CAPTCHA-bypass lures and ClickFix-style social engineering are helping credential thieves get past both users and security tools, and the latest Q1 2026 data shows these tactics are becoming more common.
Microsoft Threat Intelligence says email phishing remained massive in scale, but attackers increasingly favored link-based delivery, QR code lures, and CAPTCHA-gated pages to steal credentials.
Microsoft recorded about 8.3 billion email-based phishing threats in the first quarter of 2026, with monthly volume easing from 2.9 billion in January to 2.6 billion in March.
CAPTCHA Bypass and ClickFix Lures
Link-based messages made up 78% of email threats, while malicious payloads fell from 19% in January to 13% in February and March, showing a clear move toward hosted phishing infrastructure.
QR code phishing was the fastest-growing tactic, more than doubling over the quarter, and it reached its highest monthly level in at least a year by March.
.webp)
Credential theft remained the main goal behind malicious payloads throughout the quarter.
Microsoft said this shift suggests threat actors preferred phishing pages hosted online rather than payloads that render locally on a victim’s device.
That approach can make attacks faster to deploy and harder for security tools to catch early.
.webp)
CAPTCHA-gated phishing also surged sharply in March, jumping 125% to 11.9 million attacks after declines in January and February.
Attackers rotated among HTML, PDF, SVG, DOC/DOCX, and email-embedded URL delivery methods, which suggests active testing to find the most effective bypass path.
Microsoft also observed that the share of CAPTCHA-gated sites hosted on Tycoon2FA infrastructure fell to 41% in March, showing the tactic is spreading beyond one platform.
.webp)
One major theme in the quarter was the use of fake CAPTCHA pages to delay analysis and push users into interacting with the attack.
Microsoft also noted ClickFix-style abuse, where fake verification prompts trick users into copying or executing malicious commands instead of simply entering credentials.
A separate early-2026 campaign described fake CAPTCHA lures as a way to deliver a stealthy information stealer, reinforcing how effective the technique has become.
Tycoon2FA remained a key example of how disruption can hurt phishing operations, at least temporarily.
After Microsoft’s Digital Crimes Unit and partners moved against its infrastructure in early March, associated email volume dropped 15% for the rest of the month, and access to active phishing pages was reduced.
The platform later shifted hosting providers and registration patterns, but Microsoft described that as partial recovery rather than a full return to prior scale.
Business email compromise was still widespread too, with about 10.7 million attacks in the quarter.
Most of those messages were low-effort and generic, which shows attackers are using both sophisticated phishing kits and simple social engineering at the same time.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.