Cloud and SaaS targeting shifts toward identity, email auth, and non-human accounts in H1 2026
Trend
Summary
Hide ▲
Show ▼
Cloud and SaaS environments became top targets in H1 2026, with attackers shifting from malware and vulnerability exploitation toward identity compromise and trust-layer abuse. The trend expands risk across email authentication, cloud entitlements, supply chains, AI gateways, remote administration tooling, and non-human identities.
Related Happenings
Global phishing and identity-compromise trend across Darktrace customers in 2025
Trend
H score61
First: 26.02.2026 17:00
Last: 26.02.2026 17:00
Sources 1
About this happening:
Darktrace telemetry showed a sharp rise in identity-driven phishing across its global customer base in 2025, with more than 32 million high-confidence phishing...
Global phishing and identity-compromise trend across Darktrace customers in 2025
TrendAbout this happening: Darktrace telemetry showed a sharp rise in identity-driven phishing across its global customer base in 2025, with more than 32 million high-confidence phishing...
Timeline
-
04.08.2026 14:30 2 articles · 2h ago
Attackers target cloud and SaaS identities across email, supply chains, and AI gateways
Campaign Scope UpdateDarktrace reported that attackers in H1 2026 increasingly targeted cloud and SaaS environments by compromising identities and abusing trust controls rather than relying on malware or vulnerability exploitation. The shift extended to email authentication, cloud entitlements, software supply chains, AI gateways, remote administration tooling, and non-human identities, with examples including inbox rule changes, phishing, and a compromised SaaS account that drove activity across email, SaaS, and network layers.
Show sources
- Cloud and SaaS Environments Now Top Targets for Attackers — www.infosecurity-magazine.com — 04.08.2026 14:30
- Cloud and SaaS Environments Now Top Targets for Attackers — www.infosecurity-magazine.com — 04.08.2026 14:30