Updated
Updated · Computerworld · Jul 24
Microsoft Says Tycoon2FA Takedown Cut Phishing 92% as Teams Lures and BEC Surge
Updated
Updated · Computerworld · Jul 24

Microsoft Says Tycoon2FA Takedown Cut Phishing 92% as Teams Lures and BEC Surge

3 articles · Updated · Computerworld · Jul 24

Summary

  • Tycoon2FA-linked phishing volume fell 92% from pre-disruption averages, with monthly traffic dropping to 1.2 million messages in June after the platform’s takedown, Microsoft said in its Q2 2026 email threat report.
  • That disruption hit older tactics hard: QR-code phishing dropped to 8.3 million attacks in June from 18.7 million in March, while CAPTCHA-gated phishing fell to 2.2 million from 12 million.
  • Attackers shifted instead to Microsoft Teams and automation, with Teams-based phishing rising through Q2 and one scripted BEC campaign reaching 42,000 organizations in under three hours.
  • Microsoft also tracked a separate campaign targeting 107,000 users through nested EML files, calendar invites and a Microsoft authentication redirect to hide malware behind trusted cloud services.
  • Microsoft urged organizations to pair email filtering with phishing-resistant MFA or passkeys, plus tools such as Safe Links and Zero-hour Auto Purge, arguing the defenses stay largely the same even as delivery methods change.

Insights

Microsoft cut Tycoon2FA phishing by 92%, so why are Teams lures and OAuth device-code attacks rising even faster?
If phishing-resistant MFA stops password theft, what still lets attackers abuse real Microsoft sign-ins and steal access anyway?