Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
Trend
Summary
Hide ▲
Show ▼
Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on compromise. The share of cases that began with phishing rose to just over half, up from one-third in the previous quarter. Other recurring entry paths included exploitation of public-facing applications and drive-by compromise.
Related Happenings
Microsoft 365 AitM phishing campaign using residential proxies
Campaign
H score34
First: 07.08.2026 13:38
Last: 07.08.2026 13:38
Sources 1
About this happening:
An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Microsoft 365 AitM phishing campaign using residential proxies
CampaignAbout this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor Meta
H score40
First: 04.08.2026 20:27
Last: 04.08.2026 20:27
Sources 1
About this happening:
Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor MetaAbout this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
Microsoft Teams OAuth phishing campaign targeting 120 organizations
Campaign
H score30
First: 30.07.2026 15:00
Last: 30.07.2026 15:00
Sources 1
About this happening:
A Microsoft Teams-themed phishing campaign is abusing Microsoft’s legitimate authentication infrastructure to steal OAuth access and compromise corporate accounts...
Microsoft Teams OAuth phishing campaign targeting 120 organizations
CampaignAbout this happening: A Microsoft Teams-themed phishing campaign is abusing Microsoft’s legitimate authentication infrastructure to steal OAuth access and compromise corporate accounts...
UAT-11764 QR code phishing campaign against organizations
Campaign
H score29
First: 28.07.2026 16:00
Last: 28.07.2026 16:00
Sources 1
How related:
The campaign, which is described as persistent and was ongoing as of late June 2026, uses auto-generated victim-tailored PDF documents which contain QR codes that direct victims to adversary-controlled Microsoft 365 credential harvesting pages.
About this happening:
A persistent QR code phishing campaign attributed to UAT-11764 is stealing Microsoft 365 credentials from organizations and reusing compromised mailboxes for follo...
UAT-11764 QR code phishing campaign against organizations
CampaignHow related: The campaign, which is described as persistent and was ongoing as of late June 2026, uses auto-generated victim-tailored PDF documents which contain QR codes that direct victims to adversary-controlled Microsoft 365 credential harvesting pages.
About this happening: A persistent QR code phishing campaign attributed to UAT-11764 is stealing Microsoft 365 credentials from organizations and reusing compromised mailboxes for follo...
Kratos ecosystem shift changes threat-actor operations
Threat Actor Meta
H score39
First: 22.07.2026 02:07
Last: 22.07.2026 02:07
Sources 1
About this happening:
The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Kratos ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Timeline
-
28.07.2026 03:00 2 articles · 10d ago
Cisco Talos reports phishing as the dominant initial access vector
Technical Analysis UpdateCisco Talos published an Incident Response Trends report showing that phishing accounted for the initial attack vector in just over half of incidents investigated during March to June 2026, rising from one-third in the previous quarter. The analysis also highlighted a persistent QR code phishing campaign attributed to UAT-11764 that targeted organizations with victim-tailored PDF files leading to Microsoft 365 credential-harvesting pages, then used stolen credentials for inbox-rule creation and follow-on phishing.
Show sources
- Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques — www.infosecurity-magazine.com — 28.07.2026 16:00
- Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques — www.infosecurity-magazine.com — 28.07.2026 16:00