Cisco Talos

29 stats2 reports

All Statistics

Phishing was the primary means of gaining initial access in over half of Cisco Talos Incident Response engagements this quarter, up from approximately one-third of engagements last quarter.

Cisco TalosIR Trends Q2 2026·2w ago
PhishingInitial Access

Authentication abuse was observed in 65% of Cisco Talos Incident Response engagements this quarter, up from 35% last quarter.

Cisco TalosIR Trends Q2 2026·2w ago
Authentication AbuseAuthentication

Ransomware incidents made up over 20% of Cisco Talos Incident Response engagements this quarter, similar to just under 20% last quarter.

Cisco TalosIR Trends Q2 2026·2w ago
RansomwareIncident Response

The ARToken panel exposed 80+ API endpoints for device code phishing, primary refresh token persistence, email access, BEC operations, and SharePoint exfiltration.

Cisco TalosIR Trends Q2 2026·2w ago
Phishing

Threat actors maintained undetected access for approximately three days before ransomware deployment in the observed Sinobi engagement.

Cisco TalosIR Trends Q2 2026·2w ago
RansomwarePersistenceIncident Response

Vulnerable, exposed, or unpatched internet-facing infrastructure was observed in 31% of engagements this quarter, compared to 25% last quarter.

Cisco TalosIR Trends Q2 2026·2w ago
Internet-Facing

Unlimited outbound email thresholds enabled threat actors to propagate malicious activity in almost 15% of Cisco Talos Incident Response engagements this quarter.

Cisco TalosIR Trends Q2 2026·2w ago
Email SecurityThreat Propagation

Healthcare accounted for 17% of all engagements, while public administration and manufacturing each accounted for 14% of engagements.

Cisco TalosIR Trends Q2 2026·2w ago
HealthcarePublic AdministrationManufacturing

Insufficient logging and visibility was observed in 42% of Cisco Talos Incident Response engagements this quarter, up from 18% last quarter.

Cisco TalosIR Trends Q2 2026·2w ago
LoggingVisibility

In 2025, 35% of Talos IR phishing cases involved internal phishing.

Cisco Talos2025 Year In Review·4mo ago
Internal Phishing

According to their data leak site, in 2025, Qilin targeted more than 40 victims every month except January.

Cisco Talos2025 Year In Review·4mo ago
RansomwareQilin

Device compromise attacks where attackers register their own hardware as a trusted factor, increased by 178%.

Cisco Talos2025 Year In Review·4mo ago
Device Compromise Attacks

Akira and Play, ranked as second and third most prolific ransomware groups, respectively.

Cisco Talos2025 Year In Review·4mo ago
RansomwareAkiraPlay

23% of CVEs directly impact network devices like VPN appliances, next-generation firewalls (NGFWs), load balancers, routers, and others.

Cisco Talos2025 Year In Review·4mo ago
CVEsNetwork Devices

25% of the top-targeted vulnerabilities impact widely used frameworks and libraries.

Cisco Talos2025 Year In Review·4mo ago
VulnerabilitiesFrameworksLibraries

32% of the top-targeted vulnerabilities are at least a decade old.

Cisco Talos2025 Year In Review·4mo ago
Vulnerabilities

The number of device registration events reported by users as fraud increased 178% from 2024 to 2025.

Cisco Talos2025 Year In Review·4mo ago
FraudFraudulent Device Registrations

Technology is the top-targeted industry at 36% for MFA spray attacks.

Cisco Talos2025 Year In Review·4mo ago
MFA Spray AttacksTechnology

In 2025, attackers compromised victims via phishing emails in 40% of Talos IR cases.

Cisco Talos2025 Year In Review·4mo ago
Phishing

Nearly 40% of the top-targeted vulnerabilities impacted end- of-life (EOL) devices.

Cisco Talos2025 Year In Review·4mo ago
VulnerabilitiesEOL Devices

60% of the top 20 terms appearing in phishing subject lines were the same in 2024 and 2025, such as “request,” “invoice,” “payment,” “email,” “fwd,” “message,” “report,” and “meeting.”

Cisco Talos2025 Year In Review·4mo ago
PhishingPhishing Subject Lines

Qilin was the most seen ransomware variant in 2025.

Cisco Talos2025 Year In Review·4mo ago
RansomwareQilin

The popularity of the other groups in last year’s top five fell significantly this year, with LockBit 3.0 moving from first to 35th, RansomHub from second to eighth, and Hunter’s International from fifth to 28th.

Cisco Talos2025 Year In Review·4mo ago
RansomwareLockBit 3.0RansomHubHunter's International

Qilin affiliates take home a significant portion of their ransom payments (up to 80 - 85%), higher than typical RaaS payout structures.

Cisco Talos2025 Year In Review·4mo ago
RansomwareQilinRaaS

In 2025, nearly a third of MFA spray attacks targeted identity and access management (IAM) applications.

Cisco Talos2025 Year In Review·4mo ago
MFA Spray AttacksIAM

The number of investigations Talos conducted into China-nexus campaigns increased nearly 75% this year compared to 2024.

Cisco Talos2025 Year In Review·4mo ago
China-nexus Campaigns

Application delivery controllers (ADCs) accounted for 22% of the top 50 targeted network devices.

Cisco Talos2025 Year In Review·4mo ago
Network DevicesApplication Delivery Controllers

The majority of the 50 most-targeted network infrastructure vulnerabilities (66%) affect device-specific firmware.

Cisco Talos2025 Year In Review·4mo ago
Network Infrastructure VulnerabilitiesDevice-Specific Firmware

January remains least active month for ransomware activity.

Cisco Talos2025 Year In Review·4mo ago
RansomwareJanuary