Microsoft Observed 7.6 Billion Phishing Emails in Q2 2026

KnowBe4 Team | Aug 18, 2026

Researchers at Microsoft warn that phishing emails are still the top initial access vector, with more than 2 billion phishing threats detected each month during the second quarter of 2026.

“Microsoft detected approximately 7.6 billion email-based phishing threats throughout the quarter, with monthly volumes declining modestly from 2.7 billion in April to 2.4 billion in June,” the researchers write. “Credential phishing remained the dominant objective behind malicious payloads, while business email compromise (BEC) activity largely returned to historical norms after a brief, anomalous surge in April. Notable campaigns observed during the quarter also demonstrated how threat actors combine automation, trusted services, and multi-stage delivery chains to scale operations.”

Notably, Microsoft observed a business email compromise (BEC) campaign that targeted 42,000 organizations in under three hours.

“On June 1, 2026, Microsoft Defender Research observed a high-volume BEC campaign that used automation to operate at scale,” the researchers write. “Over a send window of under three hours (14:08–16:52 UTC), the actor reached more than 67,000 users across more than 42,000 organizations, almost exclusively in the United States. Targeting spanned a broad range of industries rather than a single vertical, most notably retail and consumer goods (17%), technology and software (15%), and financial services (14%). The campaign ran two lures in succession from shared infrastructure: a request impersonating sales executives to obtain aging report data and customer contact details, and a payroll diversion pretext impersonating the CEO or President to redirect salary payments to attacker-controlled bank accounts.”

The researchers also warn of a surge in Microsoft Teams phishing, which can evade email security filters.

“While email remains the dominant initial access vector, threat actors increasingly abused Microsoft Teams during Q2 to deliver social engineering, phishing, and malware payloads,” Microsoft says. “Unlike email, Teams traffic typically bypasses secure email gateways and benefits from the perceived legitimacy of a colleague-initiated chat, which can make lures particularly effective in this environment. Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+1%), then increasing another 10% into June.”

Microsoft has the story: Email threat landscape: Q2 2026 trends and insights

FAQs

What is the Apple FaceTime scam?

It's a social engineering attack where scammers impersonate Apple Support over an unsolicited FaceTime call, claiming fraudulent activity or a technical issue with the victim's account. They exploit the call's real-time, familiar-brand format to pressure victims into handing over payment card details, banking credentials, or Apple ID logins.

What should I do if I get an unsolicited call claiming to be from Apple?

Apple recommends hanging up immediately, since the company doesn't proactively call customers about account or device issues. You can then report the call to the FTC at reportfraud.ftc.gov or to local law enforcement.

How do scammers spoof Apple's caller ID?

Attackers use caller ID spoofing to make an incoming call appear as though it's coming from Apple or Apple Support, even though the number is fake. This exploits users' trust in a familiar brand name to lower their guard before the scam begins.

See KnowBe4 Defend™ in Action

Learn how Defend™ strategically enhances Microsoft 365's native security to catch the threats Secure Email Gateways (SEGs) miss.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.