Banner Hexagons
July 29, 2026

LevelBlue TTP Briefing finds stolen identities are outpacing traditional cyber defences

Latest threat intelligence reveals business email compromise remains the leading cyber incident as attackers increasingly exploit trusted identities, machine credentials, and software supply chains

July 24, 2026LevelBlue, the world’s largest pure-play provider of managed security services, has released its Q2 (April to June) 2026 Tactics, Techniques and Procedures (TTP) Briefing, which reveals that attackers are increasingly relying on compromised identities rather than traditional intrusion techniques to gain and maintain access to organisational environments.

Based on frontline incident response investigations conducted during April to June of 2026, the report provides insight into the tactics, techniques, and procedures threat actors are using to compromise organisations. This briefing also incorporates intelligence from SpiderLabs, strengthening visibility into emerging threats across today’s cyber landscape.

Devon Ackerman, Global Services Leader, Digital Forensics and Incident Response (DFIR), LevelBlue, said, “Attackers are spending less time trying to break in and more time using identities organisations already trust. Once they have a valid account, session token or machine identity, they can often move through an environment without raising suspicion.

“Traditional security controls remain important; however, organisations also need visibility into how identities and APIs are being used across their environments. Monitoring privileged access, cloud identities, and trusted integrations with third parties are becoming just as important as protecting the network perimeter.”

Why are attackers targeting identities?

Business email compromise (BEC) remained the most common incident investigated, highlighting the continued value threat actors place on compromised identities.

The report found:

  • business email compromise accounted for 45 per cent of incidents
  • multi-factor authentication (MFA) was bypassed in every business email compromise incident where it had been deployed
  • cloud intrusion became the third most common incident type
  • attackers increasingly abused OAuth tokens, application programming interface (API) keys and machine identities to gain access to cloud environments.

How are attackers gaining access?

Phishing continued to be the leading intrusion vector, with threat actors combining social engineering and credential theft to establish initial access.

The report found:

  • phishing and social engineering accounted for 65 per cent of initial intrusion vectors
  • external remote services accounted for 9 per cent
  • valid accounts represented 7 per cent of initial access methods.

ClickFix campaigns re-emerged, using fake CAPTCHA and error prompts to trick users into running malicious commands.

Are software supply chain attacks changing the threat landscape?

Software supply chain attacks continued to evolve, with attackers increasingly targeting trusted third-party integrations instead of organisations directly.

The report highlights the growing abuse of OAuth applications, API keys, and machine identities to access connected cloud environments. Recent incidents, including the compromise of market intelligence platform Klue, demonstrate how a single trusted integration can create downstream risk for multiple organisations.

Are attackers moving faster?

Attackers continued to reduce the time between initial access and achieving their objectives, leaving organisations with less time to detect and contain malicious activity.

The report found:

  • incidents resolved within three to 10 days increased from 23 per cent in Q1 (January to March) to 42 per cent in Q2
  • incidents lasting longer than 31 days fell from 38 per cent to 23 per cent
  • financial services remained the most targeted industry, followed by education and research, and legal, and professional services.

To download the full Q2 2026 Tactics, Techniques and Procedures Briefing, click here.

For more information, visit www.levelblue.com.

About LevelBlue

LevelBlue reduces risk and builds lasting resilience so organisations can innovate and advance their mission with confidence. As the world’s largest pure-play managed security services provider, LevelBlue combines AI-powered security operations, advanced threat intelligence and elite human expertise to deliver strategic advisory, managed security, offensive security and incident response services. Learn more at www.levelblue.com.

Share: