Historical intelligence backfill. This assessment covers reporting originally published on 2026-07-23 and was added to the RWP archive on 2026-09-07.
Q2 2026 email after Tycoon2FA: 92% less kit mail, more Teams and leftover QR
Microsoft's July landscape is the aftermath of the March disruption — Tycoon2FA to 1.2 million messages in June, CAPTCHA-gated and QR shares down, Teams phishing climbing.
Bottom line up front
CONFIRMED 23 July 2026 Microsoft Q2 email landscape. After the March DCU/Europol Tycoon2FA action, kit-linked phishing volume fell 92% from pre-disruption averages. March −15%, April −22%, May −74% to 1.5 million, June −20% to 1.2 million (year-low). Tycoon2FA share of CAPTCHA-gated sites 41% in March → 12% by June; QR redirect share 20% → 14%. QR still 8.3 million in June vs 18.7 million March peak. Teams-based phishing rose through Q2 (CSO recap: +19% March→April, then +10% into June). No single PhaaS replaced Tycoon2FA at that scale in Q2. Sequel to this archive's Q1 post and Tycoon2FA disruption post — not a merge.
Historical backfill of 23 July 2026 reporting; added 7 September 2026.
What happened
You can take down a platform. Crime moves to Teams and whatever QR still works.
Why it mattered
SOC dashboards that only watch SMTP will declare victory while helpdesk-vish on Teams is up.
Who / what was affected
Global Microsoft telemetry.
Technical context
Keep token-theft detections. Measure Teams phishing as a first-class queue. QR inspection stays on even after the peak.
Exploitation / threat status at the time
CONFIRMED Microsoft stats.
ASSESSED displacement not disappearance.
What defenders should have done
- Do not sun-set QR detections.
- Staff a Teams-abuse queue.
- Remember 1.2 million is still a lot of mail.
RWP assessment
Confidence: High on the telemetry. Disruption works; it does not end phishing.
Defensive actions
- FIDO2 still the actual control.
- Cross-channel reporting (mail + Teams).
- Watch for the next kit in Q3, not a vacuum.
Sources
- Microsoft — Email threat landscape Q2 2026
- CSO Online — Email threats changed after the Tycoon2FA take-down
- Microsoft — Email threat landscape Q1 2026