News

Tycoon2FA Takedown Reshapes Phishing: BEC and Teams Attacks Surge

4 min read Editorial

Microsoft has released its “Email threat landscape: Q2 2026 trends and insights” report, highlighting a significant shift in the cyber threat landscape following the successful disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform. While the takedown has drastically reduced traditional phishing volumes, it has inadvertently pushed threat actors toward more sophisticated and automated delivery methods, including Business Email Compromise (BEC) and Microsoft Teams-based social engineering.

The report provides a detailed breakdown of how the elimination of Tycoon2FA’s infrastructure has rippled through the ecosystem of cybercriminal tools, forcing adversaries to adapt their strategies in real-time.

The Decline of Tycoon2FA and Legacy Phishing

According to Microsoft, the volume of phishing attacks linked to the Tycoon2FA platform fell by 92% from pre-disruption averages. This decline was steady across the quarter, with Tycoon2FA-linked phishing volume dropping 15% in March, another 22% in April, and a massive 74% in May to just 1.5 million messages. By June, the volume fell further by 20% to 1.2 million, marking the lowest monthly volumes observed in at least a year.

Advertisement

The disruption also severely impacted specific phishing techniques that relied heavily on Tycoon2FA’s infrastructure. QR code lures and fake CAPTCHA pages, which accounted for 12% and 14% of industry activity in June respectively, saw dramatic drops. QR code phishing fell from a peak of 18.7 million attacks in March to 8.3 million in June, while CAPTCHA-gated phishing plummeted from 12 million to 2.2 million attacks over the same period.

A close-up of a hand holding a smartphone displaying a suspicious QR code, with a blurred background of a busy office.
QR code phishing attacks have declined significantly since the Tycoon2FA disruption.

These statistics indicate that the customer base for Tycoon2FA struggled to migrate to replacement infrastructure quickly. The platform had been a critical enabler for large-scale, low-effort attacks, and its removal has created a vacuum that attackers are now filling with more complex methods.

The Rise of Automated BEC and Teams Phishing

As traditional phishing channels dried up, attackers turned to Business Email Compromise (BEC) and abuse of legitimate collaboration tools. Microsoft observed a highly automated BEC campaign that reached over 67,000 users using scripted emails, Amazon Simple Email Service (SES), and engagement tracking. In a notable instance, an automated BEC campaign reached 42,000 organizations in under three hours.

Simultaneously, Microsoft Teams has emerged as a new vector for social engineering. Attackers are establishing conversations to build trust before attempting credential theft or delivering malicious payloads. Microsoft reported that Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding flat into May (+1%), and increasing another 10% into June.

A professional sitting at a desk with a laptop showing the Microsoft Teams interface, with a subtle warning icon overlay
Microsoft Teams is increasingly being abused as a channel for social engineering attacks.

Another concerning trend is the use of multi-stage phishing campaigns that abuse Microsoft’s authentication flow. These campaigns use nested email (EML) files, calendar invitations, and trusted cloud services like Teams archive recording and ICS calendar invites to disguise malware delivery behind legitimate infrastructure. One such campaign targeted 107,000 users, demonstrating how adversaries are leveraging trusted Microsoft services to bypass security controls.

Defensive Recommendations

Microsoft’s report emphasizes that while attack vectors are evolving, the core defensive principles remain rooted in strong authentication and email protection. The company recommends organizations complement email filtering with phishing-resistant authentication methods, such as passkeys and phishing-resistant MFA, to reduce the effectiveness of credential theft campaigns.

For email security, Microsoft advises strengthening Exchange Online Protection and Microsoft Defender for Office 365 with capabilities like Safe Links and Zero-hour Auto Purge (ZAP). ZAP is particularly crucial for removing malicious emails that have already been delivered to mailboxes before they are read. Additionally, enforcing passwordless authentication methods like Windows Hello, FIDO keys, and Microsoft Authenticator can significantly mitigate the risk of credential-based attacks.

What This Means for You

The shift from Tycoon2FA to BEC and Teams phishing underscores the importance of a multi-layered security approach. If you are an IT administrator, prioritize deploying phishing-resistant MFA and enabling ZAP in Defender for Office 365. For end-users, be vigilant against unsolicited Teams messages and emails requesting sensitive information, even if they appear to come from trusted sources. The evolution of these threats means that relying solely on email filters is no longer sufficient; robust authentication controls are your best defense.

Source: Computerworld

Over to you: Are you relying on standard MFA, or have you switched to phishing-resistant methods like passkeys?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement