22 views
57 minutes ago

Attackers defeated MFA in 65% of the breaches Cisco Talos investigated last quarter

Fady Younes, Managing Director for Cybersecurity at Cisco
Fady Younes, Managing Director for Cybersecurity at Cisco

Authentication abuse featured in 65% of Cisco Talos Incident Response engagements in the second quarter of 2026, up from 35% in the previous quarter, according to the security firm’s latest quarterly Incident Response Trends report.

Phishing was the leading route into victim environments, accounting for more than half of engagements where an initial access vector could be established, against roughly a third in Q1. Many of those cases carried an MFA bypass component, including OAuth device-code phishing and adversary-in-the-middle frameworks used to intercept session tokens. Talos also recorded MFA fatigue attacks, attacker-registered devices enrolled for authentication, and legacy protocols that sidestep MFA altogether.

“Identity has become a critical battleground in cybersecurity as attackers increasingly look for ways to exploit legitimate credentials and trusted tools to gain access and remain undetected,” said Fady Younes, Managing Director for Cybersecurity, Cisco Middle East, Türkiye, Africa, Caucasus and Central Asia (METAC). “As organisations across the region accelerate digital transformation and adopt new technologies, protecting identities must remain a core part of their security strategy. Organisations should prioritise phishing-resistant authentication, strengthen visibility across their environments and focus on detecting unusual behaviour before attackers can move further through the network.”

QR codes and phishing-as-a-service

Talos tracked a QR code phishing campaign running from April into late June that primarily targeted Australian organisations. The operators, tracked as UAT-11764, used compromised Microsoft 365 accounts to generate victim-tailored PDF attachments carrying QR codes, which routed recipients to credential harvesting pages. Successful compromises were followed by inbox rule creation, malicious document staging on SharePoint and further internal and external phishing from the hijacked mailbox.

A separate engagement exposed ARToken, a phishing-as-a-service platform closely linked to EvilTokens. Its operator panel offers more than 80 API endpoints covering device code phishing, primary refresh token persistence, mailbox access, business email compromise and SharePoint exfiltration, all driven from a browser dashboard. The platform abuses the OAuth device authorisation flow to defeat MFA without ever capturing a password.

Ransomware operators weaponise RMM tools

Ransomware and pre-ransomware activity accounted for more than 20% of engagements, broadly level with just under 20% in Q1. Talos responded to Sinobi for the first time, alongside Nitrogen and Warlock.

In the Sinobi case, operators installed a trojanised MeshAgent binary as a SYSTEM-level auto-start service and used it as their primary command-and-control channel over encrypted WebSocket, a technique not previously attributed to the group in public reporting. The agent kept the intrusion hidden for roughly three days before encryption. Attackers then moved laterally over RDP and WinRM using a weak service account password cracked from the domain credential store, staged data for exfiltration with rclone, and pushed the ransomware domain-wide through a malicious Group Policy Object logon script.

Warlock operators, also tracked as Storm-2603, deployed an installer for Zoho Assist Unattended Agent, a tool built for administrative control of an endpoint with no user logged in. That engagement stopped short of encryption, though the activity matched a successful Warlock attack Talos handled in May.

Healthcare leads the target list again

Healthcare was the most targeted vertical for the second consecutive quarter at 17% of engagements, with public administration and manufacturing on 14% each. Most healthcare victims were organisations directly supporting clinical or diagnostic services, and almost all public administration victims were local governments.

Beyond authentication abuse, insufficient logging and visibility was the second most common security weakness at 42% of engagements, up from 18% in Q1, with short retention windows repeatedly preventing investigators from establishing the initial access vector or the scope of data theft. Exposed or unpatched internet-facing infrastructure featured in 31% of engagements, including ToolShell, an older Telerik UI deserialisation flaw and SD-WAN and VPN appliance vulnerabilities.

Unlimited outbound email thresholds helped attackers spread in almost 15% of engagements. In one case, a compromised mailbox pushed out more than 6,600 phishing and spam messages shortly after the credentials were stolen.

Talos recommends moving to phishing-resistant MFA such as FIDO2 and WebAuthn or hardware keys, restricting self-service MFA enrolment behind helpdesk verification, blocking legacy authentication through Conditional Access, running centralised logging with a minimum of 90 days of retention held off-device, patching or decommissioning exposed and end-of-life systems, and enforcing outbound email rate limits.

Leave a Reply

Don't Miss

Cisco introduces Antares small language models for secure code scanning.

Cisco launches Antares AI models to detect software vulnerabilities

Cisco has unveiled Antares, a family of small language models designed to
Cisco sets three principles for operationalising AI in the enterprise

Cisco warns enterprises are bolting AI onto unsuitable legacy systems

Cisco has urged organisations to stop layering AI onto legacy systems, revealing

Welcome to

By signing or creating an account you agree with our Code of conduct & Privacy policy