Cisco Talos, CrowdStrike, and Verizon all published 2026 threat data pointing to the same shift. Attackers are getting in through people again, then moving through identity systems that leave almost nothing recognisable as malware behind.
Key Takeaways
For two quarters, phishing looked like it was losing ground. Exploitation of public-facing applications had climbed as high as 62% of tracked intrusions, and the industry's attention shifted accordingly toward patch cadence and edge device hardening. Cisco Talos's Q1 2026 incident response data shows that shift was temporary. Phishing is back on top, and what happens after an attacker gets in looks less like a breach every quarter.
Talos's Q1 2026 numbers show phishing involved in over a third of engagements where the initial access vector could be determined, retaking the top spot it had ceded since the second half of 2025. Valid account abuse was second at 24%, and exploitation of public-facing applications fell to 18%, down sharply from its prior high. MFA weaknesses were a factor in 35% of engagements, a reminder that having multi-factor authentication deployed and having it configured correctly are not the same thing.
The report also documents the first case Talos has attributed to a specific AI tool used inside a live phishing campaign. Adversaries used Softr, a legitimate no-code site builder, to stand up credential-harvesting pages that impersonated Microsoft Exchange and Outlook Web Access login screens. Telemetry suggests the technique has been in use since May 2023 and is only now showing up with enough frequency to name. The 2026 Verizon Data Breach Investigations Report puts a number on the broader trend: 44% of AI-assisted initial access techniques it tracked were phishing-related, and 28.6 million phished identity records were recaptured across 2025 alone.
What phishing hands an attacker has also changed. CrowdStrike's 2026 Global Threat Report found 82% of the intrusions it tracked were malware-free, built instead on valid credentials, trusted identity flows, and approved SaaS integrations that never trip a signature-based control. Valid account abuse alone accounted for 35% of cloud incidents. Once inside, attackers move fast: the average eCrime breakout time, the window between initial access and lateral movement onto a second system, dropped to 29 minutes, a 65% improvement in attacker speed since 2024, with the single fastest observed breakout clocked at 27 seconds.
The report also recorded an 89% increase in attack volume from AI-enabled adversaries year over year, a 141% increase in spam email used for initial access, and a 563% jump in fake CAPTCHA lures, a social engineering technique that tricks a user into pasting a malicious command into their own clipboard. None of that requires a dropped executable. When credential theft and legitimate tooling do the work, there is often no malware sample for a defender to pull apart afterward.
Verizon's 2026 DBIR found ransomware involved in 48% of all breaches, the highest share the report has recorded, even as the median ransom payment fell to $139,875 and 69% of victims refused to pay. The more useful number sits earlier in the timeline: 73% of ransomware victims had an infostealer infection or a credential leak event in the year before the attack, and half of those credential events occurred within just 95 days of the ransomware hitting. With 5.3 billion credential pairs already circulating in criminal marketplaces during 2025 and 40% of corporate users found to have reused a password already known to be exposed, the raw material for that pipeline is not scarce, it is sitting in log files most security teams are not reviewing until after encryption starts.
Read together, the three reports describe one pipeline rather than three separate problems. Phishing supplies the credentials, identity-based movement turns those credentials into access that looks legitimate, and ransomware is frequently just the visible endpoint of an intrusion that had already been sitting inside the network for months.
The number worth carrying forward is not 48%, the record ransomware share of breaches. It is 95, the number of days most organisations had between a warning sign they could have caught and an attack they could not.
Guide
Talos just watched phishing retake the top spot for initial access, and this guide breaks down why credential theft keeps outpacing the technical defences built to stop it.
Download
Report
With 82% of intrusions now malware-free and breakouts landing in 29 minutes, this report tracks the access, escalation, and lateral movement a signature-based tool will never flag.
Download
Whitepaper
Verizon traced 73% of ransomware victims back to a credential leak months earlier, and these real incidents map that same path from initial access to encryption.
Download
Only 9% of organisations can scan unstructured data in real time.
Unit 42 found encryption present in just 78% of 2025 extortion cases.
Only 21.9% of enterprises treat AI agents as independent identities yet.