Q2 2026 Email Threat Landscape Shows Surge in Phishing and Business‑Email‑Compromise Campaigns
What Happened — Microsoft’s Threat Intelligence team reports that Q2 2026 saw a 27 % rise in credential‑phishing emails and a 42 % jump in Business‑Email‑Compromise (BEC) attempts versus Q1. Malicious attachments shifted toward weaponized Office macros, while “password‑spray” attacks leveraged newly‑leaked corporate address lists.
Why It Matters for Compliance & Audit Readiness
- Phishing and BEC are classic vectors that test the effectiveness of SOC 2 CC6.1 (Logical Access) and CC6.2 (User Management) controls; a successful breach can invalidate your access‑control evidence.
- Continuous Security Awareness Training provides the audit‑ready documentation that demonstrates due‑diligence in mitigating social‑engineering risk.
- The trend underscores the need for real‑time phishing‑simulation metrics as part of your SOC 2 readiness evidence package.
Who Is Affected — Financial services, technology SaaS providers, retail/e‑commerce, and any organization that relies on corporate email for transaction processing.
Recommended Actions
- Map your phishing‑simulation program to SOC 2 CC6.1/CC6.2 controls and capture completion rates as audit evidence.
- Enforce MFA on all mail‑gateway admin accounts and privileged users.
- Deploy DMARC/DKIM/SPF enforcement and monitor for spoofed domains.
- Conduct quarterly “live‑phish” exercises and update your security‑awareness curriculum to reflect the latest tactics.
Technical Notes — The report cites a 15 % increase in macro‑based Office payloads (CVE‑2025‑XXXX) and a rise in credential‑phishing kits that exploit Outlook Web Access (OWA) login pages. Attackers are also re‑using compromised Microsoft 365 tenant credentials for lateral movement.
Source: Microsoft Security Blog – Email Threat Landscape Q2 2026