
Microsoft says Tycoon2FA phishing volume fell 92% after disruption
Microsoft says Tycoon2FA-linked phishing fell 92% after disruption, but Teams-based social engineering kept rising in Q2.
Microsoft's latest quarterly email threat report points to a rare measurable setback for a large phishing-as-a-service ecosystem, while warning that attackers are shifting the pressure into newer channels. In research published July 23, Microsoft Threat Intelligence and the Microsoft Defender Security Research Team said phishing volume tied to the Tycoon2FA platform was running at roughly 8% of its late-2025 baseline by the end of June 2026.
The finding follows Microsoft's March disruption campaign against Tycoon2FA infrastructure. According to the company, Tycoon2FA-linked phishing dropped 15% in March, 22% in April, 74% in May and another 20% in June, reaching about 1.2 million messages for the month. Microsoft compared that with an average of 15.1 million monthly Tycoon2FA-linked phishing messages during the second half of 2025.
What changed in Q2
The report says the takedown affected two techniques that had become common in credential theft campaigns: QR-code phishing and CAPTCHA-gated phishing pages. Tycoon2FA's share of CAPTCHA-gated phishing sites fell from 41% in March to 12% by June, down from a December 2025 peak of 76%. Its share of QR-code campaigns redirecting to Tycoon2FA domains also declined, from 20% in March to 14% in June.
Microsoft still detected about 7.6 billion email-based phishing threats across April, May and June, so the broader threat did not disappear. Monthly phishing volume fell modestly from 2.7 billion in April to 2.4 billion in June, while credential theft remained the dominant objective. The company also noted that attackers continued rotating file formats and delivery methods, with HTML and PDF attachments remaining common malicious payloads.
Defenders still have work to do
The clearest warning in the report is that successful disruption can change attacker behavior rather than end it. QR-code phishing dropped from a March peak of 18.7 million attacks to 8.3 million in June, and CAPTCHA-gated phishing declined from nearly 12 million attacks in March to 2.2 million in June. At the same time, Microsoft said Teams-based social engineering kept rising during Q2, and malicious call attempts reached nearly ten times the mid-2025 baseline by the end of the quarter.
For security teams, the takeaway is practical: infrastructure disruption can buy time, but controls still need to follow attackers across email, collaboration apps, identity flows and attachments. Microsoft recommends layered detection and response, attention to adversary-in-the-middle credential theft, and monitoring for campaigns that abuse trusted services or authentication redirects to make phishing links look safer than they are.
Sources
Cover photo by Markus Winkler on Pexels, used under the Pexels License.
CyberOGZ Team






Comments (0)
Leave a Comment