Report by Google Cloud
Cloud Threat Horizons Report H1 2026
Key Findings
21% of cybersecurity intrusions investigated involved compromised trusted relationships with third-parties.
10% of intrusions investigated involved Business Email Compromise (BEC), with actors targeting banking details for wire and deposit fraud.
Threat actors exploited identity issues to gain initial access in 83% of the incidents involving major cloud and SaaS-hosted environments.
Threat actors targeted data in 73% of cloud-related incidents.
Initial access by threat actors using misconfiguration, which accounted for 29.4% of incidents in the first half of 2025, dropped to 21% in H2 2025.
RCE increased nearly five-fold from 2.9% in H1 to 13.6% in H2
Software supply chain compromises accounted for 3% of cybersecurity intrusions investigated.
45% of intrusions resulted in data theft without immediate extortion attempts at the time of the engagement
2% of cybersecurity intrusions investigated involved vulnerability exploitation.
Exposed sensitive UI or APIs fell from 11.8% in H1 to 4.9% in H2.
28% of intrusions investigated resulted in data theft that bore indications of extortion.
Threat actors exploited third-party software-based entry (44.5%) more frequently than weak credentials—a significant increase from the 2.9% observed in H1 2025.
21% of cybersecurity intrusions investigated involved actors leveraging stolen human and non-human identities for initial access.
7% of cybersecurity intrusions investigated resulted from actors gaining access through improperly configured application and infrastructure assets.
When malicious insiders used personally controlled cloud services to exfiltrate data, 12% of those malicious insiders used multiple cloud storage services, including Google Drive, Dropbox, Microsoft OneDrive, and Apple iCloud.
17% of phishing cases involved voice-based social engineering (vishing).
In 35% of cases where data exfiltration occurred, the malicious insider absconded with data through multiple paths such as a combination of email and cloud or USB storage device and cloud.