Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
Trend
Summary
Hide ▲
Show ▼
Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on compromise. The share of cases that began with phishing rose to just over half, up from one-third in the previous quarter. Other recurring entry paths included exploitation of public-facing applications and drive-by compromise.
Related Happenings
UAT-11764 QR code phishing campaign against organizations
Campaign
H score29
First: 28.07.2026 16:00
Last: 28.07.2026 16:00
Sources 1
How related:
The campaign, which is described as persistent and was ongoing as of late June 2026, uses auto-generated victim-tailored PDF documents which contain QR codes that direct victims to adversary-controlled Microsoft 365 credential harvesting pages.
About this happening:
A persistent QR code phishing campaign attributed to UAT-11764 is stealing Microsoft 365 credentials from organizations and reusing compromised mailboxes for follo...
UAT-11764 QR code phishing campaign against organizations
CampaignHow related: The campaign, which is described as persistent and was ongoing as of late June 2026, uses auto-generated victim-tailored PDF documents which contain QR codes that direct victims to adversary-controlled Microsoft 365 credential harvesting pages.
About this happening: A persistent QR code phishing campaign attributed to UAT-11764 is stealing Microsoft 365 credentials from organizations and reusing compromised mailboxes for follo...
Kratos ecosystem shift changes threat-actor operations
Threat Actor Meta
H score39
First: 22.07.2026 02:07
Last: 22.07.2026 02:07
Sources 1
About this happening:
The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Kratos ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
23AndMe hit by network compromise
Incident
H score55
First: 16.07.2026 16:47
Last: 16.07.2026 16:47
Sources 1
About this happening:
23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...
23AndMe hit by network compromise
IncidentAbout this happening: 23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...
Latest development: 17.07.2026 17:30
23andMe reached an $18m settlement with a coalition of 42 US attorneys general over the 2023 credential stuffing breach, and the agreement adds new data protection requirements for 23andMe customer data and TTAM Research.
Identity-based access becomes the leading ransomware initial-access trend in 2026
Trend
H score28
First: 15.07.2026 15:45
Last: 15.07.2026 15:45
Sources 1
About this happening:
Identity-based attacks became the leading ransomware initial-access trend, raising the risk of credential abuse and legitimate login misuse across affected networks. S...
Identity-based access becomes the leading ransomware initial-access trend in 2026
TrendAbout this happening: Identity-based attacks became the leading ransomware initial-access trend, raising the risk of credential abuse and legitimate login misuse across affected networks. S...
QR code phishing surged across email threats in Q1 2026
Trend
H score73
First: 05.05.2026 09:35
Last: 05.05.2026 09:35
Sources 1
How related:
An example of this, as detailed by researchers, was a QR code phishing campaign which targeted organizations in an effort to harvest login credentials and further propagate the attacks by automatically targeting the victims’ contacts too.
About this happening:
QR code phishing remains a growing email threat trend across organizations, with Q1 2026 telemetry showing it as the fastest-growing vector in Microsoft's reportin...
QR code phishing surged across email threats in Q1 2026
TrendHow related: An example of this, as detailed by researchers, was a QR code phishing campaign which targeted organizations in an effort to harvest login credentials and further propagate the attacks by automatically targeting the victims’ contacts too.
About this happening: QR code phishing remains a growing email threat trend across organizations, with Q1 2026 telemetry showing it as the fastest-growing vector in Microsoft's reportin...
Timeline
-
28.07.2026 03:00 2 articles · 15h ago
Cisco Talos reports phishing as the dominant initial access vector
Technical Analysis UpdateCisco Talos published an Incident Response Trends report showing that phishing accounted for the initial attack vector in just over half of incidents investigated during March to June 2026, rising from one-third in the previous quarter. The analysis also highlighted a persistent QR code phishing campaign attributed to UAT-11764 that targeted organizations with victim-tailored PDF files leading to Microsoft 365 credential-harvesting pages, then used stolen credentials for inbox-rule creation and follow-on phishing.
Show sources
- Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques — www.infosecurity-magazine.com — 28.07.2026 16:00
- Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques — www.infosecurity-magazine.com — 28.07.2026 16:00