Jul 26, 2026 · 9 min read
Microsoft Blocked 7.6 Billion Phishing Threats in Q2
Microsoft's Q2 2026 email threat report is a quarter of falling numbers: phishing volume down, QR attacks halved, CAPTCHA gated pages down 81%, and the Tycoon2FA platform down 92% after a March takedown. Read the same quarter through independent telemetry and the good news gets considerably more complicated.
Microsoft detected 7.6 billion phishing threats between April and June 2026, and the trend inside that number went the direction defenders want. April closed at 2.7 billion. June closed at 2.4 billion. Nearly every category in the report fell alongside it, and the steepest drop belonged to Tycoon2FA, a phishing platform that at its peak accounted for roughly 62% of all phishing Microsoft blocked.
Then read CrowdStrike's telemetry from the same period. The operators were rebuilding within days of the takedown, buying fresh infrastructure, running identical tradecraft. Two vendors, one quarter, opposite conclusions. Both are correct, and the gap between them is the most useful thing in the report.
Key Takeaways
- Microsoft detected 7.6 billion phishing threats in Q2 2026, falling from 2.7 billion in April to 2.4 billion in June, according to its Q2 2026 email threat landscape report.
- Tycoon2FA volume fell 92%, from a pre disruption average of 15.1 million messages per month to 1.2 million in June, after the March 4, 2026 Europol and Microsoft takedown seized more than 300 domains.
- CrowdStrike observed Tycoon2FA operators back at early 2026 activity levels within days, procuring fresh IPv6 addresses from a Romanian provider with tactics unchanged from before the seizure.
- Credential phishing made up 94% to 96% of all payload based attacks in every month of Q2 2026, meaning the mailbox itself is the objective rather than a route to one.
- A single business email compromise campaign on June 1, 2026 reached more than 67,000 users across more than 42,000 organizations in 164 minutes, roughly 409 targets per minute, delivered through the Amazon SES API.
What Did Microsoft Actually Measure in Q2 2026?
Microsoft measured a broad, simultaneous decline across almost every phishing category it tracks, with March 2026 serving as the peak month for several of them. The company's quarterly telemetry covers threats blocked across its email security stack, so these are attempts stopped, not successful compromises.
| Category | Peak | June 2026 | Change |
|---|---|---|---|
| Tycoon2FA messages per month | 15.1M (H2 2025 average) | 1.2M | −92% |
| CAPTCHA gated phishing | 12M (March 2026) | 2.2M | −81% |
| QR code phishing attacks | 18.7M (March 2026) | 8.3M | −56% |
| All phishing threats per month | 2.7B (April 2026) | 2.4B | −11% |
The QR figure deserves a footnote, because the delivery mechanism shifted underneath it. PDF carriers fell from 79% of QR attacks in April to 58% in June while Office documents climbed from about 20% to 40%. Attackers did not abandon the technique; they changed the wrapper around it, which is exactly what you would expect once PDF based detection matured.
Did the Tycoon2FA Takedown Actually Work?
It worked at suppressing volume and failed at removing the operators, which are two different outcomes that a single percentage cannot express. On March 4, 2026, Europol and Microsoft, joined by TrendAI, Cloudflare, Proofpoint, SpyCloud and others, seized more than 300 domains tied to the platform. Infosecurity Magazine reported the service had roughly 2,000 subscribers and had cycled through more than 24,000 domains since launching in August 2023, selling adversary in the middle kits that intercept session cookies and one time passcodes.
The decline was staged rather than instant: 15% in March, another 22% in April, a 74% collapse in May to 1.5 million, then a further 20% to 1.2 million in June. That gradient matters. A platform killed outright produces a cliff, not a slope. A slope suggests subscribers draining away as the service degraded, which is a market effect rather than a technical one.
CrowdStrike's post takedown analysis found campaign activity dropped to 25% of baseline on March 4 and 5, then returned to early 2026 levels within days. Researchers documented ten active phishing domains still serving Tycoon2FA pages, eight of eleven tracked login IP addresses procured from Romania based M247 after March 1, and one server that predated the operation entirely. Their conclusion was blunt: the tradecraft did not change. Domain seizures are cheap for defenders and cheap for attackers to replace, a pattern Gblock covered when the Kratos phishing platform was dismantled earlier this month.
Does Falling Volume Mean Falling Risk?
No, and the concentration data in this report is the reason. If disrupting one vendor moves the global phishing curve by this much, the phishing economy is not a diffuse criminal marketplace. It is an oligopoly. Microsoft's own March analysis of the kit put Tycoon2FA at roughly 62% of blocked phishing at its peak, which means about 2,000 paying subscribers were driving a majority of what a hyperscale mail provider was stopping worldwide.
That concentration cuts both ways. It explains why the takedown produced such a visible dent, and it explains why the dent is fragile. Volume is a supply side metric. What defenders care about is conversion, and nothing in a quarterly message count tells you whether the remaining 1.2 million monthly Tycoon2FA messages convert better or worse than the 15.1 million did. A degraded service that sheds its least competent subscribers may well leave behind a more effective residue. Falling attempt counts with unknown success rates is not a security improvement, it is a measurement gap. Gblock's earlier look at Tycoon2FA domain spoofing covers how convincing those messages were before any of this happened.
Why Is Credential Phishing 94% of Payload Attacks?
Because the mailbox stopped being the road to the target and became the target. Credential phishing held between 94% and 96% of all payload based attacks in every single month of Q2 2026, a stability that is more telling than any of the declining numbers. Attackers are not experimenting. They have converged on one objective and one asset class.
Attachment mix supports that reading. HTML files carried 35% to 41% of attacks monthly and PDFs another 24% to 31%, both formats that render a credential capture page locally rather than dropping an executable. SVG usage, which spiked to 23% back in July 2025, fell to about 7%. Meanwhile, calendar invite files quadrupled in June with a 277% jump, and malicious Microsoft Teams call attempts hit nearly ten times the mid 2025 weekly baseline, clustered between 14:00 and 20:00 UTC on weekdays. Attackers are following the working day into whatever channel authenticates you.
Once a session cookie is stolen, password rotation is theatre, which is the same lesson from hijacked Outlook inboxes bypassing MFA. The 94% figure is the industry telling you where to spend detection budget.
How Fast Was the June 1 BEC Campaign?
Fast enough that no human review process could have kept pace with it. Between 14:08 and 16:52 UTC on June 1, 2026, one campaign reached more than 67,000 users across more than 42,000 organizations, per Microsoft's report. That is 164 minutes, roughly 409 recipients and 256 distinct organizations per minute. Delivery ran through the Amazon SES API with messages assembled by Python's standard email.mime library, meaning no custom tooling and no bespoke infrastructure.
Targeting skewed almost entirely to the United States, concentrated in retail and consumer goods (17%), technology and software (15%), and financial services (14%). The operational implication is the part worth internalising: by the time a first report reaches a SOC queue, triage happens, and an indicator is distributed, the campaign has already finished. Two weeks later a separate "staff update" run hit more than 107,000 users at 19,000 organizations across June 14 and 15, using an OAuth redirect through a ClickUp attachment host to deliver a BAT dropper. April's BEC spike to 9 million attacks, a 121% jump on March, corrected to 3.4 million in May and 3.9 million in June, so volume normalised while burst intensity did not.
Why Email Users Should Care
Campaigns that hit 42,000 organizations in under three hours are not built on guesswork about which addresses exist. Automation at that scale rewards target lists that have been validated in advance, and the cheapest validation method available is an invisible tracking pixel, the same transparent 1x1 image that marketing platforms embed to log opens. Load the image, and the sender learns the address is live, actively monitored, roughly where you are, and what client renders your mail. Princeton researchers measuring this at scale found that roughly 30% of emails leak the recipient's address to at least one third party on open, usually deliberately, in "I never signed up for this!" published in the Proceedings on Privacy Enhancing Technologies.
This is reconnaissance, not the attack, and the distinction should be stated plainly. Blocking tracking pixels does not stop credential phishing, will not detect an adversary in the middle proxy, and offers nothing against a stolen session cookie. Every control in this report's defensive picture, phishing resistant authentication and session anomaly detection above all, matters more. What pixel blocking does is deny the reconnaissance layer, so an address contributes no open signal and no engagement data to whoever is compiling lists.
Gblock strips those pixels out of Gmail automatically. Treat it as removing one input from an attacker's targeting model, not as phishing protection, and it is a reasonable piece of a much larger stack.
What Should Security Teams Take From This Quarter?
The quarter argues for reweighting detection toward identity and away from volume metrics. A few concrete shifts follow directly from the data:
- Stop treating blocked message counts as a risk indicator. Track credential submission attempts, anomalous token issuance, and impossible travel sign ins instead, since 94% of payloads are aimed at those exact outcomes.
- Assume takedowns buy weeks, not quarters. CrowdStrike's evidence of rebuilt infrastructure within days means any playbook written around a seized platform staying dead will expire quickly.
- Build automated containment for burst campaigns. A 164 minute delivery window means human in the loop response arrives after the fact; auto quarantine and rapid tenant wide message purge are the only controls operating on that timescale.
- Extend phishing monitoring beyond the inbox. Malicious Teams calls at ten times baseline and calendar invite files up 277% in June show the attack surface widening into every channel that carries an authentication prompt.
- Deploy phishing resistant MFA. NIST SP 800-63B authenticator guidance remains the practical baseline against the adversary in the middle kits this report tracks.
Read carelessly, Microsoft's Q2 report says phishing is receding. Read against independent telemetry, it says something narrower and more useful: coordinated disruption can compress a criminal market's output for a quarter, and the market rebuilds while the graph is still falling. The 92% number is real. So is the fact that the people behind it never left.
Sources: Microsoft Security Blog, Email threat landscape Q2 2026, Microsoft Security Blog, Inside Tycoon2FA, CrowdStrike, and Infosecurity Magazine.