logo

Microsoft Flagged 8.3B Phishing Emails in Q1 as QR Codes, CAPTCHAs Rise

ID: 4ec4e924-546d-565a-8ff1-986b4305f6b6

STIX ID: report--4ec4e924-546d-565a-8ff1-986b4305f6b6

Feed Name: TechRepublic Security

Threat Score
75/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Joseph Ofonagoro

...
...

Microsoft flagged billions of phishing emails over a three-month period and reports a shift toward modular, multi-stage phishing campaigns: commercial phishing-as-a-service platforms (e.g., Tycoon2FA tied to Storm-1747), CAPTCHA-gated file payloads (PDF, HTML, DOCX, SVG), and high-volume BEC tactics are enabling large-scale, evasive attacks; defenders should employ layered controls (Safe Links, Safe Attachments, SmartScreen, endpoint/network protections) and user training to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.