
QR-PDF Phishing Hits M365, MFA Bypass Surges
Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…
Microsoft reports billions of phishing attempts in Q2 2026, with attackers increasingly using attachments (PDF/DOC/HTML) and new formats like calendar invites to trick employees into entering credentials. The report also highlights continued growth in Teams-based social engineering and notes that most BEC scams start with simple “conversation starter” emails before moving to fraud.
According to Microsoft's Q2 2026 threat data, business email compromise (BEC) campaigns rarely lead with a financial request. Instead, most begin with a short, vague message such as "Are you at your desk?" These generic conversation starters made up 87 to 92 percent of initial contact emails each month during the quarter. Once a target replies, the attacker uses the established rapport to move toward a fraudulent ask, such as a wire transfer or document request, later in the exchange.
Alongside this, Microsoft tracked roughly 7.6 billion email-based phishing threats in Q2, with credential phishing as the dominant objective. Attackers also leaned on QR codes embedded in PDF and DOC/DOCX attachments to route victims to fake login pages, and increasingly used calendar invitations (ICS files) that can inject malicious links directly into a user's calendar without requiring a click on the invite itself.
Each of these methods works by lowering a target's guard:
Finance, executive assistant, HR, and procurement staff are common BEC targets because they can action payment or document requests. Employees across all roles should treat generic, out-of-context opening messages as a potential early-stage BEC attempt and verify the sender through a separate, known channel before continuing the conversation. Security awareness efforts should also expand beyond email to cover Teams messages, voice calls, and calendar invites, since these channels can feel more trusted to users and are increasingly used to carry out the same underlying credential theft and fraud objectives Microsoft observed in email traffic. See MITRE ATT&CK technique T1566 for background on phishing delivery methods referenced in this report.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Microsoft found generic conversation-starter emails like this accounted for 87 to 92 percent of initial contact emails each month, as attackers build rapport before making a fraudulent request rather than asking for money upfront.
QR codes are increasingly delivered inside PDF or DOC/DOCX attachments, leading victims to credential-stealing login pages rather than requiring a malicious download.
Yes. ICS calendar invitations can inject malicious links into a user's calendar without requiring an explicit open-and-click interaction, and this technique nearly quadrupled in June.
Microsoft observed continued growth in Teams-based social engineering, including voice phishing, since these channels can appear more trustworthy to users than email.
You get an email from a VP: “Are you at your desk?” No details. Just that line. That’s classic BEC. Microsoft saw billions of phishing emails, and up to 92% of these scams now start with vague openers like this to build rapport before asking for money or sensitive files. Here’s the twist: the same quarter, QR code phishing in PDFs and DOCX surged too, attachments telling you, “Scan the QR code to sign in,” then stealing your password on a fake login page. If you get a vague “Are you at your desk?” or a random QR code attachment, don’t answer or scan, pause and call or message the person using a known contact to confirm it’s really them.

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…