Phishing now starts most intrusions as attackers beat MFA

Phishing has gone from one route into corporate networks to the dominant one. Cisco Talos Incident Response says phishing was the initial access vector in more than half of the intrusions it handled in the second quarter of 2026, up from roughly a third the quarter before, and that attackers defeated or sidestepped multi-factor authentication in 65 percent of engagements, nearly double the previous quarter 35 percent.

That second figure is the one worth staring at. MFA is the control most organizations rely on to make a stolen password worthless, and Talos IR watched it fall routinely. The methods were adversary-in-the-middle proxies, which sit between the user and the real login page and steal the session token after a legitimate sign-in, outright session token theft, MFA fatigue attacks that spam a user with push prompts until one gets approved, and attackers enrolling their own devices as a second factor.

QR codes in PDFs, and a campaign aimed at Australia

Delivery is adapting around email security rather than fighting it. Talos saw attackers embedding QR codes inside PDF attachments, which moves the malicious link out of scannable text and onto the victim personal phone, and hosting landing pages on trusted cloud platforms that gateways are reluctant to block.

Since April, Talos has tracked a persistent QR phishing campaign hitting mainly Australian organizations, run by an actor it designates UAT-11764. The operation uses already-compromised Microsoft 365 accounts to generate victim-tailored PDFs, harvests credentials through fake M365 login pages, then works through each newly captured mailbox contact list to push the campaign further inside and outward. After compromise the actor creates inbox rules to hide its activity and stages malicious documents on SharePoint. Talos assesses with high confidence that the campaign will continue. Defenders can see the wider country picture on our Australia threat profile.

The team also pulled apart a phishing-as-a-service platform called ARToken, closely linked to the earlier EvilTokens platform. It gives affiliates a dashboard exposing more than 80 API endpoints covering device code phishing, persistence through primary refresh tokens, mailbox access, business email compromise and SharePoint exfiltration. It bypasses MFA by abusing the Microsoft OAuth device authorization flow rather than by stealing passwords at all.

Ransomware crews hide inside remote support tools

Ransomware and pre-ransomware activity accounted for more than 20 percent of engagements. Talos IR responded to Sinobi ransomware for the first time, alongside returning names Nitrogen and Warlock, and in each case the operators leaned on legitimate remote monitoring and management software instead of custom backdoors.

In the Sinobi engagement the actor installed a trojanized MeshAgent binary, the open-source agent from the MeshCentral remote management suite, as a SYSTEM-level auto-start service talking to an attacker server over encrypted WebSocket. That let its traffic blend into normal administrative activity and it sat undetected for roughly three days. The actor then moved laterally over RDP and WinRM using a service account whose weak password it cracked from the domain credential store, staged data for exfiltration with rclone, and finally pushed the encryptor across the whole domain through a malicious Group Policy logon script. Warlock operators, also tracked as Storm-2603, were seen deploying the Zoho Assist unattended agent, which grants remote control of a machine with nobody logged in.

Who is getting hit, and what to fix

Health care was the most targeted sector for the second quarter running at 17 percent of engagements, with public administration and manufacturing behind it at 14 percent each. The common thread is a low tolerance for downtime, which is exactly the leverage extortion depends on. Talos also found insufficient logging in 42 percent of engagements, up from 18 percent, including domain controller logs kept for only hours and cloud telemetry that did not reach back far enough to identify how the attacker first got in.

The fixes follow directly: move to phishing-resistant MFA such as FIDO2 or hardware keys, require helpdesk verification for MFA enrollment, block legacy authentication, keep at least 90 days of centralized logs forwarded off-device so they survive tampering, and hunt for unauthorized remote management agents rather than trusting signature detection. Attackers reaching staff through everyday business tools is now routine, as the recent wave of fake IT support calls over Microsoft Teams showed. The full quarterly report, written by Lexi DiScola, is on the Talos blog.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions