After Tycoon2FA Was Shut Down, Phishing Criminals Went Looking for New Tricks
Microsoft's Q2 2026 email threat report shows that busting a major phishing-for-hire service slashed attack volume by 92%, but criminals quickly pivoted to Microsoft Teams chats and automated email campaigns that hit tens of thousands of organisations in hours.

Key points
- Phishing volume linked to the Tycoon2FA service fell 92% after authorities disrupted it, according to Microsoft's Q2 2026 email threat report.
- A single automated business email compromise campaign reached more than 67,000 users in under three hours during Q2 2026.
- Microsoft Teams-based phishing attacks rose 19% from March to April 2026 and kept climbing through June.
- QR code phishing peaked at 18.7 million attacks in March 2026 before dropping to 8.3 million in June 2026.
- Microsoft recommends passwordless sign-in tools and automatic removal of malicious emails already sitting in inboxes.
A major crackdown on one of the internet's biggest phishing-for-hire services has changed what email fraud looks like, at least for now. Microsoft's quarterly email threat report, first covered by CSO Online, shows that shutting down the Tycoon2FA platform, a service that let criminals rent ready-made phishing kits the way a business rents software, slashed the volume of fake emails it powered by 92%.
That is a big number. But criminals adapted fast.
What was Tycoon2FA, and why does its takedown matter?
Tycoon2FA was a "phishing-as-a-service" platform, meaning it sold ready-to-use fraud tools to criminals who lacked the technical skill to build their own. Customers paid a fee and received everything needed to send convincing fake login pages and steal passwords at scale.
At its height, the platform was behind 12% of all QR code phishing attacks (where criminals hide a malicious link inside a scannable square image) and 14% of CAPTCHA-gated phishing attacks (where victims are shown a "prove you're human" puzzle before being handed a fake login page). These tricks made the scam look more legitimate.
After the disruption, monthly message volume from Tycoon2FA-linked campaigns fell from tens of millions to just 1.2 million in June 2026, the lowest figure Microsoft had recorded in at least a year.
How did criminals respond?
They found other doors. The most notable shift was a move to Microsoft Teams, the workplace chat app used by millions of office workers.
Instead of a suspicious email, victims received a Teams message from an account that looked like a colleague or supplier. Criminals built up trust through conversation before trying to steal login credentials or deliver malware, which is software designed to damage or spy on a device. Teams-based attacks rose 19% from March to April 2026, held steady in May, then climbed another 10% into June.
Two specific campaigns stood out in the quarter.
| Campaign | Scale | Method |
|---|---|---|
| Automated BEC campaign | 67,000+ users reached | Scripted emails via Amazon SES with engagement tracking |
| Multi-stage phishing campaign | 107,000 users targeted | EML files, calendar invites, Microsoft auth redirect |
| QR code phishing (March peak) | 18.7 million attacks | Malicious link hidden in scannable image |
| QR code phishing (June) | 8.3 million attacks | Same method, lower volume |
| CAPTCHA phishing (March) | 12 million attacks | Fake "prove you're human" page |
| CAPTCHA phishing (June) | 2.2 million attacks | Same method, lower volume |
Business email compromise, or BEC, refers to fraud where criminals impersonate a boss or supplier by email to trick staff into transferring money or sharing sensitive data. That category spiked 121% between March and April before falling back in May.
What should ordinary people actually do?
Microsoft's defensive advice did not change much despite the shifting threat. The company recommends moving away from traditional passwords entirely, using tools like Windows Hello (sign-in by face or fingerprint), physical security keys called FIDO keys, or the Microsoft Authenticator app on your phone.
For organisations, the report calls for enabling Zero-hour Auto Purge, a feature inside Microsoft's email security tools that automatically deletes a malicious email from an employee's inbox even after it has already been delivered, before anyone opens it.
The failure mode here is assuming the problem got smaller because one platform went down. The threat shifted channels. A staff member who would recognise a dodgy email may not think twice about a friendly Teams message.
If your workplace uses Microsoft Teams or any chat platform for business communication, be cautious about any message that eventually asks you to click a link, enter a password, or approve a payment, even if the sender looks familiar.
Operational takeaway: turn on automatic purge for delivered mail and treat a Teams message requesting credentials with the same suspicion you would a cold-call asking for your bank details.



