What Microsoft’s Q2 phishing report says about QR codes, fake CAPTCHAs and Teams attacks

Microsoft detected approximately 7.6 billion email-based phishing threats during the second quarter of 2026, down from about 8.3 billion in Q1. The decline is encouraging, but Microsoft’s data shows that attackers are changing tactics rather than disappearing. QR-code and CAPTCHA-gated phishing fell sharply, while Microsoft Teams-based social engineering and voice phishing continued to grow.

The full figures are available in Microsoft’s Q2 2026 email threat report.

What Microsoft saw in Q2 2026

Microsoft’s disruption of the Tycoon2FA phishing-as-a-service platform in March continued to affect activity throughout Q2. By June, phishing messages linked to Tycoon2FA were running at about 8% of their average monthly level during the second half of 2025, representing a 92% decline from that baseline.

TechniqueWhat Microsoft recorded
Email phishingApproximately 7.6 billion threats during Q2, compared with 8.3 billion in Q1
QR-code phishingFell from 18.7 million attacks in March to 8.3 million in June
CAPTCHA-gated phishingFell from nearly 12 million attacks in March to 2.2 million in June
Teams phishingDetected attacks rose through Q2, including a 10% increase from May to June
Teams voice phishingWeekly malicious calls reached nearly 10 times the mid-2025 baseline by late June

QR-code phishing did not disappear. PDF attachments still accounted for 58% of QR-code attacks in June, while DOC and DOCX files accounted for 40%. Maintaining appropriate email security services and continuing user awareness training therefore remains important.

Fake CAPTCHAs are down, not gone

CAPTCHA-gated phishing fell by more than 81% from March to June. However, the technique is no longer confined to Tycoon2FA. Microsoft observed other phishing kits continuing to use CAPTCHA pages and frequently changing delivery methods.

Credential theft remained the objective behind 94% to 96% of malicious payload-based attacks during Q2. HTML and PDF attachments together accounted for roughly 60% to 70% of malicious payloads each month.

That makes technical controls only one part of the defence. Staff should understand why an unexpected CAPTCHA, sign-in page or attachment can still be dangerous. Regular anti phishing services and training can help employees recognise these patterns.

Teams and voice phishing are growing

The clearest shift was towards Microsoft Teams. Detected Teams phishing rose 19% from March to April, remained broadly level in May and increased another 10% in June.

Voice phishing grew more quickly. Weekly malicious Teams call attempts increased about 80% from the beginning of 2026 and were running at nearly 10 times their mid-2025 baseline by the end of June. Technical-support impersonation remained a prominent tactic, with attackers pretending to be an organisation’s IT team and warning users about account problems.

Organisations should treat unexpected Teams messages and calls with the same caution as suspicious emails. MDR services can support the detection and investigation of suspicious activity across identities and endpoints, while dark web monitoring may identify exposed credentials that could increase account-takeover risk.

What UK businesses should take from the figures

The Cyber Security Breaches Survey 2025/2026 found that 38% of UK businesses experienced phishing during the previous 12 months, making it the most commonly reported cyber attack. Impersonation affected 12% of businesses.

The financial impact varies significantly. The median perceived cost of the most disruptive breach was £0 across all affected businesses because many attacks caused no direct financial loss. However, the highest-cost 5% of cases reached at least £4,000, rising to £10,000 among medium and large businesses.

Publishing a clear help-desk procedure is one of the IT management tasks that quietly get neglected. Employees should know how genuine IT staff will contact them and how to verify unusual requests independently.

Businesses should also consider whether their managed SOC services provide visibility beyond email, including identity, endpoint and collaboration-platform activity.

Frequently asked questions

Is QR-code phishing becoming less dangerous?

No. Microsoft recorded a substantial decline in volume during Q2, but QR-code phishing remains active and can redirect users to credential-stealing websites.

Can phishing happen through Microsoft Teams?

Yes. Microsoft observed increasing Teams-based phishing and voice attacks during Q2 2026. Attackers commonly impersonate IT support or other trusted contacts.

What should staff do with an unexpected IT call?

Do not provide passwords, approve unexpected MFA prompts or run software simply because someone claims to be IT support. End the interaction and contact your organisation’s genuine help desk through an independently verified channel.

The main lesson from Q2 is that a fall in email phishing does not mean the overall social-engineering threat has gone away. Defences need to cover email, identities, endpoints, Teams and the people using them.

The threat did not go away in Q2. It changed shape. If you want help closing the gap across email, Teams and your wider setup, Northern Star’s managed IT support in London can help you tighten things without slowing your team down. Get in touch for a straight conversation about where you stand.