Report by Google Cloud

Cloud Threat Horizons Report H1 2026

17 FINDINGSPublished Mar 10, 2026
View Original Report →

Key Findings

21% of cybersecurity intrusions investigated involved compromised trusted relationships with third-parties.

Third Party Risk

10% of intrusions investigated involved Business Email Compromise (BEC), with actors targeting banking details for wire and deposit fraud.

BEC

Threat actors exploited identity issues to gain initial access in 83% of the incidents involving major cloud and SaaS-hosted environments.

Identity Initial AccessCloud SaaS

Threat actors targeted data in 73% of cloud-related incidents.

DataCloud Attack

Initial access by threat actors using misconfiguration, which accounted for 29.4% of incidents in the first half of 2025, dropped to 21% in H2 2025.

Initial AccessMisconfiguration

RCE increased nearly five-fold from 2.9% in H1 to 13.6% in H2

RCE

Software supply chain compromises accounted for 3% of cybersecurity intrusions investigated.

Software Supply Chain

45% of intrusions resulted in data theft without immediate extortion attempts at the time of the engagement

Data Theft

2% of cybersecurity intrusions investigated involved vulnerability exploitation.

Vulnerability Exploitation

Exposed sensitive UI or APIs fell from 11.8% in H1 to 4.9% in H2.

Exposed Sensitive UIExposed APIs

28% of intrusions investigated resulted in data theft that bore indications of extortion.

Data TheftExtortion

Threat actors exploited third-party software-based entry (44.5%) more frequently than weak credentials—a significant increase from the 2.9% observed in H1 2025.

Third Party RiskCredentials

21% of cybersecurity intrusions investigated involved actors leveraging stolen human and non-human identities for initial access.

Identity

7% of cybersecurity intrusions investigated resulted from actors gaining access through improperly configured application and infrastructure assets.

Misconfiguration

When malicious insiders used personally controlled cloud services to exfiltrate data, 12% of those malicious insiders used multiple cloud storage services, including Google Drive, Dropbox, Microsoft OneDrive, and Apple iCloud.

CloudCloud Storage Services

17% of phishing cases involved voice-based social engineering (vishing).

PhishingVishingInitial Access

In 35% of cases where data exfiltration occurred, the malicious insider absconded with data through multiple paths such as a combination of email and cloud or USB storage device and cloud.

Data Exfiltration