Security

Phishing Reclaims the Top Spot for Initial Access, and 82% of What Follows Skips Malware Entirely

Cisco Talos, CrowdStrike, and Verizon all published 2026 threat data pointing to the same shift. Attackers are getting in through people again, then moving through identity systems that leave almost nothing recognisable as malware behind.

September 14, 2026 · Security
An empty security operations centre at night, rows of monitors displaying camera feeds above a bank of unoccupied workstations

Key Takeaways

  • Phishing reemerged as the most observed initial access vector in Q1 2026, present in over a third of intrusions where the entry point could be determined, per Cisco Talos incident response data.
  • CrowdStrike found 82% of the intrusions it tracked in 2026 were malware-free, relying instead on valid credentials and legitimate identity workflows.
  • The average eCrime breakout time, the gap between initial access and lateral movement, fell to 29 minutes, with the fastest observed case at just 27 seconds.
  • 73% of ransomware victims in the 2026 Verizon Data Breach Investigations Report had an infostealer infection or credential leak in the year before the attack, half within 95 days.

For two quarters, phishing looked like it was losing ground. Exploitation of public-facing applications had climbed as high as 62% of tracked intrusions, and the industry's attention shifted accordingly toward patch cadence and edge device hardening. Cisco Talos's Q1 2026 incident response data shows that shift was temporary. Phishing is back on top, and what happens after an attacker gets in looks less like a breach every quarter.

Phishing Never Left, It Just Went Quiet for a Few Quarters

Talos's Q1 2026 numbers show phishing involved in over a third of engagements where the initial access vector could be determined, retaking the top spot it had ceded since the second half of 2025. Valid account abuse was second at 24%, and exploitation of public-facing applications fell to 18%, down sharply from its prior high. MFA weaknesses were a factor in 35% of engagements, a reminder that having multi-factor authentication deployed and having it configured correctly are not the same thing.

The report also documents the first case Talos has attributed to a specific AI tool used inside a live phishing campaign. Adversaries used Softr, a legitimate no-code site builder, to stand up credential-harvesting pages that impersonated Microsoft Exchange and Outlook Web Access login screens. Telemetry suggests the technique has been in use since May 2023 and is only now showing up with enough frequency to name. The 2026 Verizon Data Breach Investigations Report puts a number on the broader trend: 44% of AI-assisted initial access techniques it tracked were phishing-related, and 28.6 million phished identity records were recaptured across 2025 alone.

Once They're In, There's Often Nothing Left to Detect

What phishing hands an attacker has also changed. CrowdStrike's 2026 Global Threat Report found 82% of the intrusions it tracked were malware-free, built instead on valid credentials, trusted identity flows, and approved SaaS integrations that never trip a signature-based control. Valid account abuse alone accounted for 35% of cloud incidents. Once inside, attackers move fast: the average eCrime breakout time, the window between initial access and lateral movement onto a second system, dropped to 29 minutes, a 65% improvement in attacker speed since 2024, with the single fastest observed breakout clocked at 27 seconds.

The report also recorded an 89% increase in attack volume from AI-enabled adversaries year over year, a 141% increase in spam email used for initial access, and a 563% jump in fake CAPTCHA lures, a social engineering technique that tricks a user into pasting a malicious command into their own clipboard. None of that requires a dropped executable. When credential theft and legitimate tooling do the work, there is often no malware sample for a defender to pull apart afterward.

The Ransomware at the End Was Preventable Months Earlier

Verizon's 2026 DBIR found ransomware involved in 48% of all breaches, the highest share the report has recorded, even as the median ransom payment fell to $139,875 and 69% of victims refused to pay. The more useful number sits earlier in the timeline: 73% of ransomware victims had an infostealer infection or a credential leak event in the year before the attack, and half of those credential events occurred within just 95 days of the ransomware hitting. With 5.3 billion credential pairs already circulating in criminal marketplaces during 2025 and 40% of corporate users found to have reused a password already known to be exposed, the raw material for that pipeline is not scarce, it is sitting in log files most security teams are not reviewing until after encryption starts.

Read together, the three reports describe one pipeline rather than three separate problems. Phishing supplies the credentials, identity-based movement turns those credentials into access that looks legitimate, and ransomware is frequently just the visible endpoint of an intrusion that had already been sitting inside the network for months.

The number worth carrying forward is not 48%, the record ransomware share of breaches. It is 95, the number of days most organisations had between a warning sign they could have caught and an attack they could not.

Share

More in Security

All Resources →