Microsoft published its 2026 Digital Defense Report on 1 October. Most of the coverage went to AI-run attacks and ransomware. The part that matters most for anyone who runs company email is quieter, and it sits on pages 33 and 45 of the PDF: phishing is back as a main way in, and the typical phishing page is no longer a fake login form that just steals a password.
This piece pulls out the email findings, explains what they mean in practice, and is honest about what a mail platform (ours included) can and cannot do about them.
What the report actually says about phishing
The report covers July 2025 to June 2026. In Microsoft's incident response cases, phishing was the initial access vector in 23% of intrusions, up from 7% the year before. Over the same period, the share of cases with no identified entry point fell from 25% to 14%, so part of that jump may be better visibility, but the direction is clear.
The bigger change is the kind of phishing. Adversary-in-the-middle (AiTM) kits now make up 44.6% of identified phishing techniques, against 33.6% for standard URL phishing and 12.9% for attachments. An AiTM page is a reverse proxy. The victim sees the real sign-in page, types a real password, approves a real MFA prompt, and the proxy keeps the session cookie that comes back. On the same page Microsoft reports that 87.7% of phishing intrusions involved credential or session harvesting.
And once an attacker has one working account, they go looking for more. Of intrusions that started with valid accounts, 52.2% involved follow-on credential theft.
Why a six-digit code no longer saves you
Here is the uncomfortable part. SMS codes, authenticator-app codes and push approvals all stop the old attack, where someone buys a leaked password and logs in from another country. None of them stop AiTM. The proxy simply forwards whatever the user types, code included, to the real server in real time. The user did everything right and still handed over a live session.
What does stop it is authentication that is tied to the website's address: FIDO2 security keys and passkeys. The browser will not sign a challenge for a look-alike domain, so there is nothing useful for a proxy to relay. Microsoft's own recommendations in the report say the same thing in plainer words: move beyond traditional MFA and prioritise phishing-resistant methods.
We think that is right, and it applies to us. FanMail offers SMS one-time passwords and TOTP authenticator codes as a second factor. They are a big improvement over passwords alone, and for many organisations they are the only second factor people will actually enrol in. They are not phishing-resistant, and we would rather say so here than have a customer learn it from an incident report.
The delivery tricks that get past filters
Getting the victim to the proxy page is the other half, and the report shows attackers rotating formats faster than filters adapt:
QR codes in PDFs. Microsoft Defender for Office 365 detected more than 145 million QR code phishing attacks, and by April 2026 PDFs carried 79% of them. The user opens the PDF on a work laptop and scans the code with a personal phone, which sits outside every corporate control.
CAPTCHA gates. On the same page, more than 100 million phishing attacks put a CAPTCHA in front of the credential page, which keeps automated scanners from ever seeing it.
Device code phishing. The lure sends people to the real Microsoft device sign-in page and the attacker collects OAuth tokens afterwards. No fake page at all, so there is nothing to block by URL.
Fake help desk. A burst of junk email, then a chat message from a new account posing as IT support offering to fix it. That one is aimed at your people's trust in their own support team.
We wrote earlier about how a PDF can carry script into a help desk or file share, in our note on hardening PDF attachment downloads. The QR-in-PDF trend is a different attack through the same door: a file format everyone treats as safe.
Five things to do this quarter
Start passkeys or FIDO2 keys with the accounts that matter most. Admins, finance, HR and anyone who can approve payments. You do not need the whole company on day one.
Shorten and watch sessions. AiTM steals a session, not a password, so long-lived sessions and silent token refresh are what make it pay. Alert on the same session appearing from a new network.
Treat QR codes in attachments as links. If your mail filter cannot read a QR code inside a PDF, assume users will scan it with a phone that has no protection.
Tell staff how the real help desk contacts them. One sentence in onboarding, repeated every few months: support never asks you to install a remote tool from a chat message.
Keep SPF, DKIM and DMARC strict on your own domains. It will not stop a look-alike domain, but it stops the cheapest version of the attack, a spoof of your exact address.
Where FanMail fits, and where it does not
FanMail is a self-hosted mail platform built on Stalwart Mail Server. It can help with parts of the list above: outgoing mail is signed with DKIM and checked against SPF and DMARC, the message reader sanitises HTML and can block external images, and users can turn on SMS or authenticator-app two-factor login. Because it runs on your own servers, the server logs are yours to query when you want to check where a session has been used.
What it does not do is make SMS or TOTP codes phishing-resistant, and no mail server can. If AiTM is your main worry, put phishing-resistant authentication in front of email, whatever mail product you use. For more on why we built SMS login in the first place, see our notes on SMS OTP, and if you are comparing hosted options, our FanMail, Google Workspace and Zoho Mail comparison covers data control and cost.
Originally published on fanpino.com.
Top comments (0)