Home » Emerging Technologies » Cyber Security » Identity Attacks Rise as Phishing Surges in Q2
News Desk -

Share

Identity attacks intensified in the second quarter of 2026, as phishing accounted for more than half of cybersecurity incident response engagements, according to Cisco Talos’ latest Incident Response Trends report.

Authentication abuse was observed in 65% of engagements during the quarter. Meanwhile, phishing increased from 35% of engagements in Q1 to more than 50% in Q2. Authentication abuse also nearly doubled quarter over quarter.

The findings highlight a growing focus on identity-based attacks. Threat actors are increasingly seeking legitimate credentials and trusted tools to gain access to enterprise environments and avoid traditional security controls.

“Identity has become a critical battleground in cybersecurity as attackers increasingly look for ways to exploit legitimate credentials and trusted tools to gain access and remain undetected,” said Fady Younes, Managing Director for Cybersecurity, Cisco Middle East, Türkiye, Africa, Caucasus and Central Asia (METAC).

He added that organizations should prioritize phishing-resistant authentication, strengthen visibility across their environments and detect unusual behavior before attackers can move further through networks.

Attackers exploit legitimate tools

Ransomware and pre-ransomware activity accounted for more than 20% of Talos Incident Response engagements during the quarter.

Cisco Talos observed ransomware operators using legitimate remote management tools in previously unreported ways. The approach helped them maintain persistent access while reducing the likelihood of detection.

For example, Sinobi ransomware operators used a trojanized MeshAgent binary as a primary command-and-control mechanism. This tactic had not previously been associated with the group in public reporting.

Similarly, Warlock ransomware operators were observed using the Zoho Assist Unattended Agent. The tool had not previously been publicly attributed to the group.

Using legitimate tools can make malicious activity harder to distinguish from normal enterprise operations. As a result, attackers may maintain access and move through environments without immediately triggering security alerts.

Healthcare remains most targeted

Healthcare was the most targeted industry in Talos Incident Response engagements for the second consecutive quarter. Public administration and manufacturing followed.

The findings highlight continued pressure on sectors that manage sensitive information and rely heavily on the availability of critical systems and services.

Strengthening defenses

Cisco Talos recommends adopting phishing-resistant multi-factor authentication, including hardware security keys, to strengthen defenses against identity attacks.

Organizations should also maintain centralized logging with at least 90 days of retention. This can improve investigation capabilities and visibility across environments.

In addition, organizations should prioritize rapid patching of internet-facing infrastructure and introduce outbound email thresholds to help limit the spread of phishing campaigns.

Overall, the latest findings show that identity attacks are becoming a growing concern as threat actors combine phishing, authentication abuse and legitimate enterprise tools to maintain access and evade detection.