Security

Authentication Abuse Nearly Doubled in One Quarter, and Attackers Are Using Your Own Enrollment Process to Get In

Cisco Talos's Q2 2026 incident response data shows phishing crossing the halfway mark, a QR-code PDF campaign routing victims to credential-harvesting pages, and a new ransomware variant riding in on remote management tools IT already trusts.

September 21, 2026 · Security
An empty modern security operations centre with rows of desks and a wall of monitors displaying surveillance and network feeds

Key Takeaways

  • Phishing was the initial access vector in over 50% of Cisco Talos incident response engagements in Q2 2026, up from roughly 35% the quarter before.
  • Authentication abuse appeared in 65% of engagements, nearly double the 35% recorded in Q1, driven by adversary-in-the-middle proxies, session-token theft, MFA fatigue, and self-enrolled attacker-controlled devices.
  • A campaign Talos tracks as UAT-11764 used auto-generated, victim-tailored PDFs with embedded QR codes to route targets to Microsoft 365 credential-harvesting pages, running from April through late June 2026 against mostly Australian organisations.
  • Ransomware showed up in more than 20% of engagements, including a new variant called Sinobi that reached domain-wide encryption using a trojanized MeshAgent binary and the Zoho Assist Unattended Agent.

Six months ago, phishing had just reclaimed the top spot for initial access after ceding it to edge-device exploitation for two straight quarters, with Cisco Talos's Q1 2026 data marking the first quarter phishing had led the category since the second half of 2025. The latest incident response numbers show that recovery was not a blip. Phishing kept climbing, and the more telling figure sits one line below it: authentication abuse, what an attacker does once they are past the front door, nearly doubled in the same three months.

Authentication Abuse Nearly Doubles While Phishing Climbs Past Half

Cisco Talos's Q2 2026 IR Trends report puts phishing in over 50% of engagements where the initial access vector could be determined, up from around 35% in Q1. Authentication abuse rose alongside it, showing up in 65% of engagements against 35% the quarter before, a jump Cisco's own security leadership has since flagged as one of the sharpest quarter-over-quarter moves in the report's history. The bypass methods behind that number read like a checklist of controls most organisations believe they already have covered: adversary-in-the-middle proxies that sit between a user and a real login page, session-token theft that skips the credential entirely, MFA fatigue attacks that simply wait out an annoyed user, exploitation of the OAuth device authorization flow, and legacy authentication protocols that route around modern MFA altogether.

Self-enrolled attacker-controlled devices deserve particular attention, because that failure sits upstream of the login screen entirely. If an attacker can register a new device against a compromised account before anyone notices, every MFA prompt that follows looks legitimate, because from the identity provider's perspective, it is. That moves the fix out of the authentication stack and into device enrollment policy and fleet oversight, the part of the identity chain most audits still treat as a provisioning task rather than a security control.

A QR Code in a PDF Is All Some Campaigns Need Now

The report's clearest example of that shift is a campaign Talos tracks as UAT-11764, active from April through late June 2026 and aimed mostly at Australian organisations. It sent auto-generated, victim-tailored PDF documents containing QR codes that pointed to adversary-controlled Microsoft 365 credential-harvesting pages, a delivery method built specifically to slip past email gateways that scan for malicious links rather than embedded images.

Once inside, the operators didn't need new infrastructure to keep going. Talos found them creating inbox rules for persistence and hosting follow-on phishing material directly on SharePoint, turning the target's own content-sharing platform into distribution infrastructure for the next round of victims. It's a pattern that shows up across the wider report too: phishing links increasingly sit on trusted cloud platforms rather than throwaway domains, because a link hosted on infrastructure a spam filter already trusts is a link that survives the trip to the inbox.

The Ransomware at the End Rides In on Tools IT Already Approved

Ransomware appeared in more than 20% of Q2 engagements, and the quarter's newest entrant illustrates why credential and identity abuse matters even after the encryption starts. Sinobi, first observed in April 2026, reached domain-wide encryption using a trojanized MeshAgent binary deployed as a SYSTEM-level auto-start service alongside the Zoho Assist Unattended Agent, both legitimate remote monitoring and management tools with no malware signature for an endpoint tool to flag. The operators pushed both through malicious Group Policy Object logon scripts, a deployment path that reaches every machine in a domain in a single push.

None of the four figures above is really a phishing statistic. Each one is about what a stolen, spoofed, or self-enrolled credential can do once MFA has already been satisfied, however that happened. The quarter's real shift wasn't that attackers found a new way in. It's that they stopped needing malware to move once they were there.

The number worth carrying forward isn't 50%, phishing's new share of initial access. It's 65, the share of engagements where the login itself, not the inbox, was the thing that actually gave.

Share

More in Security

All Resources →