In This Article
Your people live in Microsoft Teams. They approve wires in it, ask the help desk for password resets in it, and answer calls in it from names they half recognize. Meanwhile the channel your institution has spent fifteen years hardening, email, just got measurably quieter.
Microsoft published its Q2 2026 email threat landscape report on July 23, covering April through June. The headline number is genuinely good news: phishing tied to one of the largest phishing-as-a-service platforms in the world fell off a cliff after a disruption operation. The number underneath it is the one that should shape your next quarter of security spending.
Weekly malicious call attempts inside Microsoft Teams are now running at nearly ten times their mid-2025 baseline. For banks, credit unions, and mortgage companies, that is a channel shift your awareness training, your email gateway, and quite possibly your monitoring have not caught up to.
What Microsoft's Q2 2026 data actually says
Precision matters here, because the easy summary of this report is wrong. It is not true that "email phishing is declining." Different populations inside the data moved in different directions, and one of them moved sharply upward.
Here is what Microsoft reported for April through June 2026:
| What moved | Direction | The figure Microsoft reported |
|---|---|---|
| Phishing linked to the Tycoon2FA platform | Down sharply | Running at roughly 8% of its pre-disruption baseline by the end of Q2, a 92% total decline since the disruption operation began in March 2026 |
| Business email compromise, overall volume | Up, then back down | April recorded nearly 9 million BEC attacks, a 121% increase over March and more than double any previous month |
| Invoice-payment-themed BEC specifically | Down sharply | Fell 67% in May and another 77% in June, ending below 0.4% of all attacks, down from around 3.6% in March |
| Payroll-diversion themed requests | Down moderately | From roughly 4% of attacks in March to 2.3% by June |
| Microsoft Teams phishing | Up | Rose 19% from March to April, held roughly flat into May at plus 1%, then rose another 10% into June |
| Microsoft Teams vishing (malicious calls) | Up sharply | Weekly attempts rose 31% from April to May and another 27% into June, up roughly 80% since the start of 2026 |
Two things this data does not prove
It does not prove a causal pivot. Microsoft's figures show one channel collapsing and another climbing during the same quarter. That is a correlation across two co-occurring movements, not evidence that the same operators packed up their email infrastructure and moved to Teams. Treat it as a shift in where the risk sits, not as a proven migration story.
It does not mean email is solved. The 92% decline applies to one named platform. BEC as a whole spiked hard in April. If you read this report and reduce email controls, you have misread it.
Why Teams is a harder channel to defend than email
Every financial institution has decades of accumulated email defense: gateways, quarantine, banner warnings on external senders, phishing simulations, and staff who have been told a thousand times to hover over a link before clicking it. Teams has almost none of that institutional muscle memory.
One finding in the Q2 report makes the training gap concrete. Microsoft reported that more than half, 52%, of Teams-based phishing attacks in June used generic display names rather than obvious IT-support impersonation.
If your awareness training teaches staff to be suspicious of a Teams message from "IT Support," the lure it is built around now accounts for less than half of these attacks.
That is the practical problem. The recognizable lure has become the less common one. A message from a plausible-looking generic name does not trip the pattern your staff were taught, and a voice call inside a trusted internal tool carries an authority that an email never had.
We have written before about how these intrusions actually run once contact is made. The mechanics are covered in detail in our breakdown of the nine-stage Teams helpdesk impersonation attack chain, and the adversary-in-the-middle pattern behind large-scale credential theft is covered in our analysis of the Code of Conduct campaign. This article is about what changed in the numbers, not a repeat of those walkthroughs.
Why This Matters for Financial Institutions
A bank or credit union employee receiving a Teams call believes they are inside the tenant. External access and federation settings often allow contact from outside organizations by default, which means the trust the interface implies is not always earned. The employee who would never act on an unexpected email is materially more likely to act on an unexpected internal-looking call.
The consequence is not theoretical. Wire authorization, member account changes, and loan file access all sit one social-engineering success away from staff who use Teams as their default workspace.
The institutions that handle this well are not the ones with better email filters. They are the ones whose provider treats Teams as a monitored surface, with the same seriousness the inbox has been getting since 2010.
BEC did not go away, it changed shape
The collapse in invoice-themed business email compromise is real and worth noting. It is also the narrowest possible reading of the BEC data.
April 2026 saw nearly 9 million BEC attacks, a 121% increase over March and more than double any previous month Microsoft had recorded. The invoice-payment theme then fell 67% in May and 77% in June. Payroll-diversion themes declined more modestly, from roughly 4% of attacks in March to 2.3% by June. What that describes is a change in pretext mix, not a retreat.
The reason this matters more for your institution than for most businesses is the loss profile. BEC is not a nuisance category.
The FBI's Internet Crime Complaint Center recorded $20.877 billion in total reported losses across 1,008,597 complaints in 2025, a 26% year-over-year increase in losses, according to its 2025 Internet Crime Report. BEC accounted for $3,046,598,558 of that. Microsoft also reported an automated BEC campaign in early June 2026 that reached more than 67,000 users in under three hours, which is a useful reminder that the volume is now machine-generated and the response window is short.
If your BEC controls need a refresher, our guide on stopping wire fraud and BEC at banks covers the payment-verification side in depth.
What Microsoft recommends
Microsoft's guidance for this threat class is consistent and worth following. Note that these controls span several different products and licensing tiers, so treat this as a set of capabilities to confirm rather than a single switch to flip.
Review the recommended settings for Exchange Online Protection and Microsoft Defender for Office 365. Enable Zero-hour auto purge so delivered mail can be pulled back after the verdict changes. Turn on Safe Links and Safe Attachments. Run attack simulation training. Enable network protection in Microsoft Defender for Endpoint. Encourage browsers that support Microsoft Defender SmartScreen. Enable passwordless authentication using Windows Hello, FIDO keys, or Microsoft Authenticator, and apply Conditional Access policies with phishing-resistant multifactor authentication on privileged accounts.
Two of those deserve emphasis for financial institutions. Phishing-resistant multifactor authentication on privileged accounts is designed to break the credential-and-token theft chain these campaigns depend on. And Zero-hour auto purge matters more as attacks get faster, because a campaign that reaches 67,000 users in under three hours will beat any human triage process.
Confirming that all of this is actually on, and stays on as tenants drift, is a standing operational job rather than a project. That is the job we do inside the tenants we manage.
For the email-side configuration baseline examiners tend to probe, our walkthrough of the Defender for Office 365 anti-phishing configuration covers the specific policy settings.
What we do for Guardian tenants
The following are our recommendations, not Microsoft's. Microsoft's Q2 report does not address Teams governance or data-loss policy, and we think both belong in the response to this data.
As a Tier-1 Microsoft Cloud Solution Provider, we manage the Microsoft 365 tenants of more than 750 banks, credit unions, and mortgage companies. That is the vantage point this data looks different from. Across the tenants we manage, email is almost always the mature surface: the gateway is tuned, the policies are documented, the simulations run on a schedule, because that is where fifteen years of examiner attention went. Teams is rarely held to that standard. External access is often still whatever the tenant shipped with, and collaboration-channel signals sit outside anyone's monitoring scope. That gap is the one this quarter's numbers should push you to close.
Being a Tier-1 CSP is what makes the response practical rather than advisory. We hold delegated admin in the tenant, so the Teams external-access setting, the Conditional Access policy, and the Defender coverage are things we can see and change, not things we can recommend and hope somebody gets to.
When a channel shift like this one shows up in the telemetry, these are the four things we work through with M365 Guardian customers:
- Scope Teams external access deliberately. Confirm which outside organizations can initiate chats and calls into your tenant, and narrow federation to the partners you actually work with rather than leaving it open by default.
- Bring the aftermath into monitoring, and shorten it. The call itself may never generate a signal, but what follows it does. Guardian MxDR monitors Microsoft Defender and Microsoft Entra ID signals across the tenant, so the endpoint and identity events that follow a successful lure, a remote-assistance session and an unusual sign-in, surface together rather than sitting in separate queues. It matters most in the minutes after. When Entra ID flags a risky sign-in, our zero-tolerance threat response calls the Microsoft Graph API to revoke that user's sign-in sessions, invalidating refresh tokens across their devices, and pairs with continuous access evaluation so access is re-evaluated rather than left to expire on its own. That runs automatically and around the clock instead of waiting for someone to open an alert queue. Against a campaign that reaches 67,000 users in under three hours, the response has to move faster than a person reading email.
- Put data-loss policy on payment-instruction changes. Microsoft Purview policies on the documents and messages that carry banking detail changes give you a control that survives whichever pretext is in fashion this quarter.
- Retrain against the current lure. Awareness content built around "IT Support" display names is now aimed at the smaller half of the problem. Training should cover unexpected internal calls and generic display names.
The operational takeaway
Do not reduce email controls on the strength of a decline in one phishing platform. Add coverage for the channel that grew. The institutions that get caught by this shift will be the ones whose monitoring, training, and governance all still assume email is where the attack arrives.
Your inbox is monitored. Is Microsoft Teams? See what Guardian MxDR covers.
We review Microsoft 365 tenant configuration for financial institutions every day, including Teams external access, Defender coverage, and the Conditional Access policies that examiners ask about. A short conversation will tell you where the gaps are.
What examiners will ask about this
In the examinations our customers walk us through, the questions we see landing hardest are about social-engineering resilience and detection capability rather than perimeter checkboxes. A channel shift of this size is exactly the kind of thing an examiner expects an institution to have noticed.
- Can you show that collaboration-platform threats are inside the scope of your security monitoring, not just email?
- Does your security awareness program reflect current attacker technique, with a documented refresh cadence?
- Are external access and federation settings for Teams documented as a deliberate decision rather than a default?
- Does your incident response plan cover an intrusion that begins with a voice call rather than an email?
That last one is where most plans are thin. Our Microsoft 365 incident response playbook walks through the examiner-ready structure, including the identity-compromise path these Teams campaigns lead to. If you would rather find out where your own tenant sits before an examiner does, grade your current security posture or talk to us.
Frequently Asked Questions
Only in part, and the distinction matters. Microsoft reported that phishing linked to the Tycoon2FA platform fell 92% from its pre-disruption baseline, ending Q2 at roughly 8% of that level. But business email compromise overall spiked in April 2026 to nearly 9 million attacks, a 121% increase over March. Invoice-themed BEC specifically then collapsed, falling 67% in May and 77% in June. These are different populations moving in different directions, so a blanket statement that email phishing declined is not accurate.
Microsoft reported that average weekly malicious call attempts over Teams rose 31% from April to May 2026 and another 27% into June, and that weekly vishing attempts have increased roughly 80% since the beginning of 2026. By the end of the quarter, weekly malicious Teams call attempts were running at nearly ten times the mid-2025 baseline. Teams-based phishing volume rose 19% from March to April, held roughly flat into May at plus 1%, then rose another 10% into June.
No. The data shows two movements happening in the same quarter: phishing tied to one platform collapsed after a disruption operation, and Teams-based phishing and vishing climbed. That is a correlation, not proof that the same operators shifted channels. The practical implication is the same either way, which is that risk now sits in a channel most institutions monitor less closely, but the causal claim is not supported by the reported figures.
Microsoft reported that more than half of Teams-based phishing attacks in June 2026 used generic display names rather than obvious IT-support impersonation. Most security awareness training teaches staff to be suspicious of a Teams message claiming to be from IT support. If the majority of attacks no longer use that lure, the training is aimed at the smaller share of the problem. Awareness programs should be updated to cover unexpected internal calls and unfamiliar generic display names.
Microsoft's guidance includes reviewing recommended settings for Exchange Online Protection and Microsoft Defender for Office 365, enabling Zero-hour auto purge, turning on Safe Links and Safe Attachments, running attack simulation training, enabling network protection in Microsoft Defender for Endpoint, using browsers that support Microsoft Defender SmartScreen, enabling passwordless authentication through Windows Hello, FIDO keys or Microsoft Authenticator, and applying Conditional Access policies with phishing-resistant multifactor authentication on privileged accounts. These controls span Defender for Office 365, Defender for Endpoint, and Microsoft Entra, so they involve different products and licensing tiers rather than a single setting.
The FBI Internet Crime Complaint Center recorded 24,768 business email compromise complaints in 2025 with $3,046,598,558 in reported losses, making BEC the second most costly crime type by loss after investment fraud. Total reported losses across all crime types reached $20.877 billion across 1,008,597 complaints, a 26% year-over-year increase in losses. BEC remains among the highest-consequence threats for banks, credit unions, and mortgage companies because it targets payment authorization directly.