Identity-Based Attacks Surge as Phishing and Authentication Abuse Rise
The latest Incident Response Trends report from Cisco Talos reveals a significant shift in cyberattack tactics. Phishing accounted for more than half of cybersecurity incident response engagements in Q2 2026, while authentication abuse was observed in 65% of engagements. This surge in identity-based attacks has led to an increase in the use of legitimate tools by attackers, making malicious activity harder to distinguish from normal enterprise operations.
Cisco Talos warns that healthcare remains the most targeted sector, followed closely by public administration and manufacturing. To strengthen their security posture, organisations are urged to adopt phishing-resistant multi-factor authentication methods, maintain centralised logging with at least 90 days of retention, prioritise rapid patching of internet-facing infrastructure, and introduce outbound email thresholds.
Fady Younes, MD for cybersecurity at Cisco Middle East, Türkiye, Africa, Caucasus and Central Asia (METAC), notes that 'identity has become the new security battleground' and that attackers are 'weaponizing legitimate credentials and trusted tools to infiltrate networks and operate undetected'. He stresses that organisations must adopt phishing-resistant authentication, gain visibility across all environments, and detect suspicious behaviour before attackers advance through their network.