# Why this matters Phishing was the primary initial access vector in more than half of Cisco Talos Incident Response engagements during Q2 2026. At the same time, attackers increased their focus on authentication abuse, which Talos observed in 65% of engagements — nearly double the previous quarter. For defenders, that means attacks are combining improved delivery tricks with targeted techniques to defeat multifactor protections.
- Authentication abuse rose to 65% of engagements, compared with 35% last quarter.
# How attackers are changing delivery Attackers are altering how they deliver phishing to evade conventional email defenses:
- QR code–embedded PDFs: Auto-generated, victim-tailored PDFs containing QR codes direct targets to adversary-controlled Microsoft 365 credential harvesters. These PDFs can bypass gateways that focus on scanning attachments and links.
- Trusted cloud hosting: Links and pages hosted on reputable cloud platforms are used as intermediaries to appear legitimate to users and some automated checks.
A highlighted campaign targeted Australian organizations: compromised Microsoft 365 accounts were used to harvest credentials and propagate phishing through internal contact lists. When credentials were captured, attackers performed post-compromise actions like creating inbox rules, hosting malicious files on SharePoint, and sending internal phishing to expand access.
# How multifactor protections are being bypassed Talos documents multiple methods attackers used to bypass or defeat MFA:
- Adversary-in-the-middle (AitM) proxies and session-token theft that capture authentication tokens rather than passwords.
- MFA fatigue attacks that bombard users with approval prompts until they accept one.
- Self-enrolled devices or attacker-controlled device registration added as legitimate authenticators.
- Continued reliance on legacy authentication protocols that bypass MFA mechanisms.
# Fast, phone-driven malware installs (WindRelay example) Group-IB observed vishing campaigns that install a new Android RAT called WindRelay. Attackers impersonated bank staff, convinced victims to install a malicious app, and completed full fraud in a single live call. In one documented case, a 13-minute call ended with the fraudster using remote access to take out a loan and stream card data via a fake terminal. The attack chain relied on social pressure, urgency, and instructing the victim to enter PINs or approve actions themselves.
# Concrete next steps for defenders
- Treat phishing and authentication abuse as connected risks: strengthen both email/web filtering and identity protections.
- Reduce attack surface for token theft: enforce modern authentication protocols, remove legacy authentication, and block self-enrollment paths for MFA without administrative oversight.
- Harden user workflows against social engineering: use conditional access policies that require device compliance and contextual checks before granting high-value access.
- Monitor for post-compromise behaviors: mailbox rules, unexpected SharePoint activity, and internal message spikes can indicate lateral propagation.
- Train incident response teams for QR-code and cloud-hosted phishing chains so they can quickly trace redirect paths and revoke compromised sessions.
# Bottom line Phishing remains the dominant entry point, and attackers now combine evasive delivery with multiple MFA-bypass techniques. Defenders should assume credential theft alone is not the end state — attackers will attempt token capture, device enrollment, and internal propagation. Addressing identity controls and post-compromise detection will reduce the likelihood that a single click becomes a broad breach.