Middle East Sees Surge in Identity-Based Cyber Threats
Cisco's Talos cybersecurity division released its Incident Response Trends report for Q2 2026, highlighting growing identity-based threats in the Middle East and Africa region. Phishing accounted for more than half of all incident response engagements during this period, while authentication abuse was observed in 65% of cases.
The increase in phishing attacks is a significant concern, as it can allow attackers to gain access to enterprise environments and evade traditional security controls. To combat this threat, Cisco recommends that organizations adopt phishing-resistant multi-factor authentication methods, such as hardware security keys.
Ransomware operators are also increasingly using legitimate remote management tools to maintain persistent access and reduce the likelihood of detection. The Sinobi ransomware group was observed using a trojanized MeshAgent binary as a primary command-and-control mechanism, while Warlock ransomware operators used the Zoho Assist Unattended Agent.
The healthcare sector remains the most targeted industry in Talos Incident Response engagements for the second consecutive quarter. Cisco emphasizes the importance of strengthening defenses against identity-based attacks by adopting robust security measures and maintaining centralized logging with at least 90 days of retention to support investigation and visibility.