CyberheistNews Vol 16 #34 Microsoft Observed 7.6 Billion Phishing Emails in Q2 2026

KnowBe4 Team | Aug 25, 2026
Cyberheist News

CyberheistNews Vol 16 #34  |   August 25th, 2026

Microsoft Observed 7.6 Billion Phishing Emails in Q2 2026

Researchers at Microsoft warn that phishing emails are still the top initial access vector, with more than two billion phishing threats detected each month during the second quarter of 2026.

"Microsoft detected approximately 7.6 billion email-based phishing threats throughout the quarter, with monthly volumes declining modestly from 2.7 billion in April to 2.4 billion in June," the researchers write. "Credential phishing remained the dominant objective behind malicious payloads, while business email compromise (BEC) activity largely returned to historical norms after a brief, anomalous surge in April.

"Notable campaigns observed during the quarter also demonstrated how threat actors combine automation, trusted services and multi-stage delivery chains to scale operations."

Notably, Microsoft observed a business email compromise (BEC) campaign that targeted 42,000 organizations in under three hours.

"On June 1, 2026, Microsoft Defender Research observed a high-volume BEC campaign that used automation to operate at scale," the researchers write. "Over a send window of under three hours (14:08–16:52 UTC), the actor reached more than 67,000 users across more than 42,000 organizations, almost exclusively in the U.S.

"Targeting spanned a broad range of industries rather than a single vertical, most notably retail and consumer goods (17%), technology and software (15%) and financial services (14%). The campaign ran two lures in succession from shared infrastructure: a request impersonating sales executives to obtain aging report data and customer contact details, and a payroll diversion pretext impersonating the CEO or President to redirect salary payments to attacker-controlled bank accounts."

The researchers also warn of a surge in Microsoft Teams phishing, which can evade email security filters.

"While email remains the dominant initial access vector, threat actors increasingly abused Microsoft Teams during Q2 to deliver social engineering, phishing and malware payloads," Microsoft says. "Unlike email, Teams traffic typically bypasses secure email gateways and benefits from the perceived legitimacy of a colleague-initiated chat, which can make lures particularly effective in this environment.

"Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+1%), then increasing another 10% into June."

Blog post with links:
https://blog.knowbe4.com/microsoft-7-6-billion-phishing-emails-q2-2026

How to Defend Your Microsoft Teams Against AI Phishing Attacks

Today, one in five attacks on Microsoft Teams is multi-channel, using email to make contact and chat apps to launch the attack. Securing your inbox alone is no longer enough to close this dangerous security gap.

Cybercriminals aren't just targeting email anymore—they are using AI to trick employees across every messaging tool they rely on. When old security tools miss these attacks, your entire messaging setup is left exposed.

Join Javvad Malik, KnowBe4's Lead CISO Advisor, to learn why messaging security must go beyond the inbox, and how a modern approach uses behavioral AI to stop attacks before they spread. We'll show you how to protect your team across email and chat without making security complicated.

You'll learn:

  • Why attackers love chat and how they move from email into apps like Microsoft Teams
  • Why basic rules miss smart phishing tricks, fake emails and bad links
  • How smart AI stops attacks, looking at message context and sender habits to catch threats before users see them
  • How real-time warnings teach users to spot suspicious messages
  • Ways to prevent accidental leaks and automatically block wrong-recipient emails and stop sensitive data from leaving your business

Close every security gap and learn how to spot hidden messaging risks.

Date/Time: TODAY, Tuesday, August 25, @ 2:00 PM (ET)

Save My Spot:
https://info.knowbe4.com/defend-your-teams-against-ai-phishing-attacks?partnerref=CHN2

Ransomware Has Changed and Your Defenses Need to Change with It

By Erich Kron

For years, ransomware was treated mostly as a malware problem. A user clicked something bad, files were encrypted, a ransom note appeared and everyone had a very bad week.

That version still exists, of course, because cybercriminals love recycling old hits. But ransomware has changed significantly over the last year. It is no longer just about encrypting files; it is now a business disruption model built around stolen identities, social engineering, data theft, operational pressure and attacks on recovery systems.

In other words, ransomware is not just trying to lock up your data anymore. It is trying to find out whether your organization can still function when things start breaking.

One of the biggest shifts has been the fragmentation of the ransomware ecosystem. After law enforcement pressure and disruptions against major groups, the market did not collapse. Instead, affiliates moved around, new groups gained traction and the ransomware economy kept going.

Groups such as Qilin, Akira, Play, Cl0p, INC Ransom and others have remained active, proving that ransomware is less dependent on one "big bad" group and is more like a criminal gig economy.

That makes defense more complicated. Taking down one group is good news, but it does not remove the access brokers, stolen credentials, affiliate operators or playbooks that fuel the next group. It is like stepping on one ant at a picnic and declaring victory over nature.

Another major change is the growing role of identity. Many ransomware attacks are no longer dramatic "hacking" events in the traditional sense. Attackers are logging in with valid credentials, abusing weak multifactor authentication, stealing session tokens or manipulating help desks into resetting access.

That means identity security is ransomware defense. Organizations need phishing-resistant MFA where possible, strong conditional access policies, monitoring for suspicious logins, privileged access controls and better processes for password and MFA resets.

If a help desk can be talked into resetting an account based on a convincing phone call and a few pieces of personal information, that is not a secure process. That is a security-themed trust exercise.

Social engineering has also become more professional. Scattered Spider-style activity showed how effective voice phishing, employee impersonation and help desk manipulation can be against even large organizations. These attacks are researched, conversational and operationally focused.

Attackers often know who to impersonate, what systems to ask about and how to create urgency without sounding like a cartoon villain. The defense here cannot be "tell employees to be more careful" and then walk away feeling productive.

[CONTINUED]
https://blog.knowbe4.com/ransomware-changed-defenses-need-change

See Real-Time Coaching, Now Part of KnowBe4 Security Awareness Training

Nearly three out of four users don't repeat the same mistake after just one coaching message. The catch? Most security awareness programs never send it. Your users complete a module, pass a quiz and move on, but even your most security conscious employees slip under pressure, and by the time training catches it, the moment's gone.

Join us for a live demo of Real-Time Coaching, part of KnowBe4's AI-native SAT. See how it works alongside AI-powered training and attack simulations to close the gap between knowing and doing, changing behavior and strengthening your security culture.

What you'll see in this demo:

  • AI-Personalized Training & Attack Simulation: Role- and risk-based content from the industry's most diverse library, paired with realistic, evolving phishing simulations that expose vulnerabilities before attackers do.
  • In-the-Moment SecurityTips: Contextual coaching triggered the instant risky behavior is detected, whether a missed Social Engineering Indicator or a risk signal from your security stack, delivered in Slack, Teams and Google Chat.
  • Coaching Categories: 20+ pre-built categories ready to go. Connect a third-party vendor to activate coaching automatically, or build custom categories in a few steps.
  • AIDA (AI Defense Agents): Automates your security awareness program so your team can focus on threats, not admin work.

The mistakes your users make happen in real time, and reinforcing secure behavior should too. Register now and see how KnowBe4 puts real-time reinforcement directly in your hands.

Date/Time: Wednesday, September 2, @ 2:00 PM (ET)

Save My Spot:
https://info.knowbe4.com/sat-demo-month3?partnerref=CHN

Research Report: From Agentic Risk to Human Wins

As autonomous AI agents move from being optional tools in your organizations to an invisible, automated layer of your workforce, the gap between traditional security awareness and real-world behavior is widening.

Drawing insights from 800 cybersecurity leaders and 3,200 employees across the globe, this report shows you how to shift your perspective from seeing security as a technology problem to treating it as a culture. You'll learn how forward leaning organizations move past simple compliance to create an integrated, "culture-embedded" approach that turns the workforce into a powerful defense.

Discover:

  • What percentage of leaders see unapproved AI tools as a top threat and how "shadow employees" are performing tasks without oversight
  • How often employees admit to making security mistakes despite knowing the safe action, and how to bridge that gap with context-driven guardrails
  • How to get started building better cultures and better partnerships with the AI working alongside your employees effectively and safely
  • Go beyond basic compliance by learning how 4,000 cybersecurity peers are navigating the shift to a security-first culture.

Download Now:
https://info.knowbe4.com/report/research-report-from-agentic-risk-to-human-wins?utm_source=chn_email&utm_medium=email&utm_campaign=dg-ces-campaign-26&utm_content=agentic-risk-to-human-wins-wp


Let's stay safe out there.

Warm regards,

Stu Sjouwerman, SACP
Executive Chairman
KnowBe4, Inc.

PS: Yours Truly in Forbes: "Your AI Agent Thinks It's Right, And That's Exactly The Problem."
https://www.forbes.com/councils/forbestechcouncil/2026/06/25/your-ai-agent-thinks-its-right-and-thats-exactly-the-problem/

PPS: One more thing. The workforce has changed. Half of it doesn't have a badge. KnowBe4 secures all of it, both humans and AI agents.

Quotes of the Week  
"A successful man is one who can lay a firm foundation with the bricks others have thrown at him."
- David Brinkley - Journalist (1920 - 2003)

"The greater danger for most of us lies not in setting our aim too high and falling short; but in setting our aim too low, and achieving our mark."
- Michelangelo - Artist (1475 - 1564)

Thanks for reading CyberheistNews

You can read CyberheistNews online at our Blog
https://blog.knowbe4.com/cyberheistnews-vol-16-34-microsoft-observed-7-6-billion-phishing-emails-in-q2-2026

Security News

Report: Royal Mail Impersonation Drives Surge in UK Phishing Attacks

Phishing attacks in the UK have surged by 140%, with Royal Mail topping the list of most commonly spoofed brands, according to new research by BrokerChooser.

The researchers observed 6,650 monthly UK searches related to Royal Mail scam attempts. "This adds up to an estimated 79,800 searches a year – almost double PayPal in second (47,520 annual searches) and more than three times HMRC (22,680 annual searches)," the researchers write.

"Evidently, the nation's postal service has become a prime target for fraudsters, who prey on the anticipation of those waiting on a delivery. A common tactic is to send fake messages claiming a small fee – usually between £1 and £3 – is needed for redelivery or customs clearance.

"These messages often contain links to fake websites designed to steal personal and payment details. Remember that legitimate courier companies will never ask for payments through text or email links."

BrokerChooser notes that AI tools have drastically improved the sophistication of these scams, allowing attackers to easily craft convincing phishing messages. "With AI, scammers have all become experts at copying logos, mimicking writing styles and recreating the tone of trusted companies," the researchers write.

"Consumers should stay alert when receiving unexpected texts, emails or messages claiming to be from their bank, delivery company or a government service. Avoid clicking any links straight away. Instead, visit the company's official website or app directly to check whether the message is genuine."

Employees can avoid falling for these scams by maintaining a healthy sense of suspicion and being on the lookout for social engineering tactics.

"Phishing scams often create panic to stop people from thinking clearly," the researchers write. "Fraudsters like to use false urgency, claiming your account will be locked, your parcel will be returned or you owe an immediate payment, all to cloud your judgement.

"Take a moment to verify the request before sharing any information or making a payment to avoid falling into their trap." KnowBe4 empowers your workforce to make smarter security decisions every day.

Business Money has the story:
https://www.business-money.com/announcements/uk-phishing-scams-soar-140-royal-mail-paypal-hmrc-among-top-10-most-impersonated-brands-by-cybercriminals/

Warning: Malicious AI Tools Are Spreading in the Criminal Underground

Criminals are now selling malicious AI tools for use in cyberattacks, according to researchers at Trellix. These tools dramatically lower the barrier for unskilled crooks to launch sophisticated attacks.

"In the first half of 2026, the Trellix research team identified multiple distinct AI-related offerings across major underground forums," the researchers write. "These offerings span the full spectrum of the attack lifecycle, from initial reconnaissance and exploit development through payload delivery, evasion and post-compromise operations."

One of the tools, called "APEX AI," allows threat actors to simply type in a targeted domain, and the tool will lay out a detailed, step-by-step plan for a ransomware attack. The tool even goes so far as to identify employees who would be best to target with spear phishing attacks.

The researchers have observed a great deal of interest in these tools on underground forums, and early signs indicate that attackers are seeing success with the tools.

"What distinguishes the current moment from earlier periods of AI hype in criminal communities is the shift from experimentation to commercialization," Trellix says. "The services documented here are not proof-of-concept (PoC) demonstrations or theoretical discussions.

"They are structured commercial offerings with pricing tiers, support channels, update cadences and in some cases, customer reviews. This maturation mirrors the broader evolution of the cybercriminal economy, where specialization and service-based models have long been the norm for ransomware, initial access brokerage and exploit development."

Trellix concludes that the proliferation of malicious AI platforms will fundamentally change the cybercriminal economy, and organizations should expect to see faster and more sophisticated attacks from a larger number of threat actors.

"The integration of AI into this existing commercial infrastructure represents a qualitative change in capability, not merely a quantitative one," the researchers write. "Tasks that previously required skilled human operators working across multiple tools and data sources are being compressed into single-prompt workflows.

"Evasion techniques that previously required manual tuning per target environment are being automated through per-build morphing."

One more thing. The workforce changed. Half of it doesn't have a badge. KnowBe4 empowers all of it; The people and the agents working alongside them. KnowBe4 empowers the digital workforce, humans and AI agents.

Trellix has the story:
https://www.trellix.com/blogs/research/weaponized-ai-commoditization-of-cybercrime/

What KnowBe4 Customers Say

Check out this amazing feedback on LinkedIn from one of our customers!

"Earlier this year, I was evaluating vendors for security awareness training and phishing simulations. Here's exactly how the buying process went: I started with a ChatGPT prompt which led me to Reddit. Based on the subreddit, I narrowed it down to three vendors that seemed to meet our needs.

"So far, so good.

"Then I went to the website of all three vendors. None of them showed pricing, none of them allowed immediate sign-up. All three required a "talk to sales" form. I submitted demo requests.

"Then… nothing. Radio silence for 24 hours. At that point, I wasn't "browsing." I was ready to move forward. I wanted to buy, but I couldn't.

"Then, an account executive called me. I moved forward with that vendor: KnowBe4. Simply because they moved fastest. When multiple solutions meet my requirements, speed becomes the deciding factor, even for a long-term decision.

"It turns out KnowBe4 also delivers a top-notch product and customer experience. After being onboarded, their CEO, Bryan Palma, sent me an email to check in on my experience. I shared feedback on a specific product feature, and it was resolved the same day. Awesome to see a company move fast in their sales and post-sales processes."

– A.K., Co-Founder & Co-CEO

The 10 Interesting News Items This Week
  1. Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes:
    https://therecord.media/russia-wildberries-cyberattack-ukraine

  2. OpenAI: The Defender’s Window Aug-17 (explaining the breakout incident):
    https://openai.com/index/the-defenders-window/

  3. CISA gives feds 3 days to fix actively exploited Ray RCE bug:
    https://www.theregister.com/security/2026/08/18/cisa-gives-feds-3-days-to-fix-actively-exploited-ray-rce-bug/5289007

  4. The Russian hurdle in Trump’s new offensive cyber program:
    https://www.nextgov.com/cybersecurity/2026/08/russian-hurdle-trumps-new-offensive-cyber-program/415493/

  5. Staying Ahead of Adversarial AI Through Agentic Source Code Review:
    https://cloud.google.com/blog/topics/threat-intelligence/staying-ahead-of-adversarial-ai-through-agentic-source-code-review

  6. New phishing kit enables AI-generated voice phishing:
    https://www.group-ib.com/blog/balonx-sistema-mexico-phaas/

  7. Suspected Chinese threat actor automates operations with agentic AI:
    https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/

  8. Users should be wary of putting sensitive info in public Google Docs:
    https://www.theregister.com/security/2026/08/13/passwords-stored-in-public-google-doc-then-showed-up-in-search-results/5287028

  9. Deceptive sites use legitimate links to redirect users to shady downloads:
    https://www.malwarebytes.com/blog/threat-intel/2026/08/41-deceptive-download-sites-show-a-real-link-then-send-you-somewhere-else

  10. Threat actors increasingly abuse enterprise collaboration platforms:
    https://unit42.paloaltonetworks.com/communication-channel-identity-risks/

Cyberheist 'Fave' Links
This Week's Links We Like, Tips, Hints and Fun Stuff

Topics: Cybercrime

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.