Phishing isn’t new and has been around for almost longer than most of us can remember. Most of us have been warned about suspicious emails for years, companies run regular security training and multi-factor authentication is now fairly common, but Cisco Talos’ latest incident-response data shows that attackers are still having a lot of success getting people to hand over access to their accounts.
According to the Cisco Talos Q2 2026 Incident Response Trends report, phishing accounted for more than half of the incidents Talos responded to during the second quarter of 2026. That’s up from 35% in the previous quarter. Authentication abuse increased just as sharply and appeared in 65% of engagements, almost doubling quarter on quarter.
The obvious problem is that a stolen login doesn’t necessarily look like an attack. If someone has the right username, password and whatever else they need to get past authentication, they can access the same email, cloud services and company systems as the person whose account they’ve taken over. From there, it becomes much harder to tell that something is wrong.
This is one of the reasons identity has become such an important part of cybersecurity. Companies have spent years improving the security around their networks and devices, while more of the things employees use every day have moved online. Email, cloud storage, business applications and remote-working tools all depend on accounts and permissions. Get access to the right account and an attacker may already have access to quite a lot.
Cisco’s Fady Younes, Managing Director for Cybersecurity across the Middle East, Türkiye, Africa, Caucasus and Central Asia, describes identity as “the new security battleground”.
“Attackers are weaponising legitimate credentials and trusted tools to infiltrate networks and operate undetected,” he says.
It’s strong wording, but authentication abuse showing up in 65% of Talos’ incident-response engagements gives some idea of why Cisco is placing so much emphasis on it.
Attackers are using legitimate tools too
Ransomware and pre-ransomware activity accounted for more than 20% of Talos’ engagements during the quarter, and some ransomware operators were using remote-management software that also has perfectly legitimate uses.
Sinobi ransomware operators were seen using a trojanised MeshAgent binary as a command-and-control mechanism, something Talos says hadn’t previously been publicly associated with the group. Warlock ransomware operators were also using the Zoho Assist Unattended Agent, another tool that hadn’t previously been publicly linked to that group.
It becomes harder to spot when attackers start using the same tools the company already uses. Remote-management software isn’t suspicious simply because it’s installed on a computer. An IT team may use it every day to manage machines, troubleshoot problems or help someone working from home.
Security teams therefore need to know more than whether a particular piece of software is present. Who is using it, when are they using it and what are they doing with it? A remote connection from somebody in the IT department during working hours might be completely normal. The same account behaving differently from the way it usually does may need a closer look. The software hasn’t suddenly become malicious. The person using it may be the problem.
MFA helps, but not all MFA is the same
Talos recommends phishing-resistant multi-factor authentication, including hardware security keys, as one of the ways companies can make stolen credentials less useful. It also recommends centralised logging with at least 90 days of retention, rapid patching of internet-facing infrastructure and outbound email thresholds that can help limit phishing campaigns.
Multi-factor authentication has become fairly common, but switching it on doesn’t automatically mean an account is secure. There are different ways of doing MFA and some are more difficult for an attacker to get around than others.
A hardware security key, for example, gives an attacker another problem to solve because knowing the password alone isn’t enough. That doesn’t mean every company needs to replace its existing authentication system immediately, but it does mean there’s more to MFA than whether the box has been ticked.
Logging is similarly unexciting until somebody needs it. If a company discovers that an account or machine has been compromised, security teams need enough historical information to work out when the attacker arrived, what they accessed and what they did afterwards. Talos recommends keeping centralised logs for at least 90 days for exactly that reason.
Cisco has previously raised similar questions about South African cybersecurity readiness. The Talos incident-response figures aren’t broken down by country, so they can’t tell us how often these particular attacks are happening in South Africa. They do, however, describe attacks against the same types of accounts, cloud services and remote-access systems used by businesses here.
Healthcare remains the biggest target
Healthcare was the most targeted sector in Talos’ incident-response engagements for the second consecutive quarter, followed by public administration and manufacturing.
It’s not difficult to understand why those organisations are attractive targets. A hospital can’t simply stop treating patients while its systems are being investigated. Public-sector organisations still have services to provide and manufacturers can lose money very quickly when production stops. Those organisations also tend to hold a lot of information that people would prefer not to have stolen.
Younes says identity protection should become a bigger priority as African organisations adopt more cloud and AI services. More cloud services generally mean more accounts and more places where somebody needs to prove that they’re actually the person they claim to be.
Phishing has changed a lot from the badly written emails most of us were taught to look out for. Attackers can steal legitimate credentials and then use software that was never designed to be malicious in the first place.
The method has become more sophisticated, but the basic idea hasn’t really changed much. Convince the right person to give you access and you may not have to break in at all.

