BEC ‘Are you at your desk?’ Lures Surge in Q2

Microsoft Security Blog · Medium sophistication
Last updated July 30, 2026

Microsoft reports billions of phishing attempts in Q2 2026, with attackers increasingly using attachments (PDF/DOC/HTML) and new formats like calendar invites to trick employees into entering credentials. The report also highlights continued growth in Teams-based social engineering and notes that most BEC scams start with simple “conversation starter” emails before moving to fraud.

How the Attack Worked

According to Microsoft's Q2 2026 threat data, business email compromise (BEC) campaigns rarely lead with a financial request. Instead, most begin with a short, vague message such as "Are you at your desk?" These generic conversation starters made up 87 to 92 percent of initial contact emails each month during the quarter. Once a target replies, the attacker uses the established rapport to move toward a fraudulent ask, such as a wire transfer or document request, later in the exchange.

Alongside this, Microsoft tracked roughly 7.6 billion email-based phishing threats in Q2, with credential phishing as the dominant objective. Attackers also leaned on QR codes embedded in PDF and DOC/DOCX attachments to route victims to fake login pages, and increasingly used calendar invitations (ICS files) that can inject malicious links directly into a user's calendar without requiring a click on the invite itself.

Why It Succeeded

Each of these methods works by lowering a target's guard:

  • A vague opener like "Are you at your desk?" contains no clear ask, so it doesn't trigger the skepticism a direct financial request might.
  • QR codes shift the interaction to a mobile device, often outside the reach of corporate email security tooling.
  • Calendar invites are processed differently than standard attachments, so a malicious link can land in a user's calendar without an obvious open-and-click step.
  • Teams-based social engineering, including voice phishing, exploits the assumption that internal collaboration tools are inherently more trustworthy than email.

What to Watch For

  • Unsolicited messages that open with small talk or vague questions and push for a reply before stating a purpose.
  • Attachments, PDF or DOC/DOCX, that ask you to scan a QR code to sign in.
  • Unexpected calendar invites, especially ones with unfamiliar join or sign-in links, that arrive without prior discussion.
  • Unusual voice calls or Teams messages requesting sensitive actions, particularly from unfamiliar internal-looking contacts.

Building Resistance

Finance, executive assistant, HR, and procurement staff are common BEC targets because they can action payment or document requests. Employees across all roles should treat generic, out-of-context opening messages as a potential early-stage BEC attempt and verify the sender through a separate, known channel before continuing the conversation. Security awareness efforts should also expand beyond email to cover Teams messages, voice calls, and calendar invites, since these channels can feel more trusted to users and are increasingly used to carry out the same underlying credential theft and fraud objectives Microsoft observed in email traffic. See MITRE ATT&CK technique T1566 for background on phishing delivery methods referenced in this report.

Key findings

  • Microsoft observed approximately 7.6 billion email-based phishing threats during Q2 2026, with credential phishing as the dominant goal.
  • Teams-based social engineering grew, including voice phishing (vishing), with weekly malicious call attempts reaching nearly 10x the mid-2025 baseline by quarter end.
  • Tycoon2FA-linked phishing volume dropped 92% from pre-disruption averages and shifted toward .RU infrastructure after being forced off Cloudflare.
  • QR code phishing became almost entirely attachment-based in Q2, with a notable swing from PDF toward DOC/DOCX attachments.
  • CAPTCHA-gated phishing volumes fell sharply from March highs, with delivery methods rotating (PDF, SVG, embedded URLs, etc.).
  • BEC activity spiked anomalously in April, and most BEC scams began with generic outreach messages designed to start a conversation.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Executives, Executive assistants, HR, Procurement, IT helpdesk / support staff.
  • Affected industries: All industries (cross-sector), Organizations using Microsoft Teams, Organizations using Microsoft 365 email and calendaring.
  • Attack channels: email.
  • Impersonated: A colleague or business contact (unspecified in article), A service or login portal (unspecified in article), Meeting organizer or business contact (unspecified in article).

Red flags to watch for

  • Vague, out-of-context opener with no details
  • Unusual tone or timing for the supposed sender
  • Conversation is pushed to continue rather than stating a clear business purpose
  • Unsolicited attachment asking you to scan a QR code
  • Pressure to use a mobile device to complete a login
  • Attachment format changes (PDF vs DOC/DOCX) used to bypass filters
  • Unexpected meeting invite from an unknown sender
  • Calendar entry includes an unfamiliar ‘join’ or sign-in link
  • Invite arrives without prior discussion or agenda
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

Why do BEC scams open with 'Are you at your desk?'

Microsoft found generic conversation-starter emails like this accounted for 87 to 92 percent of initial contact emails each month, as attackers build rapport before making a fraudulent request rather than asking for money upfront.

How are QR codes being used in phishing attacks?

QR codes are increasingly delivered inside PDF or DOC/DOCX attachments, leading victims to credential-stealing login pages rather than requiring a malicious download.

Can a calendar invite alone be dangerous?

Yes. ICS calendar invitations can inject malicious links into a user's calendar without requiring an explicit open-and-click interaction, and this technique nearly quadrupled in June.

Is phishing moving beyond email?

Microsoft observed continued growth in Teams-based social engineering, including voice phishing, since these channels can appear more trustworthy to users than email.

Read the video transcript

You get an email from a VP: “Are you at your desk?” No details. Just that line. That’s classic BEC. Microsoft saw billions of phishing emails, and up to 92% of these scams now start with vague openers like this to build rapport before asking for money or sensitive files. Here’s the twist: the same quarter, QR code phishing in PDFs and DOCX surged too, attachments telling you, “Scan the QR code to sign in,” then stealing your password on a fake login page. If you get a vague “Are you at your desk?” or a random QR code attachment, don’t answer or scan, pause and call or message the person using a known contact to confirm it’s really them.

Similar attacks

QR-Code PDFs Steal Microsoft 365 Logins

QR-Code PDFs Steal Microsoft 365 Logins

Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing…

July 28, 2026
How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

July 29, 2026