Report by Cisco Talos

IR Trends Q2 2026

9 FINDINGSPublished Jul 28, 2026
View Original Report →

Key Findings

Phishing was the primary means of gaining initial access in over half of Cisco Talos Incident Response engagements this quarter, up from approximately one-third of engagements last quarter.

Cisco TalosIR Trends Q2 2026·2w ago
PhishingInitial Access

Authentication abuse was observed in 65% of Cisco Talos Incident Response engagements this quarter, up from 35% last quarter.

Cisco TalosIR Trends Q2 2026·2w ago
Authentication AbuseAuthentication

Ransomware incidents made up over 20% of Cisco Talos Incident Response engagements this quarter, similar to just under 20% last quarter.

Cisco TalosIR Trends Q2 2026·2w ago
RansomwareIncident Response

The ARToken panel exposed 80+ API endpoints for device code phishing, primary refresh token persistence, email access, BEC operations, and SharePoint exfiltration.

Cisco TalosIR Trends Q2 2026·2w ago
Phishing

Threat actors maintained undetected access for approximately three days before ransomware deployment in the observed Sinobi engagement.

Cisco TalosIR Trends Q2 2026·2w ago
RansomwarePersistenceIncident Response

Vulnerable, exposed, or unpatched internet-facing infrastructure was observed in 31% of engagements this quarter, compared to 25% last quarter.

Cisco TalosIR Trends Q2 2026·2w ago
Internet-Facing

Unlimited outbound email thresholds enabled threat actors to propagate malicious activity in almost 15% of Cisco Talos Incident Response engagements this quarter.

Cisco TalosIR Trends Q2 2026·2w ago
Email SecurityThreat Propagation

Healthcare accounted for 17% of all engagements, while public administration and manufacturing each accounted for 14% of engagements.

Cisco TalosIR Trends Q2 2026·2w ago
HealthcarePublic AdministrationManufacturing

Insufficient logging and visibility was observed in 42% of Cisco Talos Incident Response engagements this quarter, up from 18% last quarter.

Cisco TalosIR Trends Q2 2026·2w ago
LoggingVisibility