Skip to main content
← Back to all posts
email security··8 min read·By Quantm Security Team

Advanced Email Threats Small Businesses Should Watch in 2026

QR-code phishing, CAPTCHA evasion, session theft, vendor compromise, conversation hijacking, BEC, and malicious content for AI assistants require layered controls.

The advanced email threats that matter to small businesses in 2026 are not defined by polished writing alone. Attackers are combining QR codes, multi-step redirects, CAPTCHA pages, trusted cloud services, stolen sessions, compromised suppliers, and legitimate conversation context to bypass simple checks.

The response is not a single new product. It is to connect message inspection with identity, device, business-process, and incident-response controls.

QR-code phishing

A QR code can hide a destination inside an image and move the user from a managed computer to a phone. The landing page may imitate Microsoft 365, a document service, or an MFA setup process.

Use image-aware message inspection where available, mobile-access controls, user training, and a policy that unexpected QR codes are reported rather than scanned. Microsoft observed a sharp increase in QR phishing during Q1 2026, but businesses should use their own telemetry to set priorities.

CAPTCHA and multi-step evasion

A CAPTCHA or benign first page can hide the final destination from automated systems. Redirect chains may change based on device, location, or time.

Time-of-click analysis, browser protection, DNS or web controls, endpoint telemetry, and user reports give the business more opportunities to identify the chain.

Adversary-in-the-middle and session theft

Some phishing kits proxy a legitimate sign-in and capture both credentials and the resulting session. Basic MFA may be completed by the victim during the attack.

Prefer phishing-resistant authentication, restrict risky access, monitor sign-ins, protect sessions where supported, and maintain a playbook that revokes sessions and reviews authentication methods, OAuth grants, inbox rules, and affected devices.

Vendor compromise and conversation hijacking

A compromised supplier or client account can provide authentic sender infrastructure and real thread history. The attacker may wait for an invoice or sensitive exchange, then substitute payment instructions or a malicious document.

Independent verification of bank and account changes remains essential. Email authentication cannot prove that the person controlling a valid account is authorized to make the request.

Business email compromise without payloads

BEC may contain no link or file. It relies on authority, urgency, secrecy, or a familiar relationship to cause a transfer or disclosure.

Protect high-risk workflows with dual approval, known-channel verification, role-based training, and clear escalation. Technical anomaly detection can help, but business controls decide whether the requested action proceeds.

Malicious instructions for AI workflows

When an AI assistant summarizes or acts on email, attacker-written content becomes untrusted input to the automation. Hidden or visible instructions may try to change classification, expose information, or trigger an action.

Limit what email-connected automation can access and do. Require approval for sensitive actions, separate instructions from message content, retain logs, and use supported filtering. Microsoft documents prompt-injection detection for supported Defender for Office 365 Plan 2 environments.

Priority map

Threat Control to verify first
QR phishing Image inspection, mobile access, reporting
CAPTCHA or redirects Time-of-click, browser, DNS and endpoint signals
Session theft Phishing-resistant MFA, Conditional Access, session response
Vendor compromise Independent payment and account-change verification
Payload-free BEC Approval workflow and role-based training
AI workflow injection Least privilege, approval gates, logging, content filtering

Revisit the AI-enabled phishing control guide for Microsoft 365 details and how email filters work for the inspection pipeline. The email security control model for SMBs places these threats in context. Use a tenant-specific Microsoft 365 security review to prioritize controls against your actual licence, workflows, and exposure.