Report: Phishing Remains the Primary Initial Access Vector
KnowBe4, Tuesday, August 25th, 2026
KnowBe4 relays Cisco Talos data showing phishing accounted for over half of attacks observed in Q2 2026.
Phishing remains the top initial access vector, accounting for more than half of the cyberattacks Cisco Talos observed during the second quarter of 2026.
The report notes spikes in specific techniques, including QR codes embedded in PDF attachments, which move the malicious destination out of scannable text and into an image the recipient photographs with a personal device.
Talos also recorded increased use of MFA bypass techniques such as adversary-in-the-middle proxies, which relay the authentication in real time so a valid second factor does not protect the account.