Microsoft’s takedown of the Tycoon2FA phishing-as-a-service platform in March 2026 cratered its traffic by 92% by the end of June, according to newly released Q2 threat data. But while one phishing giant fell, another threat surged: malicious voice calls over Microsoft Teams hit ten times their mid-2025 rate, turning the workplace chat app into a prime social engineering surface.

The numbers tell a stark story. In the second quarter of 2026, Microsoft detected 7.6 billion email-based phishing threats—a slight decline from earlier in the year but still a staggering volume. Credential theft remained the goal behind 94–96% of all malicious payloads. Business email compromise (BEC) continued at industrial scale, with one automated campaign reaching 67,000 users across 42,000 organizations in under three hours. Meanwhile, attackers increasingly bypassed the inbox entirely, targeting employees through Teams calls, chats, and meeting invites.

The Unraveling of a Phishing Powerhouse

Tycoon2FA was not just another phishing kit. It was a full-blown service that let criminals deploy adversary-in-the-middle attacks, capturing credentials and even hijacking authentication sessions. Its infrastructure used QR codes, CAPTCHA gates, and ever-changing file formats to evade detection. During the second half of 2025, the platform was linked to an average of 15.1 million malicious emails per month.

After Microsoft’s Digital Crimes Unit disrupted its infrastructure in March 2026, that number collapsed. Tycoon2FA-linked messages fell to 1.5 million in May and 1.2 million in June—a 92% decline from the earlier baseline. The platform’s share of CAPTCHA-gated phishing pages dropped from 41% in March to just 12% in June, while its share of QR code campaigns fell from 20% to 14% over the same period.

That disruption had a downstream effect on entire categories of attack. CAPTCHA-gated phishing, which peaked at nearly 12 million attacks in March, plummeted 81% to 2.2 million by June. QR code phishing fell from 18.7 million to 8.3 million attacks. For once, a coordinated takedown had dealt a measurable blow to the phishing economy.

But the attackers didn’t pack up. They simply shifted their tactics.

The New Frontier: Your Teams App Is Ringing

While email defenses scored a big win, Microsoft Teams became the hottest new attack surface. Weekly malicious voice call attempts over Teams rose steadily through the quarter, and by late June were nearly ten times higher than the mid-2025 baseline. The calls are deliberately timed: they spike between 14:00 and 20:00 UTC, Monday through Friday—right when employees are most likely to be online and receptive.

The ruse is almost always the same: a caller impersonates IT support, warning of an account lockout or security update. But attackers have gotten smarter about blending in. In June, more than half of Teams phishing attempts used generic display names rather than obvious “Help Desk” labels. They’ve also shifted their email addresses away from support-themed domains toward SaaS and scanning terminology—the same language used in the rising tide of “ClickFix” scams that trick users into running malicious PowerShell commands.

One campaign observed by Microsoft in June shows just how far these multi-stage attacks can go. Employees received an email that appeared to come from their own “Internal Affairs – Financials & Staff Updates” department. Inside was a nested .eml file disguised as a Teams voicemail recording and a calendar invite. Clicking the “Listen to Voicemail” button sent the user through a legitimate-looking Microsoft sign-in page, which then redirected to a payload hosted on ClickUp, a trusted project management platform. That payload—a .bat file—quietly fetched malware from pixeldrain.com using PowerShell.

To the victim, the entire chain looked trustworthy: a real Microsoft login page, a familiar cloud service, and no obvious malware until it was too late.

What This Means for You—Whether You’re an Admin or an Everyday User

For IT administrators and security teams: The perimeter has dissolved. You can no longer assume that securing email is enough. Attackers are now abusing the very collaboration tools your organization relies on. Teams must be governed with the same rigor as email:

  • Review external access settings. Can strangers call or message your users? If so, restrict federation or block external domains unless absolutely necessary.
  • Treat all attachments—HTML, PDF, .eml, .ics, .svg, .docx—as potentially dangerous. Enable detonation and analysis. Block executable attachments and scripts at the mail gateway where possible.
  • Calendar invitations are the new phishing vector. ICS files quadrupled in June; they can inject malicious links into a user’s calendar without requiring a click.
  • BEC attackers are automating rapport-building. Your finance and HR teams must verify any request for payroll changes, wire transfers, or sensitive data via a known, out-of-band channel—never by replying to the same email thread.

For everyday Windows and Microsoft 365 users: A call or chat on Teams is not automatically safe just because it lands in your app. If someone claiming to be from IT asks you to run a command, open a link, or share your credentials, stop. Hang up. Contact your actual help desk through your company’s official portal or phone number. Never paste code into the Run dialog, Command Prompt, or PowerShell on request. That one rule could prevent most ClickFix-style attacks.

For developers and app owners: Multi-tenant app registrations are being abused in phishing chains. Review your Azure AD application permissions. Remove unused redirect URIs. Ensure that your app doesn’t silently forward users to untrusted destinations after authentication.

How We Got Here: A Masterclass in Disruption—and Adaptation

The Tycoon2FA disruption worked because the platform relied on centralized infrastructure. After being forced off Cloudflare, it scrambled to find new hosting and ended up clustering on .ru domains—making it easier to track and block. Without a ready-made replacement at the same scale, many of its affiliate criminals had to downsize or switch to less effective methods.

But the broader phishing industry is vast and decentralized. While Tycoon2FA wilted, other actors leaned into automation, cloud services, and trusted communication channels. They realized that a Teams call can be more persuasive than an email because it feels personal and immediate. They saw that embedding malicious links inside calendar invites or verified cloud attachments could bypass reputation checks. They adopted scripted, high-volume BEC campaigns that needed only a fraction of recipients to reply to become profitable.

The lesson from Q2 2026 is not that email threats are going away. It’s that the attack surface has expanded, and defenders must expand with it.

7 Concrete Steps to Protect Your Organization Right Now

  1. Deploy phishing-resistant MFA. Passwords are stolen in bulk. Move to FIDO2 security keys, Windows Hello for Business, or certificate-based authentication for all users—especially admins, finance, and HR.
  2. Lock down Teams externally. Disable external access unless business-critical. Restrict chat and call initiation to trusted domains only. Enable link scanning and Safe Links for Teams.
  3. Treat attachments as active content. Enable sandbox detonation for email and Teams. Block .bat, .cmd, .js, .vbs, .iso, and other risky file types. Monitor .ics and .eml files closely—they were weaponized heavily in Q2.
  4. Educate users on vishing and ClickFix scams. Run training that includes fake Teams calls and “urgent” PowerShell requests. Make your acceptable use policy clear: IT will never ask you to paste commands or download files from unsolicited chats.
  5. Harden identity and session controls. Use Conditional Access to block logins from unmanaged devices, impossible travel locations, and risky IPs. Review newly created inbox rules and OAuth consent grants—they’re often signs of a successful phish.
  6. Implement DMARC, DKIM, and SPF—but don’t trust them blindly. As the Q2 data shows, attackers can send authenticated email from domains they control. Train users to evaluate the requested action, not just the sender’s domain.
  7. Establish out-of-band verification for financial requests. Payroll changes, invoice payments, and sensitive data disclosures must require secondary confirmation via a known phone number, not a reply to the original message.

What to Watch Next

Microsoft’s report shows that the Tycoon2FA takedown created a rare window of opportunity. But history suggests attackers will eventually find a replacement platform—and they’re already honing their Teams and calendar-based techniques. The next six months will likely bring more ClickFix-style lures, more automated BEC, and more abuse of trusted cloud storage for payload delivery.

For Windows and Microsoft 365 organizations, the defense must now be unified: email security, endpoint protection, identity governance, and collaboration controls operating as one system. The inbox alone isn’t the battlefield anymore. The next phish might not arrive in your email at all—it might just ring your Teams app.