Key Findings
Phishing was the primary means of gaining initial access in over half of Cisco Talos Incident Response engagements this quarter, up from approximately one-third of engagements last quarter.
Authentication abuse was observed in 65% of Cisco Talos Incident Response engagements this quarter, up from 35% last quarter.
Ransomware incidents made up over 20% of Cisco Talos Incident Response engagements this quarter, similar to just under 20% last quarter.
The ARToken panel exposed 80+ API endpoints for device code phishing, primary refresh token persistence, email access, BEC operations, and SharePoint exfiltration.
Threat actors maintained undetected access for approximately three days before ransomware deployment in the observed Sinobi engagement.
Vulnerable, exposed, or unpatched internet-facing infrastructure was observed in 31% of engagements this quarter, compared to 25% last quarter.
Unlimited outbound email thresholds enabled threat actors to propagate malicious activity in almost 15% of Cisco Talos Incident Response engagements this quarter.
Healthcare accounted for 17% of all engagements, while public administration and manufacturing each accounted for 14% of engagements.
Insufficient logging and visibility was observed in 42% of Cisco Talos Incident Response engagements this quarter, up from 18% last quarter.