Phishing continues to evolve beyond the obvious fake-email link. Microsoft’s Q2 2026 threat review highlights QR-code lures, CAPTCHA-gated phishing pages, business email compromise and increasing use of Microsoft Teams for social engineering.
What businesses should watch for
- QR codes in invoices, delivery notices or account-security messages.
- CAPTCHA pages that appear before an unexpected Microsoft sign-in.
- External Teams chats claiming to be IT support, a supplier or a senior manager.
- Urgent requests to change bank details, buy gift cards or approve unusual payments.
Recommended response
Train staff to verify unusual requests through a second channel, protect Microsoft 365 with MFA, review external Teams access, and use modern email security controls. Payment and bank-detail changes should always be independently verified using a known phone number.
Source: Microsoft Threat Intelligence, Email threat landscape Q2 2026, published 23 July 2026.