According to the Cisco Talos Incident Response Trends report for March to June 2026, published on July 28, phishing accounted for the initial attack vector in just over half of incidents investigated.
Phishing’s resurgence and the shifting baseline for initial access
Cisco Talos’ quarterly analysis shows a marked rebound in phishing as a first-step intrusion technique. The report says phishing “accounted for the initial attack vector in just over half of incidents investigated,” a significant rise from the previous quarter when Talos recorded phishing as the entry point in roughly one-third of cases. Other commonly observed initial access vectors during the period included exploitation of public-facing applications and drive-by compromise attacks — the latter occurring when users visit compromised websites designed to deliver malicious code.
QR codes and trusted cloud hosting: the UAT-11764 campaign
Talos documented a persistent QR-code phishing campaign, ongoing as of late June 2026, that targeted organizations to harvest Microsoft 365 login credentials and to propagate itself by automatically targeting the victims’ contacts. The campaign used auto-generated, victim-tailored PDF documents containing QR codes that directed recipients to adversary-controlled Microsoft 365 credential harvesting pages. Talos attributed the activity to a threat actor it labeled UAT-11764.
The researchers described two specific evasion advantages: QR codes can evade detection by many traditional email gateways, and the credential-harvesting pages were hosted on trusted cloud platforms, which may not be flagged by security solutions. Once credentials were stolen, attackers performed post-compromise actions including creating email inbox rules to evade detection and using the compromised accounts to send additional phishing emails. As the paper warned, “By weaponizing existing, trusted infrastructure like SharePoint and Microsoft 365, UAT-11764 can bypass many standard email security gateways.”
Phishing-as-a-Service kits grow more capable
Talos’ report highlights a noticeable increase in the sophistication of Phishing-as-a-Service (PhaaS) offerings. These kits now include tools and services that go beyond simple credential pages — examples cited in the report range from toolkits that bypass multi-factor authentication via the OAuth device authorization flow rather than stealing passwords, to services that provide attackers with a post-compromise toolkit such as “searching for specific information in emails with keyboards.”
Observed capabilities included automated token management, persistent access through Primary Refresh Tokens (PRTs), OneDrive and SharePoint administration, geo-dynamic templates, inbox rule manipulation, cross-account keyword monitoring, and collaborative token sharing. Researchers also noted advanced anti-analysis techniques, including layered evasion mechanisms and encrypted client-side payloads. According to the report, techniques like this highlight “the increasing sophistication of modern PhaaS platforms.”
Cisco Talos’ recommended mitigations for defenders
The report lists concrete protective measures Talos recommends to blunt phishing and the post-compromise effects observed during the quarter. They include:
- Implement properly configured, phishing-resistant MFA and tighten authentication controls
- Configure centralized logging with adequate retention across the environment
- Conduct robust patch management and reduce exposed infrastructure
- Enforce strict outbound email thresholds to disrupt attack propagation
For the UAT-11764-style QR-code campaigns specifically, Talos urged defenders to implement policies that block or flag emails containing QR codes within PDF attachments, enforce phishing-resistant multi-factor authentication on Microsoft 365 accounts, and monitor for suspicious inbox rule creation and anomalous SharePoint file staging as indicators of post-compromise activity.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: prioritize enforcement of phishing-resistant MFA, centralized logging, and monitoring for inbox-rule changes and SharePoint file staging as concrete indicators of compromise noted by Talos.
- Affected enterprises and procurement leaders: expect threat actors to increasingly leverage trusted cloud hosting and turnkey PhaaS capabilities; contractual and procurement reviews should consider vendor controls for token management and administrative misuse of OneDrive/SharePoint.
- End users and general staff: be particularly cautious about PDF attachments that include QR codes and recognize that a compromised corporate inbox can be used to automate further phishing or contact-targeted propagation.
The lesson from Cisco Talos’ March–June 2026 snapshot is not that phishing is new, but that attackers are making it more effective and more evasive by combining social engineering with trusted platform abuse and increasingly polished service offerings. Defenders who assume standard email gateways alone are sufficient will find that the adversary techniques catalogued by Talos — QR-code lures, cloud-hosted credential pages, inbox rule manipulation, and PRT-based persistence — were purpose-built to slip past those controls. Whether organizations adopt the specific mitigations Talos lists will largely determine how successful this phase of phishing campaigns becomes.




