Email threat landscape: Q2 2026 trends and insights

2026-07-25T08:52:25Z4f307f5232b6116b57345e19f5ec4401a0cadb6d4ed41f14ef48df8763b2ce41
ACR StealerAI agentsAsyncAPICI/CD compromiseClickFixEntra IDOAuth abuseSaaS misconfigurationShinyHuntersTeams social engineeringTycoon2FAautomationcredential theftcyber insurance (AXA XL)guest accessidentity and access managementimport-time payloadincident responseleast privilegemulti-stage attacksnpmpasskeysphishingsupply chain compromisetoken theft

What happened

Microsoft Security Blog posts from July 2026 highlight Q2 trends and several active intrusion campaigns: a sustained decline in some phishing techniques following disruption of the Tycoon2FA phishing platform, coupled with threat actor shifts into Teams-based social engineering and increasingly automated, multi-stage attack chains. Notable incidents include ACR Stealer campaigns (ClickFix lures to harvest browser credentials, auth tokens, and sensitive documents) and a supply‑chain compromise of AsyncAPI npm packages that used CI/CD workflows to deliver import‑time payloads. Threat actor trade

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
4f307f5232b6116b57345e19f5ec4401a0cadb6d4ed41f14ef48df8763b2ce41
Enrichment time
2026-07-25T08:52:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.