Phishing Attacks Surge as Primary Cyber-Attack Entry Method, Exploiting New Evasion Techniques
Phishing attacks have become the dominant method for initial entry in cyber incidents, as reported by Cisco Talos in their Incident Response Trends report for March to June 2026. The report highlights that phishing accounted for over half of the incidents investigated, marking a significant increase from the previous quarter. Attackers are employing innovative tools and techniques to evade detection, such as QR code phishing campaigns that target organizations to harvest login credentials. These campaigns use auto-generated, victim-tailored PDF documents containing QR codes that lead to adversary-controlled Microsoft 365 credential harvesting pages. The threat actor, identified as UAT-11764, uses methods to bypass traditional email gateway detections and host credential harvesting pages on trusted cloud platforms. Post-compromise actions include creating email inbox rules for defense evasion and using compromised accounts to send further phishing emails.