started · updated
Microsoft flags billions of email phishing threats and real-time insurance hijacking rise
Microsoft’s security team reported detecting roughly 7.6 billion email‑based phishing attempts worldwide in the second quarter of 2026, with a noticeable increase in phishing activity through Microsoft Teams and voice‑phishing (vishing). Credential theft remained the primary aim, and attack vectors such as HTML, PDF attachments and QR‑code lures continued to be exploited, although QR‑code attacks fell from their March peak.
Separate research by CTM360 revealed that phishing targeting insurance providers has evolved to hijack user accounts in real time. Attackers now use sponsored Google ads to lure victims to fake insurance login pages, synchronising the credential capture with the victim’s active session. The campaign, primarily aimed at Saudi Arabia but also observed in Europe, the United States and India, reuses infrastructure across multiple insurers, exposing personal data and enabling immediate fraud.