Microsoft Q2 2026 Threat Data: Teams Vishing Hit 10x While One Phishing Platform Collapsed

Justin Kirsch | | 10 min read
Split scene showing a dimmed email inbox on the left and a bright Microsoft Teams incoming call notification on the right, with Microsoft 365 branding

Your people live in Microsoft Teams. They approve wires in it, ask the help desk for password resets in it, and answer calls in it from names they half recognize. Meanwhile the channel your institution has spent fifteen years hardening, email, just got measurably quieter.

Microsoft published its Q2 2026 email threat landscape report on July 23, covering April through June. The headline number is genuinely good news: phishing tied to one of the largest phishing-as-a-service platforms in the world fell off a cliff after a disruption operation. The number underneath it is the one that should shape your next quarter of security spending.

Weekly malicious call attempts inside Microsoft Teams are now running at nearly ten times their mid-2025 baseline. For banks, credit unions, and mortgage companies, that is a channel shift your awareness training, your email gateway, and quite possibly your monitoring have not caught up to.

10x
Weekly malicious Microsoft Teams call attempts at the end of Q2 2026, compared with the mid-2025 baseline
Source: Microsoft Security Blog, Email threat landscape Q2 2026, July 23, 2026

What Microsoft's Q2 2026 data actually says

Precision matters here, because the easy summary of this report is wrong. It is not true that "email phishing is declining." Different populations inside the data moved in different directions, and one of them moved sharply upward.

Here is what Microsoft reported for April through June 2026:

What moved Direction The figure Microsoft reported
Phishing linked to the Tycoon2FA platform Down sharply Running at roughly 8% of its pre-disruption baseline by the end of Q2, a 92% total decline since the disruption operation began in March 2026
Business email compromise, overall volume Up, then back down April recorded nearly 9 million BEC attacks, a 121% increase over March and more than double any previous month
Invoice-payment-themed BEC specifically Down sharply Fell 67% in May and another 77% in June, ending below 0.4% of all attacks, down from around 3.6% in March
Payroll-diversion themed requests Down moderately From roughly 4% of attacks in March to 2.3% by June
Microsoft Teams phishing Up Rose 19% from March to April, held roughly flat into May at plus 1%, then rose another 10% into June
Microsoft Teams vishing (malicious calls) Up sharply Weekly attempts rose 31% from April to May and another 27% into June, up roughly 80% since the start of 2026

Two things this data does not prove

It does not prove a causal pivot. Microsoft's figures show one channel collapsing and another climbing during the same quarter. That is a correlation across two co-occurring movements, not evidence that the same operators packed up their email infrastructure and moved to Teams. Treat it as a shift in where the risk sits, not as a proven migration story.

It does not mean email is solved. The 92% decline applies to one named platform. BEC as a whole spiked hard in April. If you read this report and reduce email controls, you have misread it.

Why Teams is a harder channel to defend than email

Every financial institution has decades of accumulated email defense: gateways, quarantine, banner warnings on external senders, phishing simulations, and staff who have been told a thousand times to hover over a link before clicking it. Teams has almost none of that institutional muscle memory.

One finding in the Q2 report makes the training gap concrete. Microsoft reported that more than half, 52%, of Teams-based phishing attacks in June used generic display names rather than obvious IT-support impersonation.

If your awareness training teaches staff to be suspicious of a Teams message from "IT Support," the lure it is built around now accounts for less than half of these attacks.

That is the practical problem. The recognizable lure has become the less common one. A message from a plausible-looking generic name does not trip the pattern your staff were taught, and a voice call inside a trusted internal tool carries an authority that an email never had.

We have written before about how these intrusions actually run once contact is made. The mechanics are covered in detail in our breakdown of the nine-stage Teams helpdesk impersonation attack chain, and the adversary-in-the-middle pattern behind large-scale credential theft is covered in our analysis of the Code of Conduct campaign. This article is about what changed in the numbers, not a repeat of those walkthroughs.

Why This Matters for Financial Institutions

A bank or credit union employee receiving a Teams call believes they are inside the tenant. External access and federation settings often allow contact from outside organizations by default, which means the trust the interface implies is not always earned. The employee who would never act on an unexpected email is materially more likely to act on an unexpected internal-looking call.

The consequence is not theoretical. Wire authorization, member account changes, and loan file access all sit one social-engineering success away from staff who use Teams as their default workspace.

The institutions that handle this well are not the ones with better email filters. They are the ones whose provider treats Teams as a monitored surface, with the same seriousness the inbox has been getting since 2010.

Two-column comparison of Q2 2026 Microsoft 365 threat telemetry. Declining: Tycoon2FA phishing down 92 percent, invoice-themed BEC down 67 percent in May and 77 percent in June, payroll-diversion themes from 4 percent to 2.3 percent of attacks. Climbing: Teams vishing calls at 10 times the mid-2025 baseline, Teams phishing up 19 percent then 1 percent then 10 percent, BEC in April roughly 9 million attacks up 121 percent.
Where the attack volume moved in Q2 2026. The populations move in different directions, which is why a single "phishing is down" summary misreads the quarter.

BEC did not go away, it changed shape

The collapse in invoice-themed business email compromise is real and worth noting. It is also the narrowest possible reading of the BEC data.

April 2026 saw nearly 9 million BEC attacks, a 121% increase over March and more than double any previous month Microsoft had recorded. The invoice-payment theme then fell 67% in May and 77% in June. Payroll-diversion themes declined more modestly, from roughly 4% of attacks in March to 2.3% by June. What that describes is a change in pretext mix, not a retreat.

The reason this matters more for your institution than for most businesses is the loss profile. BEC is not a nuisance category.

$3.05B
Reported business email compromise losses in 2025 across 24,768 complaints, the second most costly crime type by loss after investment fraud
Source: FBI Internet Crime Complaint Center, 2025 Internet Crime Report

The FBI's Internet Crime Complaint Center recorded $20.877 billion in total reported losses across 1,008,597 complaints in 2025, a 26% year-over-year increase in losses, according to its 2025 Internet Crime Report. BEC accounted for $3,046,598,558 of that. Microsoft also reported an automated BEC campaign in early June 2026 that reached more than 67,000 users in under three hours, which is a useful reminder that the volume is now machine-generated and the response window is short.

If your BEC controls need a refresher, our guide on stopping wire fraud and BEC at banks covers the payment-verification side in depth.

What Microsoft recommends

Microsoft's guidance for this threat class is consistent and worth following. Note that these controls span several different products and licensing tiers, so treat this as a set of capabilities to confirm rather than a single switch to flip.

Tier-1 CSP Microsoft's standing guidance for this threat class

Review the recommended settings for Exchange Online Protection and Microsoft Defender for Office 365. Enable Zero-hour auto purge so delivered mail can be pulled back after the verdict changes. Turn on Safe Links and Safe Attachments. Run attack simulation training. Enable network protection in Microsoft Defender for Endpoint. Encourage browsers that support Microsoft Defender SmartScreen. Enable passwordless authentication using Windows Hello, FIDO keys, or Microsoft Authenticator, and apply Conditional Access policies with phishing-resistant multifactor authentication on privileged accounts.

Microsoft's standing guidance for Exchange Online Protection, Defender for Office 365, Defender for Endpoint, and Microsoft Entra. Context: Microsoft Security Blog, Email threat landscape Q2 2026, July 23, 2026.

Two of those deserve emphasis for financial institutions. Phishing-resistant multifactor authentication on privileged accounts is designed to break the credential-and-token theft chain these campaigns depend on. And Zero-hour auto purge matters more as attacks get faster, because a campaign that reaches 67,000 users in under three hours will beat any human triage process.

Confirming that all of this is actually on, and stays on as tenants drift, is a standing operational job rather than a project. That is the job we do inside the tenants we manage.

For the email-side configuration baseline examiners tend to probe, our walkthrough of the Defender for Office 365 anti-phishing configuration covers the specific policy settings.

Four-stage vertical timeline from a Teams vishing call to containment. Stage 1, often no signal: unexpected Teams call from a generic display name. Stage 2, rising alert: remote-assistance session started on the endpoint. Stage 3, critical: sign-in tokens stolen and an unusual sign-in appears. Stage 4, resolved: sessions revoked automatically and access re-evaluated. Stages 2 through 4 are bracketed as monitored by M365 Guardian using Microsoft Defender, Microsoft Entra ID, and Microsoft Graph.
The call itself often produces no signal. What Guardian MxDR monitors is the endpoint and identity activity that follows it, and the automated session revocation that closes it out.

What we do for Guardian tenants

The following are our recommendations, not Microsoft's. Microsoft's Q2 report does not address Teams governance or data-loss policy, and we think both belong in the response to this data.

As a Tier-1 Microsoft Cloud Solution Provider, we manage the Microsoft 365 tenants of more than 750 banks, credit unions, and mortgage companies. That is the vantage point this data looks different from. Across the tenants we manage, email is almost always the mature surface: the gateway is tuned, the policies are documented, the simulations run on a schedule, because that is where fifteen years of examiner attention went. Teams is rarely held to that standard. External access is often still whatever the tenant shipped with, and collaboration-channel signals sit outside anyone's monitoring scope. That gap is the one this quarter's numbers should push you to close.

Being a Tier-1 CSP is what makes the response practical rather than advisory. We hold delegated admin in the tenant, so the Teams external-access setting, the Conditional Access policy, and the Defender coverage are things we can see and change, not things we can recommend and hope somebody gets to.

When a channel shift like this one shows up in the telemetry, these are the four things we work through with M365 Guardian customers:

  • Scope Teams external access deliberately. Confirm which outside organizations can initiate chats and calls into your tenant, and narrow federation to the partners you actually work with rather than leaving it open by default.
  • Bring the aftermath into monitoring, and shorten it. The call itself may never generate a signal, but what follows it does. Guardian MxDR monitors Microsoft Defender and Microsoft Entra ID signals across the tenant, so the endpoint and identity events that follow a successful lure, a remote-assistance session and an unusual sign-in, surface together rather than sitting in separate queues. It matters most in the minutes after. When Entra ID flags a risky sign-in, our zero-tolerance threat response calls the Microsoft Graph API to revoke that user's sign-in sessions, invalidating refresh tokens across their devices, and pairs with continuous access evaluation so access is re-evaluated rather than left to expire on its own. That runs automatically and around the clock instead of waiting for someone to open an alert queue. Against a campaign that reaches 67,000 users in under three hours, the response has to move faster than a person reading email.
  • Put data-loss policy on payment-instruction changes. Microsoft Purview policies on the documents and messages that carry banking detail changes give you a control that survives whichever pretext is in fashion this quarter.
  • Retrain against the current lure. Awareness content built around "IT Support" display names is now aimed at the smaller half of the problem. Training should cover unexpected internal calls and generic display names.

The operational takeaway

Do not reduce email controls on the strength of a decline in one phishing platform. Add coverage for the channel that grew. The institutions that get caught by this shift will be the ones whose monitoring, training, and governance all still assume email is where the attack arrives.

Your inbox is monitored. Is Microsoft Teams? See what Guardian MxDR covers.

We review Microsoft 365 tenant configuration for financial institutions every day, including Teams external access, Defender coverage, and the Conditional Access policies that examiners ask about. A short conversation will tell you where the gaps are.

What examiners will ask about this

In the examinations our customers walk us through, the questions we see landing hardest are about social-engineering resilience and detection capability rather than perimeter checkboxes. A channel shift of this size is exactly the kind of thing an examiner expects an institution to have noticed.

  • Can you show that collaboration-platform threats are inside the scope of your security monitoring, not just email?
  • Does your security awareness program reflect current attacker technique, with a documented refresh cadence?
  • Are external access and federation settings for Teams documented as a deliberate decision rather than a default?
  • Does your incident response plan cover an intrusion that begins with a voice call rather than an email?

That last one is where most plans are thin. Our Microsoft 365 incident response playbook walks through the examiner-ready structure, including the identity-compromise path these Teams campaigns lead to. If you would rather find out where your own tenant sits before an examiner does, grade your current security posture or talk to us.

Frequently Asked Questions

Only in part, and the distinction matters. Microsoft reported that phishing linked to the Tycoon2FA platform fell 92% from its pre-disruption baseline, ending Q2 at roughly 8% of that level. But business email compromise overall spiked in April 2026 to nearly 9 million attacks, a 121% increase over March. Invoice-themed BEC specifically then collapsed, falling 67% in May and 77% in June. These are different populations moving in different directions, so a blanket statement that email phishing declined is not accurate.

Microsoft reported that average weekly malicious call attempts over Teams rose 31% from April to May 2026 and another 27% into June, and that weekly vishing attempts have increased roughly 80% since the beginning of 2026. By the end of the quarter, weekly malicious Teams call attempts were running at nearly ten times the mid-2025 baseline. Teams-based phishing volume rose 19% from March to April, held roughly flat into May at plus 1%, then rose another 10% into June.

No. The data shows two movements happening in the same quarter: phishing tied to one platform collapsed after a disruption operation, and Teams-based phishing and vishing climbed. That is a correlation, not proof that the same operators shifted channels. The practical implication is the same either way, which is that risk now sits in a channel most institutions monitor less closely, but the causal claim is not supported by the reported figures.

Microsoft reported that more than half of Teams-based phishing attacks in June 2026 used generic display names rather than obvious IT-support impersonation. Most security awareness training teaches staff to be suspicious of a Teams message claiming to be from IT support. If the majority of attacks no longer use that lure, the training is aimed at the smaller share of the problem. Awareness programs should be updated to cover unexpected internal calls and unfamiliar generic display names.

Microsoft's guidance includes reviewing recommended settings for Exchange Online Protection and Microsoft Defender for Office 365, enabling Zero-hour auto purge, turning on Safe Links and Safe Attachments, running attack simulation training, enabling network protection in Microsoft Defender for Endpoint, using browsers that support Microsoft Defender SmartScreen, enabling passwordless authentication through Windows Hello, FIDO keys or Microsoft Authenticator, and applying Conditional Access policies with phishing-resistant multifactor authentication on privileged accounts. These controls span Defender for Office 365, Defender for Endpoint, and Microsoft Entra, so they involve different products and licensing tiers rather than a single setting.

The FBI Internet Crime Complaint Center recorded 24,768 business email compromise complaints in 2025 with $3,046,598,558 in reported losses, making BEC the second most costly crime type by loss after investment fraud. Total reported losses across all crime types reached $20.877 billion across 1,008,597 complaints, a 26% year-over-year increase in losses. BEC remains among the highest-consequence threats for banks, credit unions, and mortgage companies because it targets payment authorization directly.


Justin Kirsch

Justin Kirsch

Co-Founder & CEO, Access Business Technologies

Justin Kirsch has built secure Microsoft cloud environments for financial institutions since 1999. As Co-Founder and CEO of Access Business Technologies, the largest Tier-1 Microsoft Cloud Solution Provider primarily dedicated to financial services, he helps more than 750 banks, credit unions, and mortgage companies detect and contain identity-based attacks across Microsoft 365, including the collaboration channels most security programs still overlook.