News2min read

Email threat landscape: Q2 2026 trends and insights

The disruption of the Tycoon2FA phishing platform in mid-2026 has significantly altered attack vectors, forcing threat actors to pivot toward Teams-based social engineering while employing more automated multi-stage chains.

High relevanceAI SecurityRed Teaming

Key Trends:

  • Phishing Decline: The removal and subsequent disruption of the Tycoon2FA phishing platform in Q2 2026 led to sustained declines across several major phishing techniques. Attackers previously reliant on this infrastructure are experiencing reduced success rates.
  • Shift to Teams Social Engineering: Threat actors have expanded their operational focus into social engineering attacks utilizing Microsoft Teams as a primary vector, leveraging the platform's integration capabilities for credential harvesting and business compromise.
  • Automation of Attack Chains: There is an observable increase in the use of increasingly automated and multi-stage attack chains. These sophisticated sequences allow adversaries to bypass traditional detection mechanisms more effectively than single-vector campaigns.

Why it matters

This article matters because it documents a concrete, recent shift in threat actor behavior driven by infrastructure disruption (Tycoon2FA), providing actionable intelligence on how attackers are adapting their social engineering tactics toward Teams-based vectors and automating complex attack chains. Security teams must monitor these new behavioral patterns to update detection rules before they become normalized.

Takeaways

  • The removal of the Tycoon2FA phishing platform caused sustained declines in major phishing techniques during Q2 2026.
  • Threat actors are pivoting toward Teams-based social engineering attacks as a primary vector for credential theft.
  • Attackers are increasingly utilizing automated and multi-stage attack chains to bypass security controls.

Sources