64cb788bfabe1a49d
- hash: 5db1ecbbb2c90c51d81bda138d4300b90ea5eb2885cce1bd921d692214aecbc6
- hash: b5a3346082ac566b4494e6175f1cd9873b64abe6c902db49bd4e8088876c9ead
- domain: acceptable-use-policy-calendly.de
- domain: cocinternal.com
- domain: compliance-protectionoutlook.de
- domain: na.businesshellosign.de
- domain: gadellinet.com
- domain: harteprn.com
- hash: 467f4c566f8a49fa9bc5d36f50f89568
- hash: 99ce8ecb93b9a43c5697bfa9cbd13b7b
- hash: 7d509d135292020a317b0f7a2f444b665396e891
- hash: f5d0ee4f6eb348d10ccaa4f24cae392782b9bfa3
- url: https://t90141296286.p.clickup-attachments.com/t90141296286/fb39c3a9-3161-40ad-847b-0683e0409d6f/Financial_report.bat
- domain: 9i6pokerdepot.com
- domain: ecajovna.sk
- domain: ilyff.com
- domain: j-gmails.com
- domain: cocinternal.cm
- domain: t90141296286.p.clickup-attachments.com
Email threat landscape: Q2 2026 trends and insights
Description
In Q2 2026, Microsoft observed approximately 7.6 billion email-based phishing threats, with a decline in monthly volumes from April to June. The disruption of the Tycoon2FA phishing-as-a-service platform by Microsoft's Digital Crimes Unit caused a 92% drop in related phishing activity. QR code phishing and CAPTCHA-gated phishing attacks also saw significant decreases. Credential phishing remained the primary goal, comprising 94-96% of payload-based attacks. Business email compromise activity normalized after a spike in April. Meanwhile, Microsoft Teams-based threats increased sharply, with malicious call attempts nearly ten times higher than mid-2025 levels by the end of the quarter.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign report details the email threat landscape in Q2 2026, highlighting a large volume of phishing threats detected by Microsoft. The takedown of the Tycoon2FA phishing-as-a-service platform led to a substantial reduction in phishing volume associated with that service. Other phishing techniques such as QR code phishing and CAPTCHA-gated phishing also declined significantly during the quarter. Credential theft remains the dominant attack objective in payload-based phishing. Business email compromise activity returned to baseline levels after an unusual surge in April. Notably, threats leveraging Microsoft Teams increased markedly, with malicious call attempts rising to nearly tenfold the baseline established in mid-2025. Indicators include multiple malicious domains, file hashes, and URLs linked to phishing campaigns.
Potential Impact
The threat landscape involves massive volumes of phishing attacks primarily aimed at credential theft, posing risks to user account security and organizational data integrity. The disruption of a major phishing-as-a-service platform significantly reduced related phishing activity, indicating the impact of law enforcement actions. The rise in Microsoft Teams-based threats suggests an evolving attack surface targeting collaboration platforms, potentially increasing risk of social engineering and vishing attacks. Business email compromise remains a concern but has stabilized to historical norms after a temporary spike.
Mitigation Recommendations
No official patch or fix applies as this is a threat landscape report rather than a software vulnerability. Organizations should remain vigilant against credential phishing and evolving phishing techniques, particularly those targeting Microsoft Teams. Monitoring for indicators of compromise such as the listed malicious domains and hashes can aid detection. The takedown of Tycoon2FA demonstrates the effectiveness of disrupting phishing infrastructure. Continued user education on phishing risks and cautious handling of unexpected communications are recommended.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/"]
- Adversary
- null
- Pulse Id
- 6a6241aa79fc3235d84045f9
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainx2mails.com | — | |
domainacceptable-use-policy-calendly.de | — | |
domaincocinternal.com | — | |
domaincompliance-protectionoutlook.de | — | |
domainna.businesshellosign.de | — | |
domaingadellinet.com | — | |
domainharteprn.com | — | |
domain9i6pokerdepot.com | — | |
domainecajovna.sk | — | |
domainilyff.com | — | |
domainj-gmails.com | — | |
domaincocinternal.cm | — | |
domaint90141296286.p.clickup-attachments.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash11420d6d693bf8b19195e6b98fedd03b9bcbc770b6988bc64cb788bfabe1a49d | — | |
hash5db1ecbbb2c90c51d81bda138d4300b90ea5eb2885cce1bd921d692214aecbc6 | — | |
hashb5a3346082ac566b4494e6175f1cd9873b64abe6c902db49bd4e8088876c9ead | — | |
hash467f4c566f8a49fa9bc5d36f50f89568 | — | |
hash99ce8ecb93b9a43c5697bfa9cbd13b7b | — | |
hash7d509d135292020a317b0f7a2f444b665396e891 | — | |
hashf5d0ee4f6eb348d10ccaa4f24cae392782b9bfa3 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://t90141296286.p.clickup-attachments.com/t90141296286/fb39c3a9-3161-40ad-847b-0683e0409d6f/Financial_report.bat | — |
Threat ID: 6a62a5a29c2644c7f8e9860c
Added to database: 07/23/2026, 23:37:06 UTC
Last enriched: 07/23/2026, 23:56:03 UTC
Last updated: 07/24/2026, 03:45:07 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.