Threat analysis · May 2026

Phishing Campaigns Are Increasing in 2026:
What Microsoft 365 Tenants Should Watch For

Phishing is still the most common way Microsoft 365 accounts are compromised — and the campaigns are getting harder to spot. Attackers have moved far beyond bad attachments.

Phishing remains the primary entry point for Microsoft 365 account compromise. That is not new — but what the campaigns look like in 2026 is different enough that the usual advice about "don't open suspicious attachments" no longer covers it.

Today's phishing campaigns deliver their payload through links to fake Microsoft login pages, QR codes embedded in PDFs, CAPTCHA-gated credential harvesting sites, and files hosted on Microsoft's own infrastructure — OneDrive, SharePoint, and OneNote. The goal in the vast majority of cases is credential theft, and increasingly, session token theft that bypasses MFA entirely.

The attack does not end when the attacker has the password. It ends — if it ends — when the attacker has been fully evicted from the tenant.

This article covers what Microsoft is reporting in Q1 2026, how these campaigns translate into compromised Microsoft 365 accounts, what attackers do once they are inside, and the warning signs that something is wrong.

What Microsoft is seeing in Q1 2026

8.3B
Email-based phishing threats detected by Microsoft in Q1 2026
78%
Of email threats were link-based, not attachment-based
2×+
QR code phishing more than doubled during the quarter

Malicious PDFs also increased significantly, reaching their highest monthly volume in over a year by March 2026. These are not generic spam campaigns. The dominant objective is credential phishing — getting users to hand over their Microsoft 365 login details, and increasingly, their active session tokens.

Source: Microsoft Security Blog — Email threat landscape: Q1 2026 trends and insights

How phishing campaigns lead to compromised Microsoft 365 accounts

Modern phishing campaigns against Microsoft 365 follow a consistent pattern. The delivery mechanism varies — email link, QR code, PDF, or trusted cloud-hosted file — but the steps from click to compromise are largely the same.

1
User receives a convincing email

The email appears to come from a trusted source — a colleague, Microsoft, a courier, a bank, or a supplier. It contains a link, a QR code, or a PDF. The sender address or display name is crafted to look legitimate. In some campaigns, the email is sent from a previously compromised account within the organisation, making it appear completely genuine.

2
User clicks the link or scans the QR code

The link may pass through a legitimate redirect service or CAPTCHA page before reaching the credential harvesting site. This makes automated detection harder. QR codes are particularly effective because they are typically scanned on a personal phone — outside the organisation's security tooling entirely.

3
User lands on a fake Microsoft login page

The page is a close copy of the genuine Microsoft login — correct branding, correct URL structure using subdomains or typosquat domains. Adversary-in-the-middle (AiTM) phishing kits such as Tycoon2FA act as a proxy between the user and Microsoft's real login service, relaying the authentication in real time to capture the session token as well as the password.

4
User enters credentials and completes MFA

In a standard phishing attack, the password is captured and MFA stops the attacker. In an AiTM attack, the user completes MFA as normal — but the attacker's proxy captures the authenticated session token. At that point, MFA has been bypassed. The attacker has a valid, authenticated session without needing the user's MFA device.

5
Attacker signs in using the real account

The attacker replays the captured session token to access the mailbox, SharePoint, and other Microsoft 365 services as a fully authenticated user. Depending on the tenant configuration, the session may look like normal user activity and can be missed without proper logging, alerting, and review.

⚠️

Standard MFA is not enough on its own against AiTM phishing. Kits like Tycoon2FA are designed specifically to bypass push notification and TOTP-based MFA. Phishing-resistant MFA — FIDO2 security keys or certificate-based authentication — is the only reliable defence at the authentication layer. For most SMEs, enforcing Conditional Access with device compliance is the practical next step.

What attackers do after gaining access

Access to a Microsoft 365 account is rarely the end goal. It is the starting point. Once inside, attackers move quickly and methodically.

  • Send phishing from the real mailbox. Email sent from a genuine account bypasses most spam filters and appears completely trustworthy to recipients — inside and outside the organisation.
  • Upload malicious PDFs to SharePoint or OneDrive. A link to a Microsoft-hosted file looks far more credible than a random domain. These links evade URL reputation checks and are increasingly used in credential harvesting chains.
  • Create inbox rules to hide activity. Common rules delete replies to sent phishing, move security alerts to obscure folders, or mark all incoming mail as read — keeping the compromise invisible for as long as possible.
  • Set up external forwarding. Silent forwarding of all mail to an attacker-controlled address allows ongoing intelligence gathering long after the initial session has been revoked.
  • Search for valuable content. Attackers search mailboxes and SharePoint for invoices, payroll data, customer lists, banking details, and password files. This intelligence feeds Business Email Compromise fraud targeting the organisation's contacts and finance team.
  • Attempt lateral movement. The compromised account is used to send phishing to colleagues, granting the attacker access to additional accounts — often with higher privileges — within the same tenant.
  • Grant OAuth application access. Attackers can consent to OAuth applications that retain access to the mailbox even after the password is reset and sessions are revoked — a persistence mechanism that is frequently missed during cleanup.

Why SharePoint-hosted links and PDFs are effective delivery methods

A link to a file hosted on SharePoint or OneDrive passes through most email security filters without issue — it is a Microsoft domain, with a valid TLS certificate, and no threat reputation. The malicious content (a credential harvesting page, a QR code, a fake login prompt) is inside the file rather than in the email itself.

Microsoft's Q1 2026 data specifically identifies PDFs as a major delivery method for both QR code phishing and malicious payload campaigns. A PDF arriving via a legitimate Microsoft 365 account, linking to content on a Microsoft-hosted domain, is extremely difficult for both automated tooling and end users to identify as a threat.

This is why phishing-resistant controls at the authentication layer matter more than ever. If the credential harvesting succeeds, the email filter has already failed.

Signs a Microsoft 365 account may have been phished

  • Customers or contacts report unexpected or unusual emails from the account
  • Sent Items contains messages the user did not send
  • Expected replies are not arriving — being silently deleted by a mailbox rule
  • New inbox rules appear that the user did not create
  • SharePoint or OneDrive contains files the user did not upload
  • The account has been blocked by Microsoft for sending outbound spam
  • Sign-in logs show sessions from unexpected locations, IP addresses, or devices
  • The user receives MFA prompts they did not initiate
  • Security alert emails are missing or marked as read without the user opening them

What to check immediately if you suspect compromise

If you have reason to believe an account has been phished, containment comes first. These are the checks to run, in order of priority.

  • Revoke all active sessions for the affected account in Microsoft Entra ID.
  • Reset the password and verify the new credentials are not reused elsewhere.
  • Review MFA methods registered on the account — attackers sometimes register their own authenticator app or phone number before being detected.
  • Check sign-in logs in Microsoft Entra ID for sessions from unfamiliar locations, IP addresses, or user agent strings.
  • Check mailbox rules via the Exchange Admin Centre or PowerShell — look for rules that delete, move, or mark as read any category of email.
  • Check forwarding settings — both SMTP forwarding on the mailbox and any transport rules that redirect outbound mail.
  • Review OAuth app consents — any third-party application with mailbox access that the user did not knowingly authorise should be revoked.
  • Check SharePoint and OneDrive sharing for any externally shared files or links created in the period of suspected compromise.
  • Check outbound spam alerts in the Microsoft 365 Defender portal — if Microsoft has restricted the account for outbound mail, that confirms malicious sending occurred.
  • Review transport rules in Exchange Online for any rules added recently that redirect, copy, or delete mail across the tenant.

If the account had access to sensitive data, held an administrative role, or sent phishing to other users internally, a broader tenant investigation is required. The scope of what the attacker accessed or altered may extend well beyond the initial mailbox.

Get help

Email incident@iterik.ie or fill in the form below.

Prefer to talk first? Mention in the message box that you'd like a quick 15-minute phone or Teams call.

/* Close mobile nav when any link is clicked */ document.querySelectorAll('.nav-links a').forEach(a => { a.addEventListener('click', () => { document.querySelector('.nav-links')?.classList.remove('open'); }); });