As cybercriminals refine their methods of gaining access to enterprise environments, organizations are increasingly paying attention to identity-based and phishing attacks. This trend is one of the key conclusions of the Q2 2026 Incident Response Trends report, prepared by Talos, Cisco’s threat intelligence division.

Phishing continues to be the main access route, representing more than 50% of incidents, compared to the 35% observed in the previous quarter. This increase confirms the role that phishing plays in campaigns directed against companies. At the same time, the abuse of authentication credentials has skyrocketed to 65% during this period, demonstrating the growing exploitation of identity as a gateway.

“Attackers are turning cybercrime into a low-cost, high-volume business by treating identity-based attacks as a repeatable model that they can automate,” highlights Ángel Ortiz, Director of Cybersecurity at Cisco Spain. “Multi-factor authentication and administrative tools are being used as camouflage to hide malicious activity, allowing attackers to blend in with the noise of daily operations. We need to remove that cover by moving from static defenses to behavior-based visibility, exposing these threats before they move laterally through the enterprise. Organizations must adopt phishing-resistant authentication to deprive attackers of that initial entry point.”

Ransomware authors turn to legitimate tools

Ransomware and ‘pre-ransomware’ related activities accounted for more than 20% of incidents recorded during the second quarter. The Talos incident response (IR) team observed that threat actors have adopted new tactics not previously described to maintain persistent and stealthy access.

As an example, the operators of the Sinobi ransomware have used a trojanized MeshAgent binary as their primary command and control mechanism, a tactic that has not previously been associated with the group in public reports. Likewise, the Warlock ransomware operators have relied on ‘Zoho Assist Unattended Agent’, a tool that had not previously been attributed to them.

By using these trusted binaries, attackers can maintain access that often bypasses standard security alerts, allowing them to move laterally and prepare for encryption without triggering alarms. Although phishing continues to be one of the main entry doors, these tactics demonstrate how cybercriminals combine different techniques once initial access is gained.

The health sector and the public sector, under pressure

For the second consecutive quarter, the healthcare sector was the most attacked, followed closely by public administration and the manufacturing industry. These sectors continue to be a high-value target due to their critical dependence on uptime and the sensitive nature of the data they manage.

The nature of these campaigns, including QR code phishing operations, known as ‘quishing’, underscores the need to adopt a more proactive security strategy. This type of phishing allows attackers to use QR codes to direct victims to fraudulent pages designed to steal credentials or sensitive information.

Resilience is key to facing these constantly evolving threats. Therefore, it is recommended to implement phishing-resistant multi-factor authentication, such as hardware security keys, and adopt a centralized registry that is retained for at least 90 days to improve forensic visibility.

Additionally, security teams should prioritize quickly patching Internet-connected infrastructure and implementing limits on outgoing email to effectively limit the spread of potential phishing campaigns. Strengthening protection against phishing should be part of a comprehensive strategy that combines phishing-resistant authentication, behavioral monitoring, and increased detection and response capabilities.