The email threat landscape of the second quarter of 2026 has been defined by complex dynamics reflecting both the effectiveness of law enforcement actions and the remarkable adaptability of malicious actors. While major takedowns of platforms like Tycoon2FA led to drastic reductions in traditional phishing volume, cybercriminals pivoted to less protected vectors, such as voice calls through Microsoft Teams, which experienced exponential growth. For organizations seeking protection, understanding these trends is the first step toward effective cybersecurity.
One of the quarter's most impactful findings is the 92% drop in malicious emails linked to Tycoon2FA after Microsoft's Digital Crimes Unit disruption in March. This decline was neither immediate nor uniform: volumes fell 15% in April, a further 74% in May, and another 20% in June, reaching just 1.2 million messages compared to the 15.1 million average of the second half of 2025. The platform lost its grip on key tactics like QR code phishing and CAPTCHA-gated landing pages, with its CAPTCHA market share falling from 76% to 12%. However, no other service has filled that void at the same scale, suggesting fragmentation of the malicious ecosystem.
QR code phishing, which peaked at 18.7 million attacks in March, steadily declined to 8.3 million in June. More important than the quantitative reduction is the qualitative shift in delivery methods. PDF attachments, which accounted for 79% of attacks in April, fell to 58% in June, while DOC/DOCX files rose to 40%. This cyclical swapping of formats indicates operators are rotating vectors to evade security filters. Furthermore, email-embedded QR codes, which surged 336% in March, virtually disappeared, leaving the field almost exclusively to attachments.
In parallel, CAPTCHA-gated phishing suffered an even sharper collapse: from nearly 12 million attacks in March to just 2.2 million in June, an 81% drop. The rapid rotation of delivery methods continued, with PDFs losing the lead they held in April (63%) and being replaced by email-embedded URLs in June (30%). Tycoon2FA's influence in this tactic fell from 41% in March to 12% in June. For companies relying on fixed-rule security solutions, these changes represent a constant challenge, but also an opportunity to adopt smarter systems, such as those offered by Q2BSTUDIO through its cybersecurity and pentesting platform.
The malicious payload landscape remained dominated by credential theft, accounting for 94% to 96% of all payload-based attacks each month. HTML and PDF files remained the most common formats, with a combined share of 60-70%. SVG files, closely linked to Tycoon2FA, continued their decline to 7%. A notable data point was the surge in ICS files (calendar invitations), which nearly quadrupled in June (+277%), exploiting user trust in calendar notifications to inject malicious links without requiring explicit attachment opening. Such tactics, leveraging everyday process automation, can be countered with intelligent automation solutions, such as those Q2BSTUDIO implements in its process automation projects.
Business email compromise (BEC) saw an anomaly in April with nearly 9 million attacks, a 121% increase from March, but activity returned to normal in May and June with 3.4 and 3.9 million respectively. Most initial attempts (87-92%) remained generic probing messages, such as 'Are you at your desk?', before requesting wire transfers or sensitive documents. Fake invoices, which represented 3.6% of BEC attacks in March, fell to less than 0.4% in June, likely because attackers found that tactic less profitable. Automation also plays a role here: a June campaign used the Amazon SES API to send over 67,000 emails in less than three hours, generating personalized messages with tracking pixels to prioritize targets. This ability to scale attacks programmatically underscores the need for AI and machine learning solutions that can detect anomalous patterns in real time.
The most alarming growth of the quarter occurred in Microsoft Teams threats. Teams-based phishing increased 19% from March to April and another 10% toward June, but the real leap was in vishing (voice phishing): weekly malicious call attempts rose 31% from April to May and another 27% toward June, reaching nearly ten times the mid-2025 baseline. Attackers impersonate IT help desks, warning of an imminent account lockout, and choose work hours (14:00-20:00 UTC) to maximize response chances. Although many calls go unanswered, the trend is clear: cybercriminals are exploiting the trust employees place in collaboration platforms. To mitigate this risk, companies should integrate security solutions that monitor not only email but also messaging and voice channels as part of a comprehensive cybersecurity strategy.
Two notable campaigns illustrate current sophistication. The first, executed on June 1, automated a two-phase BEC attack: first requesting aging reports and then diverting payroll payments to attacker-controlled accounts. The entire process was scripted in Python and sent through Amazon SES, with DKIM-configured domains passing SPF and DKIM checks. The second campaign, between June 14-15, used a nested EML file with a calendar invitation that, when clicked, redirected through Microsoft's sign-in page to a BAT file that downloaded malware from pixeldrain. This multi-stage attack is particularly dangerous because it leverages legitimate Microsoft infrastructure to hide the real destination.
Facing this scenario, companies need a proactive, multi-layered approach. Continuous user training remains essential but is no longer sufficient. Technologies like Safe Links, Safe Attachments, Zero-hour auto purge, and endpoint protection solutions must be implemented. Furthermore, passwordless authentication and phishing-resistant MFA should be mandatory for privileged accounts. Q2BSTUDIO, as a software and technology development company, offers consulting and implementation services in cybersecurity, cloud computing, and automation that enable organizations to build solid defenses. For instance, its cloud services on Azure and AWS help deploy secure and scalable infrastructure, while its artificial intelligence and AI agents solutions can detect anomalous behavior in real time.
In summary, Q2 2026 leaves clear lessons: coordinated takedowns are effective, but attackers adapt quickly. The diversification of vectors, abuse of collaboration platforms, and campaign automation are trends that will continue to evolve. Organizations that invest in a comprehensive cybersecurity strategy, supported by AI, cloud, and automation tools, will be better prepared to face the challenges of the next quarter.




