Phishing trends and techniques
In brief
The article adds examples of calendar invitations, attached emails, nested attachments, QR code phishing, and CAPTCHA-gated phishing, and updates its reference links and wording.
What Defender admins need to know
Administrators and security professionals can use the expanded guidance to recognize current phishing techniques and help prevent related attacks.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Phishing trends and techniques
Downloads
An attacker sends a fraudulent email requestingthat asks you to open or download a documentan attachment, such as a PDF.PDF, Microsoft Word document, calendar invitation (.ics), or attached email (.eml). The attachment often containsmight contain a link or message askingthat asks you to sign in to another site,an email or file-sharing site.
Attackers can also nest attachments, such as an email or file sharing websites,that contains a calendar invitation, to opencreate a multistage phishing flow. If you enter your credentials on the document. When you access these phishing sites using your sign-in credentials,site, the attacker now hasgains access to your informationaccount information.
QR code phishing
QR code phishing, also called quishing, embeds a QR code in an image, PDF, or Word document. The message asks you to scan the code with a mobile device, which opens a credential-harvesting site. This technique moves the interaction away from email link scanning and can gain additional personal information about you.onto a device where the destination URL is harder to inspect before you open it.
CAPTCHA-gated phishing
CAPTCHA-gated phishing sites require you to complete a CAPTCHA or another interaction before they display the lure or redirect you to a spoofed sign-in page. Attackers use this extra step to make the site appear legitimate and hinder automated security analysis. The final page commonly attempts to steal credentials.
Phishing emails that deliver other threats
Spear phishing is a targeted phishing attack that involves highly customized lure content. Attackers will typically do reconnaissance work by surveying social media and other information sources about their intended target.
Spear phishing may involve trickingmight trick you into logging intosigning in to fake sites and divulgingentering your credentials. I mayAttackers might also lure you into opening documents by clicking onor selecting links that automatically install malware. With thisThe malware in place,can give attackers can remotely manipulateremote control of the infected computer.
The implanted malware serves as the point of entry for a more sophisticated attack, known as an advanced persistent threat (APT). APTs are designed to establish control and steal data over extended periods. Attackers may try to deploy more covert hacking tools, move laterally to other computers, compromise or create privileged accounts, and regularly exfiltrate information from compromised networks.
For information on the latest phishing attacks, techniques, and trends, you can read these entries on the Microsoft Security blog:
Phishers unleash simple but effective social engineering techniques using PDF attachmentsEmail threat landscape: Q2 2026 trends and insightsTax themed phishing and malware attacks proliferate during the tax filing seasonPhishing like emails lead to tech support scamInside Tycoon2FA: How a leading adversary-in-the-middle phishing kit operated at scale
@@ -11,7 +11,10 @@ ms.collection: - m365-security - tier2 ms.topic: concept-article-ms.date: 03/18/2022+ms.date: 08/07/2026+ai-usage: ai-assisted+ms.custom: msecd-doc-authoring-1015+#customer intent: As a security professional, I want to understand current phishing techniques so that I can recognize and help prevent phishing attacks. --- # Phishing trends and techniques@@ -34,7 +37,17 @@ A common IRS phishing scam is receiving an urgent email letter indicating that y ## Downloads -An attacker sends a fraudulent email requesting you to open or download a document attachment, such as a PDF. The attachment often contains a message asking you to sign in to another site, such as email or file sharing websites, to open the document. When you access these phishing sites using your sign-in credentials, the attacker now has access to your information and can gain additional personal information about you.+An attacker sends a fraudulent email that asks you to open or download an attachment, such as a PDF, Microsoft Word document, calendar invitation (`.ics`), or attached email (`.eml`). The attachment might contain a link or message that asks you to sign in to an email or file-sharing site.++Attackers can also nest attachments, such as an email that contains a calendar invitation, to create a multistage phishing flow. If you enter your credentials on the phishing site, the attacker gains access to your account information.++## QR code phishing++QR code phishing, also called quishing, embeds a QR code in an image, PDF, or Word document. The message asks you to scan the code with a mobile device, which opens a credential-harvesting site. This technique moves the interaction away from email link scanning and onto a device where the destination URL is harder to inspect before you open it.++## CAPTCHA-gated phishing++CAPTCHA-gated phishing sites require you to complete a CAPTCHA or another interaction before they display the lure or redirect you to a spoofed sign-in page. Attackers use this extra step to make the site appear legitimate and hinder automated security analysis. The final page commonly attempts to steal credentials. ## Phishing emails that deliver other threats @@ -46,7 +59,7 @@ We have also seen phishing emails that have links to [tech support scam](support Spear phishing is a targeted phishing attack that involves highly customized lure content. Attackers will typically do reconnaissance work by surveying social media and other information sources about their intended target. -Spear phishing may involve tricking you into logging into fake sites and divulging credentials. I may also lure you into opening documents by clicking on links that automatically install malware. With this malware in place, attackers can remotely manipulate the infected computer.+Spear phishing might trick you into signing in to fake sites and entering your credentials. Attackers might also lure you into opening documents or selecting links that install malware. The malware can give attackers remote control of the infected computer. The implanted malware serves as the point of entry for a more sophisticated attack, known as an advanced persistent threat (APT). APTs are designed to establish control and steal data over extended periods. Attackers may try to deploy more covert hacking tools, move laterally to other computers, compromise or create privileged accounts, and regularly exfiltrate information from compromised networks. @@ -62,6 +75,5 @@ Business email compromise (BEC) is a sophisticated scam that targets businesses For information on the latest phishing attacks, techniques, and trends, you can read these entries on the [Microsoft Security blog](https://www.microsoft.com/security/blog/): -- [Phishers unleash simple but effective social engineering techniques using PDF attachments](https://cloudblogs.microsoft.com/microsoftsecure/2017/01/26/phishers-unleash-simple-but-effective-social-engineering-techniques-using-pdf-attachments/?source=mmpc)-- [Tax themed phishing and malware attacks proliferate during the tax filing season](https://cloudblogs.microsoft.com/microsoftsecure/2017/03/20/tax-themed-phishing-and-malware-attacks-proliferate-during-the-tax-filing-season/?source=mmpc)-- [Phishing like emails lead to tech support scam](https://cloudblogs.microsoft.com/microsoftsecure/2017/08/07/links-in-phishing-like-emails-lead-to-tech-support-scam/?source=mmpc)+- [Email threat landscape: Q2 2026 trends and insights](https://www.microsoft.com/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/)+- [Inside Tycoon2FA: How a leading adversary-in-the-middle phishing kit operated at scale](https://www.microsoft.com/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/) 