Yes. Cisco Talos reported on July 28 that phishing was the way in for over half of the incidents its responders handled in the second quarter of 2026, up from about a third. IBM's 2026 breach study, out a day later, still ranks phishing first. The fix is layered: enforce DMARC, adopt phishing-resistant MFA, and train staff.
Key takeaways
- Cisco Talos: phishing was the initial access vector in over half of its Q2 2026 incident response engagements, up from about a third the quarter before.
- Talos saw "authentication abuse" in 65% of engagements, up from 35%, with attackers often getting around multi-factor authentication (MFA).
- IBM's Cost of a Data Breach Report 2026 found that one in four malicious breaches was AI-enabled, at about $6 million on average, and that phishing remained the most common way breaches began.
- DMARC at enforcement lets receiving servers block criminals forging your exact domain. It can't stop phishing sent from a hacked real mailbox or a lookalike domain, which is why MFA and training still matter.
What happened?
Talos: phishing opened more than half of incident cases
Cisco Talos, Cisco's threat intelligence and incident response team, published its quarterly incident response trends report on July 28, 2026. According to Talos, phishing was the primary way attackers gained initial access in over half of its incident response engagements in the second quarter, compared with approximately a third in the first quarter.
Talos says attackers kept changing how they deliver their lures to get past defenses:
- QR codes inside PDFs, which Talos says were used to bypass traditional email gateways.
- Links hosted on trusted cloud platforms, so the first click lands somewhere that looks legitimate.
- Spreading from the inside. One persistent QR code campaign, aimed mainly at Australian organizations, sent victim-tailored PDFs from compromised Microsoft 365 accounts and then moved through the victims' internal contact lists.
Healthcare was the most-targeted sector at 17% of engagements, followed by public administration and manufacturing at 14% each. Ransomware made up over 20% of engagements, according to Talos.
Authentication abuse nearly doubled
Talos observed authentication abuse in 65% of engagements, compared with 35% the previous quarter. It says attackers frequently bypassed or defeated MFA using adversary-in-the-middle (AiTM) proxies, session-token theft, MFA fatigue attacks and self-enrolled devices, among other methods.
In plain English, attackers aren't stopping at passwords. They capture a working sign-in session, wear people down with repeated prompts, or register their own device as a second factor.
IBM: phishing is still the most common starting point
IBM released its Cost of a Data Breach Report 2026 on July 29. According to IBM, the study was conducted by the Ponemon Institute and covers breaches at 602 organizations between March 2025 and February 2026.
IBM's headline finding: one in four malicious breaches was AI-enabled, and those breaches cost about $6 million on average. IBM says these AI-enabled attacks were mostly deepfake impersonation and AI-enabled malware. Phishing remained the most common initial attack vector.
We have left out the per-vector cost figures quoted in some early coverage, because we could not check them against the full report.
Why does this matter for your business?
Talos draws on incidents its own responders worked; IBM on a large annual study. Both put phishing first. Three lessons follow for a small or mid-sized business.
1. Email authentication blocks one kind of phishing, not all of it. SPF, DKIM and DMARC let receiving mail servers check whether a message using your domain in the From address really came from a server or signing key you authorized. With DMARC at p=reject, receiving servers can reject messages that forge your exact domain, so criminals can't easily use it to fool your customers, vendors or staff. But the Talos QR campaign came from compromised Microsoft 365 accounts: real mailboxes sending genuinely authenticated mail. DMARC can't flag that, and it doesn't cover lookalike domains either. We looked at that gap last week in our breakdown of Microsoft's Q2 2026 email threat report.
2. MFA is essential, but attackers now plan for it. A 65% authentication-abuse rate means a one-time code alone is no longer the finish line. Microsoft describes passkeys as "phishing-resistant by design" because they use public-key cryptography rather than shared secrets, and on July 13 it announced that passkeys are becoming the default authentication method in Entra ID. Our guide to the Entra ID passkey change covers the dates.
3. "It sounded like the boss" is no longer proof. IBM's finding that AI-enabled attacks were mostly deepfake impersonation and AI-enabled malware is a reminder to verify requests for money or data through a second channel, however convincing the voice, video or email.
Which defense covers which trick?
| Technique in the July reports | Does DMARC at p=reject help? | What else you need |
|---|---|---|
| Email forging your exact domain | Yes, receivers can reject it | SPF and DKIM covering every service that sends for you |
| Phishing from a hacked real mailbox (the Talos QR campaign) | No, the mail is genuinely authenticated | Phishing-resistant MFA, sign-in alerts, a culture of reporting |
| Lookalike domain | No, it's a different domain | Lookalike monitoring, external-sender tags, call-back rules |
| AiTM proxy or session-token theft | No | Phishing-resistant MFA such as passkeys |
| MFA fatigue (repeated prompts) | No | Phishing-resistant MFA; teach staff to deny and report prompts they didn't start |
| QR code inside a PDF | Only if the sender forged your domain | Treat QR codes as links; report unexpected attachments |
What should you do now?
- Check your domain's DMARC policy. Run your domain through our free email security scanner. If DMARC is missing or stuck at
p=none, plan the move toquarantineand thenrejectonce your legitimate senders pass. - Put phishing-resistant MFA on the accounts that matter most. Start with administrators, finance staff and anyone who approves payments, then roll it out to everyone.
- Review MFA registrations. Talos names self-enrolled devices as one bypass method. Look for sign-in methods or devices your staff don't recognize and remove any you can't account for.
- Teach "a QR code is a link." Talos saw QR codes in PDFs used to slip past email gateways. Staff should treat an unexpected QR code exactly like an unexpected link.
- Be wary of internal requests, too. The Talos QR campaign spread through victims' own contact lists, so an unexpected "please review this PDF" from a colleague deserves a quick check.
- Keep a call-back rule for money. Confirm any payment request or bank-detail change by phone, using a number you already have on file.
Frequently asked questions
Is phishing really the most common way breaches start in 2026?
Two separate July 2026 reports say yes. Cisco Talos found phishing was the initial access vector in over half of its second-quarter incident response engagements, and IBM's Cost of a Data Breach Report 2026 again put phishing at the top as the most common initial attack vector.
What is "authentication abuse"?
It's the term Talos uses for attackers abusing sign-in and authentication systems, often by getting past MFA instead of stopping at a stolen password. Talos lists adversary-in-the-middle proxies, session-token theft, MFA fatigue attacks and self-enrolled devices among the bypass methods. It showed up in 65% of Talos's Q2 2026 engagements, up from 35% the quarter before.
Does DMARC stop phishing?
DMARC stops one important kind: email that forges your exact domain in the From address, once your policy is set to quarantine or reject. It doesn't stop phishing sent from a hijacked real account, which passes authentication, or from lookalike domains the attacker owns. Use it alongside phishing-resistant MFA, staff training and a firm rule for verifying payment requests.
Are these numbers relevant to a small business?
Treat them as a direction, not a price tag. Talos's figures come from incidents its own responders handled, and IBM's study covers 602 organizations. Neither report focuses on small businesses, but both show attackers favoring the inbox and targeting sign-ins, and that applies to a ten-person office as much as to a large enterprise.
Sources
- Cisco Talos — IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains (July 28, 2026)
- IBM Newsroom — IBM Study: One in Four Malicious Breaches Are AI-Enabled, Costing Companies $6 Million on Average (July 29, 2026)
- Microsoft Security Blog — Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID (July 13, 2026)
- Security Ledger — Talos: Attackers Refine Phishing Playbook To Target Critical Infrastructure (July 2026)
- Microsoft Learn — Email authentication in cloud organizations (reference documentation, undated)
- Microsoft Learn — Set up DMARC to validate the From address domain for cloud senders (reference documentation, undated)
Editor's note: This article was researched and written with AI assistance. Every factual claim was checked against the sources listed above; see our fact-check process for details.
Related Topics
Ready to Secure Your Email?
Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.