logo

Phishing and MFA exploitation: Targeting the keys to the kingdom

ID: 2a6b7714-d005-5bd7-968c-cb4a2695c6b2

STIX ID: report--2a6b7714-d005-5bd7-968c-cb4a2695c6b2

Feed Name: Cisco Talos

Threat Score
70/100

Date Published: 2026-04-21

Date Updated: 2026-04-27

Author: Kri Dontje

...
...

In 2025 attackers exploited trust-based workflows: phishing (used for initial access in ~40% of incidents), cascaded phishing from compromised/trusted accounts, abuse of Microsoft 365 Direct Send to spoof internal email, and MFA-focused attacks (MFA spray and a 178% rise in device compromise) targeted IAM and sectors like higher education; the report outlines these trends and recommends mitigations such as stricter SPF/DMARC, rejecting Direct Send, lockout policies, device hardening, and phishing-resistant MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.