Cisco Talos's Q2 2026 incident response data shows phishing crossing the halfway mark, a QR-code PDF campaign routing victims to credential-harvesting pages, and a new ransomware variant riding in on remote management tools IT already trusts.
Key Takeaways
Six months ago, phishing had just reclaimed the top spot for initial access after ceding it to edge-device exploitation for two straight quarters, with Cisco Talos's Q1 2026 data marking the first quarter phishing had led the category since the second half of 2025. The latest incident response numbers show that recovery was not a blip. Phishing kept climbing, and the more telling figure sits one line below it: authentication abuse, what an attacker does once they are past the front door, nearly doubled in the same three months.
Cisco Talos's Q2 2026 IR Trends report puts phishing in over 50% of engagements where the initial access vector could be determined, up from around 35% in Q1. Authentication abuse rose alongside it, showing up in 65% of engagements against 35% the quarter before, a jump Cisco's own security leadership has since flagged as one of the sharpest quarter-over-quarter moves in the report's history. The bypass methods behind that number read like a checklist of controls most organisations believe they already have covered: adversary-in-the-middle proxies that sit between a user and a real login page, session-token theft that skips the credential entirely, MFA fatigue attacks that simply wait out an annoyed user, exploitation of the OAuth device authorization flow, and legacy authentication protocols that route around modern MFA altogether.
Self-enrolled attacker-controlled devices deserve particular attention, because that failure sits upstream of the login screen entirely. If an attacker can register a new device against a compromised account before anyone notices, every MFA prompt that follows looks legitimate, because from the identity provider's perspective, it is. That moves the fix out of the authentication stack and into device enrollment policy and fleet oversight, the part of the identity chain most audits still treat as a provisioning task rather than a security control.
The report's clearest example of that shift is a campaign Talos tracks as UAT-11764, active from April through late June 2026 and aimed mostly at Australian organisations. It sent auto-generated, victim-tailored PDF documents containing QR codes that pointed to adversary-controlled Microsoft 365 credential-harvesting pages, a delivery method built specifically to slip past email gateways that scan for malicious links rather than embedded images.
Once inside, the operators didn't need new infrastructure to keep going. Talos found them creating inbox rules for persistence and hosting follow-on phishing material directly on SharePoint, turning the target's own content-sharing platform into distribution infrastructure for the next round of victims. It's a pattern that shows up across the wider report too: phishing links increasingly sit on trusted cloud platforms rather than throwaway domains, because a link hosted on infrastructure a spam filter already trusts is a link that survives the trip to the inbox.
Ransomware appeared in more than 20% of Q2 engagements, and the quarter's newest entrant illustrates why credential and identity abuse matters even after the encryption starts. Sinobi, first observed in April 2026, reached domain-wide encryption using a trojanized MeshAgent binary deployed as a SYSTEM-level auto-start service alongside the Zoho Assist Unattended Agent, both legitimate remote monitoring and management tools with no malware signature for an endpoint tool to flag. The operators pushed both through malicious Group Policy Object logon scripts, a deployment path that reaches every machine in a domain in a single push.
None of the four figures above is really a phishing statistic. Each one is about what a stolen, spoofed, or self-enrolled credential can do once MFA has already been satisfied, however that happened. The quarter's real shift wasn't that attackers found a new way in. It's that they stopped needing malware to move once they were there.
The number worth carrying forward isn't 50%, phishing's new share of initial access. It's 65, the share of engagements where the login itself, not the inbox, was the thing that actually gave.
Whitepaper
Built on the same Cisco Talos threat intelligence behind this quarter's authentication abuse numbers, mapping the patterns behind them before they show up in your own incident queue.
Download
Guide
UAT-11764's operators hosted follow-on phishing material on SharePoint itself, and this guide frames the access controls and audit trails that keep a content platform from becoming attacker infrastructure.
Download
Whitepaper
Self-enrolled attacker-controlled devices are now a named MFA bypass method, and this whitepaper covers the automated enrollment and compliance enforcement that keeps enrollment a controlled process rather than an open door.
Download
Cyera reviewed 7,246 publicly reported AI incidents to find them.
CrowdStrike puts average eCrime breakout time at 29 minutes.
Qualys says the five-month remediation gap is entirely normal.