Historical intelligence backfill. This assessment covers reporting originally published on 2026-04-30 and was added to the RWP archive on 2026-09-07.

Daily Top · Identity

Q1 2026 email was 8.3 billion phish attempts and a 146% QR spike — then Tycoon2FA got hit

Microsoft counted about 8.3 billion email phishing threats in Q1 2026, QR phishing up 146% to 18.7 million in March, and a 15% Tycoon2FA drop after the early-March disruption.

RWP Ventures · 2026-09-07 · event 2026-03-31 · 1 min read · priority 7.2

Bottom line up front

CONFIRMED Microsoft's 30 April 2026 Q1 email landscape is the numbers layer under posts already in this archive (Tycoon2FA, RedVDS). About 8.3 billion email phishing threats in January–March, monthly 2.9B → 2.6B. QR phishing 7.6 million in January to 18.7 million in March (+146%). Tycoon2FA January was already −54% vs December 2025 (holiday plus RedVDS disruption). February +44%, then March −15% after the DCU/Europol seizure. CAPTCHA-gated kits rode the same platform.

The defender-relevant change is QR, not the 8.3 billion headline. Historical backfill of 30 April 2026 reporting; added 7 September 2026.

What happened

Volume stayed enormous while the shape moved to images that bypass attachment sandboxing. Disruption of one PhaaS moved March, not the year.

IT-009 (Q2 landscape) is the sequel; keep separate.

Why it mattered

If your Q1 2026 detections were "link in HTML," you missed the QR printout on the conference-room TV. Tycoon2FA's March dip is a control-plane win, not a user-behavior win.

Who / what was affected

Global Microsoft telemetry, not a census of successful account takeovers.

Technical context

Sandbox images; detonate QR destinations; FIDO2 so a scanned kit still fails closed.

Exploitation / threat status at the time

CONFIRMED Microsoft volume stats.

ASSESSED (high): QR growth is opportunistic copycatting of what worked, not a new actor class.

What defenders should have done

  1. QR-in-PDF/image detections in mail.
  2. Measure success as token theft blocked, not emails quarantined.
  3. Do not declare victory from one PhaaS takedown.

RWP assessment

Confidence: High on Microsoft's telemetry as Microsoft-observed.

Defensive actions

  1. Image/QR inspection on.
  2. Keep the Tycoon2FA token-revocation runbook.
  3. Watch Teams as the overflow (Q2 later confirmed that shift).

Sources

  1. Microsoft Threat Intelligence — Email threat landscape Q1 2026
  2. RedPacket Security — Email threat landscape Q1 2026 trends and insights
  3. Microsoft — Inside Tycoon2FA