logo

Report: Phishing Remains the Primary Initial Access Vector

ID: 8cedc361-f41a-58be-93cb-7545f2f17e56

STIX ID: report--8cedc361-f41a-58be-93cb-7545f2f17e56

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: KnowBe4 Team

...
...

Cisco Talos reports that phishing was the dominant initial access vector in Q2 2026, appearing in over half of Incident Response engagements, with a notable QR-code-based phishing campaign targeting Australian organizations to harvest Microsoft 365 credentials; attackers leveraged compromised accounts to propagate the campaign and performed post-compromise actions such as creating inbox rules and hosting malicious content on SharePoint. The report also documents a sharp rise in authentication abuse (observed in 65% of engagements), with adversaries bypassing MFA via adversary-in-the-middle proxies, session-token theft, MFA fatigue, and attacker-enrolled devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.