Email threat landscape: Q2 2026 trends and insights

2026-07-24T08:52:25Zcbe163b46a7a4cd4e77c2f11ce35dd7a58be878dfb4699aba521c8c730c118f7
ACR StealerAI agentsAXA XLAsyncAPICI/CD compromiseClickFixDefender ExpertsMicrosoft Entra IDOAuth abuseShinyHuntersTeams social engineeringTycoon2FAauthentication tokenscredential theftimport-time payloadincident responseleast privilegenpm supply chainpasskeysphishingsupply chain securityvishing

What happened

Microsoft Security Blog Q2‑2026 highlights: Microsoft disrupted the Tycoon2FA phishing platform, contributing to declines in several phishing techniques, but adversaries shifted to Teams‑based social engineering and more automated, multi‑stage attack chains. Active campaigns include ACR Stealer (using ClickFix lures to exfiltrate browser credentials, auth tokens, and sensitive documents) and an AsyncAPI npm supply‑chain compromise that leveraged import‑time payload delivery via trusted CI/CD workflows. Microsoft also reported ShinyHunters‑style OAuth abuse (including vishing and guest‑access/s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
cbe163b46a7a4cd4e77c2f11ce35dd7a58be878dfb4699aba521c8c730c118f7
Enrichment time
2026-07-24T08:52:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Email threat landscape: Q2 2026 trends and insights · Baitaphish