‘Phishing campaigns continue to improve sophistication and refinement’: Microsoft flags major ‘sophisticated’ phishing campaign targeting 35,000 users in 26 countries



  • Microsoft says a large phishing wave targeted more than 35,000 users at 13,000 companies, mostly in the US.
  • Slick business-style emails with urgent messages were used to bypass security controls.
  • Victims were funneled through PDF and CAPTCHA files to collect Microsoft credentials in real time.

Microsoft has warned of a large-scale phishing email campaign targeting organizations primarily based in the United States.

In a new in-depth report, Microsoft said it observed a new campaign between April 14 and 16, 2026 targeting more than 35,000 users across 13,000 companies. While the campaign affected 26 countries, more than nine in ten emails (92%) went to organizations based in the United States.

Leave a Comment

Your email address will not be published. Required fields are marked *