Find notable cyber news and cases, enriched with sources, timelines, and signals.

Identity-targeted malicious activity accounted for roughly half of confirmed investigations across customer environments in May-July 2026

Trend
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

Across May 1 to July 31, 2026, identity was the target in roughly half of confirmed malicious activity across customer environments, showing that account takeover remained a dominant attack pattern. The quarter’s findings point to repeated abuse of sessions, credentials, and phishing rather than isolated one-off intrusions. Attackers most often succeeded when they stole an already-authenticated session or used other techniques that bypassed standard login checks. The concentration of identity abuse increased operational risk because stolen access often survived password resets and even account disablement.

Related Happenings

UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign

Campaign
H score16 First: 20.08.2026 22:59 Last: 20.08.2026 22:59 Sources 1

About this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...

Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026

Trend
H score30 First: 28.07.2026 16:00 Last: 28.07.2026 16:00 Sources 1

About this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...

Google hit by network compromise

Incident
H score42 First: 14.07.2026 09:19 Last: 14.07.2026 09:19 Sources 1

About this happening: Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...

W3LL Microsoft 365 adversary-in-the-middle phishing campaign

Campaign
H score39 First: 13.04.2026 21:55 Last: 13.04.2026 21:55 Sources 1

About this happening: The W3LL phishing operation turned into a high-volume Microsoft 365 credential-theft campaign, exposing more than 17,000 victims worldwide to BEC risk. The kit use...

Global phishing and identity-compromise trend across Darktrace customers in 2025

Trend
H score61 First: 26.02.2026 17:00 Last: 26.02.2026 17:00 Sources 1

About this happening: Darktrace telemetry showed a sharp rise in identity-driven phishing across its global customer base in 2025, with more than 32 million high-confidence phishing...

Timeline

  1. 10.09.2026 17:00 2 articles · 2h ago

    Identity was the target in roughly half of confirmed malicious activity

    Campaign Scope Update

    Prophet Security's quarterly report covering May 1 to July 31, 2026 found that identity was the target in roughly half of all confirmed malicious activity across customer environments, with successful account takeovers driven by stolen sessions, browser-delivered infostealers, and highly targeted phishing. Of completed investigations, about 93% were benign and 7% were confirmed malicious, showing that the quarter's confirmed activity concentrated on account access rather than malware delivery alone.

    Show sources