Key Takeaways
- LevelBlue observed identity abuse at the center of most Q2 2026 incidents, including a 100% MFA bypass rate in BEC cases
- Software supply chain attacks expanded through OAuth tokens, API keys, and machine identities
- Phishing and social engineering retained their dominance as initial access vectors, with ClickFix resurging
LevelBlue’s latest TTP Briefing for Q2 2026 lands at a moment when identity misuse has become one of the clearest indicators of how modern intrusions unfold. The incident response teams, now supported by integrated SpiderLabs intelligence, reported that stolen identities continued to outpace defensive controls across nearly every category of attack. Taken alongside broader industry findings from sources such as the NIST digital identity guidelines, Flashpoint, and Palo Alto Networks Unit 42, the picture that emerges is an ecosystem where adversaries prefer authentic logins over forced entry.
Identity-driven intrusions have become a standard operational reality, and the pace is accelerating. When 65% of initial access stems from phishing, as the report indicates, attackers no longer need sophisticated exploits to begin. Instead, they harvest credentials, intercept sessions, or obtain tokens that remove friction from their path. The cybercrime economy has thoroughly optimized for identity.
Flashpoint’s GTIR 2026 documented 3.3 billion stolen credentials circulated through criminal markets during 2025. SpyCloud’s Identity Exposure Report highlighted 65.7 billion identity records in its datalake. Layer these statistics with the observation that MFA was bypassed in every business email compromise (BEC) incident where it was deployed—with BEC accounting for 45% of total incidents—and a common theme appears: authentication is no longer a single event, it is an ongoing process that attackers continuously manipulate.
Software supply chain attacks continued their steady rise, but the mechanics behind them have changed. The Klue incident in June 2026 shows this clearly. By compromising Klue’s API credentials, adversaries self-identifying as Icarus or Mr. Bean authenticated to Salesforce-connected environments, automating malicious activity and impacting hundreds of organizations. Attackers no longer simply compromise a vendor; they exploit the vendor’s machine identities to sidestep the intrusion path. This shifts the defender’s job from perimeter controls to ongoing identity governance for both humans and services.
The resurgence of ClickFix social engineering shows that older tactics still carry weight. Fake CAPTCHA or CloudFlare prompts instructing users to paste commands locally remain highly effective. While security awareness training helps mitigate this risk, the visual variety of these deceptive prompts makes consistency a challenge for the workforce.
The exploitation of edge and VPN appliances continues to provide attackers with high-value footholds. The Briefing lists a familiar set of vulnerabilities frequently targeting Fortinet, Ivanti, or Cisco devices. These flaws often enable unauthenticated access or bypass authentication entirely. While defenders frequently focus on endpoint or cloud detection, these perimeter devices continue to create high-impact openings. Patching them quickly and restricting management interfaces reduces exposure, although operational realities often slow those updates.
Reports from the IEEE on authentication and secure protocols highlight how identity has become the main choke point for adversaries and defenders. Thales also noted in its 2026 Data Threat Report that a majority of organizations view identity and access management as the top priority due to rising credential theft. LevelBlue’s frontline findings echo these themes, showing how attackers actively adapt to compress dwell time and accelerate their operations.
Traditional intrusions often unfolded over weeks, with 30-day dwell times serving as a historical baseline. Yet incident response data shows the percentage of cases resolved within three to 10 days jumped from 23% in Q1 to almost half in Q2. Shorter windows indicate attackers hit objectives faster, aided by living-off-the-land binaries and automated tools, leaving defenders little room for hesitation.
MFA remains valuable, although its effectiveness is heavily influenced by the architecture deployed. Phishing-resistant FIDO2 or passkey-based methods reduce exposure to token interception kits, and pairing them with continuous session monitoring and shorter token lifetimes improves resilience. This dual approach aligns with guidance from NIST’s SP 800-63 framework.
Targeted sectors are also experiencing shifts in attack volume. Financial services continued to face the highest percentage of incidents at 28%, but education and research climbed to 13%, correlating with exam periods and academic calendar pressures. Legal and professional services also increased compared to Q1. Organizations with revenues between $1 million and $100 million saw the largest share of activity, indicating adversaries continue to target mid-market companies as accessible entry points.
Ultimately, identity has become both the primary entry vector and the core persistence mechanism. Whether through OAuth token abuse, stolen credentials, or compromised API keys, adversaries move quietly when they appear as trusted users or machines. The more organizations treat identity artifacts as sensitive infrastructure rather than simple access tools, the more space they create to detect anomalies early. The urgency from Q2’s data suggests that while defensive shifts are happening, adversaries are adapting just as quickly.
⬇️