Cisco Talos reported a significant increase in identity-based attacks during the second quarter of 2026, noting that threat actors increasingly targeted credentials and access tools. According to the latest Incident Response Trends report, authentication abuse appeared in 65% of all analyzed response engagements, nearly doubling from the previous quarter.

Phishing served as the initial access vector in over 50% of response cases, up from 35% in the first quarter. This shift demonstrates how attackers avoid conventional perimeter defenses by exploiting legitimate user credentials to access corporate networks.

“Identity has become a critical battleground in cybersecurity as attackers increasingly look for ways to exploit legitimate credentials and trusted tools to gain access and remain undetected.”

Fady Younes, Managing Director for Cybersecurity, Cisco METAC

Surge in Identity-Based Attacks

The growth of identity-based attacks highlights a broader operational change among threat groups operating across corporate environments. Specifically, unauthorized actors focus on stealing verified login data to bypass multi-stage detection systems.

Furthermore, Younes stated that regional organizations advancing digital transformation must make identity protection a central element of defense plans. He advised teams to establish phishing-resistant controls and improve network-wide activity monitoring.

Exploitation of Remote Management Tools

Ransomware and pre-ransomware operations accounted for more than 20% of incident response cases during the quarter. Cisco Talos observed attackers utilizing legitimate remote management apps in previously undocumented patterns to maintain persistent access without triggering alerts.

For instance, Sinobi ransomware operators deployed a modified MeshAgent binary as their primary command-and-control mechanism. Additionally, Warlock ransomware groups used the Zoho Assist Unattended Agent, marking the first public documentation of this specific utility being used by that group.

Targeted Sectors in Q2 2026

The health-tech and medical industry remained the most targeted sector for the second consecutive quarter. Public administration ranked second, followed closely by manufacturing organizations.

Consequently, critical sectors that manage sensitive customer records face ongoing operational pressure. These organizations rely heavily on high uptime, making service interruptions particularly disruptive.

Recommended Defensive Measures

To mitigate the risks of identity-based attacks, Cisco Talos recommended deploying hardware security keys and phishing-resistant multi-factor authentication across all critical systems. Organizations should also enforce outbound email transmission limits to restrict active phishing campaigns.

Finally, security teams should maintain centralized system logging with a minimum retention period of 90 days. Rapid patching of all internet-facing systems remains essential to protect networks against unauthorized intrusions.