Microsoft said attackers are increasingly using QR-code phishing to steal credentials, with the company analyzing 8.3 billion email-based phishing threats in Q1 2026 and recording a 146% increase in quishing activity. Researchers said more than 35,000 users across roughly 13,000 organizations were targeted through emails, PDFs, and fake CAPTCHA pages carrying malicious QR codes that redirected victims through multiple sites to counterfeit login portals. Microsoft also reported a 336% surge in QR codes embedded directly in emails in March, alongside continued business email compromise lures and phishing kits such as Tycoon2FA, which it disrupted with Europol before operators began rebuilding infrastructure and shifting toward .RU domains.
The warning follows a separate Microsoft 365 security incident in which faulty heuristic anti-phishing rules in Exchange Online and Teams wrongly flagged legitimate content as malicious. The incident, tracked as EX1227432, caused valid emails to be quarantined, links to be blocked, Zero-hour Auto Purge (ZAP) actions to trigger incorrectly, and false Microsoft XDR alerts to be sent after a logic error misclassified legitimate URLs as phishing links. Microsoft said the outage was prolonged by bugs in related signature and rollback systems, underscoring how both attacker evasion and defensive misfires can disrupt cloud email security and credential protection efforts.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft researchers said rising quishing campaigns had targeted more than 35,000 users across about 13,000 organizations worldwide. The attacks used malicious QR codes in emails, PDFs, and fake CAPTCHA pages to redirect victims through multiple webpages to credential-harvesting portals.
By Q1 2026, Microsoft had analyzed more than 8.3 billion email-based phishing threats and reported a 146% increase in QR-code phishing, including a 336% surge in QR codes embedded directly in emails in March. The company also detected 10.7 million phishing threats targeting business emails and warned that attackers were increasingly using QR codes, CAPTCHA pages, and BEC lures to evade defenses.
In March 2026, Microsoft and Europol disrupted the Tycoon2FA phishing-as-a-service operation. Microsoft said this contributed to a 15% decline in attacks using Tycoon2FA methods, though the group was observed rehosting infrastructure and increasingly using .RU domains afterward.
Microsoft said the Exchange Online incident was fully resolved on 2026-02-12 after additional bugs in related security tooling and signature rollback mechanisms prolonged the disruption. The outage lasted nearly a week and had noticeable user impact across email and Teams communications.
On 2026-02-05, a Microsoft Exchange Online incident tracked as EX1227432 began when faulty heuristic phishing-detection rules incorrectly classified legitimate URLs as phishing. The issue caused legitimate emails and Teams messages to be quarantined, links to be blocked, and false Microsoft XDR alerts to be generated.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcetechradar.com
Open sourcelinkedin.com
Open sourcelinkedin.com
Open sourcecofense.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.