Phishing & Social Engineering
Tycoon2fa's 92% collapse and the quiet rise of teams vishing
Microsoft's Q2 2026 threat data shows the Tycoon2FA disruption cut its phishing volume by 92%, while Teams vishing grew to 10x the 2025 baseline, signaling a shift toward trusted workplace channels.
Emmanuel Fabrice Omgbwa Yasse AI-assisted
2026-08-04 · 5 min read

Tycoon2fa aftermath: measuring the disruption’s lasting effect
Microsoft Threat Intelligence’s Q2 2026 email threat report demonstrates disruption at scale. The March takedown of the Tycoon2FA phishing-as-a-service platform by Microsoft’s Digital Crimes Unit cut its monthly volume from an average of 15.1 million messages during the second half of 2025 to just 1.2 million by June, a 92% decline since the operation began. By the end of Q2, Tycoon2FA was running at roughly 8% of its pre-disruption baseline, and no single service had emerged to replace it at comparable scale. For context on how Microsoft’s cyber capabilities underpin such disruptions, see the GigaWiper backdoor analysis.
The platform’s share of CAPTCHA-gated phishing sites fell from 41% in March to 12% by June, down from a peak of 76% in December 2025. QR code campaigns redirecting to Tycoon2FA domains dropped from 20% of such attacks in March to 14% in June. More than 40% of newly observed Tycoon2FA domains used .RU registrations throughout the quarter, showing that attackers continued trying to find replacement hosting after being forced off Cloudflare’s anti-analysis infrastructure, though with less success.
Ripple effects on QR code and CAPTCHA-gated phishing
The Tycoon2FA takedown drove correlated declines across two phishing tactics it had dominated. QR code phishing peaked at 18.7 million attacks in March, the highest in at least a year, then fell for three consecutive months, closing June at 8.3 million attacks. CAPTCHA-gated phishing dropped even more sharply, from nearly 12 million attacks in March to 2.2 million in June, an 81% decline. The broader landscape of AI-powered phishing is explored in this report on traditional defenses failing.
Delivery methods rotated in a pattern seen throughout the past year. In QR code attacks, PDF attachments peaked at 79% of payloads in April then fell to 58% by June, while DOC/DOCX files rose from near zero to 40%. Email-embedded QR codes, which had surged in March, effectively disappeared in Q2. In CAPTCHA-gated attacks, HTML attachments declined to near single-digit shares, while email-embedded URLs reclaimed the top spot in June as every other format dropped in raw volume. No single service filled the gap left by Tycoon2FA, and operators are rotating through alternative formats rather than settling on one.
Teams-based threats fill the gap
The biggest shift in Q2 was the acceleration of social engineering on Microsoft Teams. While email phishing volumes declined overall, Teams-based voice phishing grew sharply. Average weekly malicious call attempts rose 31% from April to May and another 27% into June, with the final two weeks of June recording the highest weekly volumes on record. Since the start of 2026, weekly vishing attempts have increased roughly 80% and now run at nearly ten times the mid-2025 baseline. Similar impersonation risks have been flagged on other platforms, as WhatsApp’s username reservations demonstrated.
Attackers timed these calls for maximum engagement, with the heaviest activity between 14:00 and 20:00 UTC, Monday through Friday, and near-zero weekend traffic. Display names on Teams phishing accounts shifted away from obvious IT support branding; by June, 52% used generic names rather than help-desk labels. Teams-based phishing volume also grew steadily, rising 19% from March to April and another 10% into June. Unlike email, Teams traffic bypasses secure email gateways and benefits from the perceived legitimacy of a colleague-initiated chat.
BEC anomaly and the credential phishing backbone
Business email compromise saw one anomalous month. In April, BEC attacks surged to nearly 9 million, a 121% increase from March and more than double any previous month. The spike was short-lived. Volume fell 62% in May to 3.4 million and settled at 3.9 million in June, both consistent with the prior year’s monthly baseline. The April surge was driven by a small number of high-volume campaigns rather than a fundamental escalation.
Credential phishing remained the dominant payload objective throughout Q2, accounting for 94 to 96% of all payload-based attacks each month. HTML and PDF attachments were the most common delivery formats, together representing roughly 60 to 70% of payloads. A notable automated BEC campaign on June 1 reached over 67,000 users across 42,000 organizations in under three hours, using scripted message generation through the Amazon SES API to impersonate executives and request aging reports or payroll diversions. Messages were sent from a DKIM-signed Slovak domain, passed SPF and DKIM, and used role-based mailboxes and open-tracking pixels to prioritize follow-up.
A second campaign, observed June 14, 15, targeted more than 107,000 users with a multi-stage chain. It used a nested EML file disguised as a Teams archive recording and a calendar invitation to silently redirect victims through Microsoft’s OAuth endpoint, eventually dropping a Windows batch file that installed malware from a remote host. The attack routed through legitimate authentication infrastructure, making it harder for scanners to classify as malicious. For a look at how attackers weaponize OAuth token theft, see the ToddyCat APT’s Umbrij malware analysis.
What the Q2 data tells us
The Tycoon2FA case shows that coordinated platform takedowns can produce lasting results when paired with persistent follow-up. But the rapid growth of Teams vishing shows that attackers are resilient beyond simply finding a new phishing kit vendor. They are migrating to channels where trust is built into the protocol and traditional email defenses do not follow. This broader shift toward autonomous adversarial tactics is examined in this report on AI agents rewriting cybersecurity.
For defenders, the report makes clear that collaboration tools must be treated as primary attack surfaces. Email remains the largest vector by raw volume, but the growth rate of Teams-based threats suggests the next wave of phishing will look more like a phone call and less like a spam folder. User awareness training should now cover voice-based social engineering on work platforms, and conditional access policies should require phishing-resistant MFA for collaboration applications.
- Source : Tycoon2fa's 92% collapse and the quiet rise of teams vishing — 2026-07-23
Get the tech essentials in 3 minutes every morning
One email, every weekday, with what actually matters in AI and tech.