Identity Threats Surge as Phishing and Authentication Abuse Rise

Phishing accounted for more than half of cybersecurity incident response engagements in the second quarter of 2026, while authentication abuse was observed in 65% of engagements, according to Cisco Talos’s latest Incident Response Trends report.

The findings point to an increasing focus on identity-based attacks as threat actors seek to gain access to enterprise environments and evade traditional security controls. Phishing increased from 35% of engagements in the previous quarter to more than 50% in Q2, while authentication abuse nearly doubled quarter by quarter.

“Identity has become a critical battleground in cybersecurity as attackers increasingly look for ways to exploit legitimate credentials and trusted tools to gain access and remain undetected,” said Fady Younes, Managing Director for Cybersecurity, Cisco Middle East, Türkiye, Africa, Caucasus and Central Asia (METAC). “As organizations across the region accelerate digital transformation and adopt new technologies, protecting identities must remain a core part of their security strategy. Organizations should prioritize phishing-resistant authentication, strengthen visibility across their environments and focus on detecting unusual behavior before attackers can move further through the network.”

Attackers increasingly exploit legitimate tools
Ransomware and pre-ransomware activity accounted for more than 20% of Talos Incident Response engagements during the quarter.

Talos observed ransomware operators using legitimate remote management tools in previously unreported ways to maintain persistent access while reducing the likelihood of detection.

Sinobi ransomware operators, for example, were observed using a trojanized MeshAgent binary as a primary command-and-control mechanism, a tactic not previously associated with the group in public reporting. Warlock ransomware operators were also observed using the Zoho Assist Unattended Agent, which had not previously been publicly attributed to the group.

The use of legitimate tools can make malicious activity more difficult to distinguish from normal enterprise operations, potentially allowing attackers to maintain access and move through environments without immediately triggering security alerts.

Healthcare remains the most targeted sector
Healthcare was the most targeted industry in Talos Incident Response engagements for the second consecutive quarter, followed by public administration and manufacturing.

The findings highlight continued pressure on sectors that manage sensitive information and depend heavily on the availability of critical systems and services.

Strengthening defenses against identity-based attacks
Cisco Talos recommends that organizations strengthen their security posture by adopting phishing-resistant multi-factor authentication methods, including hardware security keys.

Organizations should also maintain centralized logging with at least 90 days of retention to support investigation and visibility, prioritize rapid patching of internet-facing infrastructure and introduce outbound email thresholds to help limit the spread of phishing campaigns.