InfoGuard AG (Headquarter)
Lindenstrasse 10
6340 Baar
Switzerland
InfoGuard AG
Stauffacherstrasse 141
3014 Bern
Switzerland
InfoGuard Deutschland GmbH
Frankfurter Straße 233
63263 Neu-Isenburg
Germany
InfoGuard Deutschland GmbH
Landsberger Straße 302
80687 Munich
Germany
InfoGuard Deutschland GmbH
Am Gierath 20A
40885 Ratingen
Germany
InfoGuard GmbH
Kohlmarkt 8-10
1010 Vienna
Austria
Between new attack techniques and known entry points, the cyber threat landscape in the first half of 2026 is in flux. An analysis of approximately 150 cyber incidents by the InfoGuard CSIRT reveals which attack patterns have become prevalent in practice. This cyber threat intelligence analysis summarizes the key findings and derives concrete priorities for your cyber defense strategy.
Among the most common attack vectors in the nearly 150 incidents were phishing (34 percent), lack of multi-factor authentication (MFA) (16 percent), and vulnerabilities (11 percent).
Among the 24 ransomware incidents examined, the lack of multi-factor authentication is particularly significant: In six out of ten cases, it was the decisive factor in the success of the attack.
Incidentally, one of our earlier articles analyzes around 350 incidents from last year. Comparing them provides context, but what is crucial for current cyber defense is understanding the actual pathways attackers will use to gain access to corporate environments in 2026.
The analysis of initial attack vectors reveals the methods attackers used to gain access to corporate environments in the first half of 2026. The spectrum ranges from phishing and a lack of multi-factor authentication to exploited vulnerabilities and misconfigurations, all the way to supply chain attacks. Furthermore, false positives account for a significant share at 23 percent. These are suspected incidents that, according to our analysis, are not confirmed as actual security incidents. This breakdown reveals where cyberattacks actually originate—and thus also where preventive security measures are particularly effective.
Figure 1: Initial vectors of cyber incidents handled in the first half of 2026 (own image archive)
Most of the phishing attacks we investigated aim to take over an existing session. In particular, Adversary-in-the-Middle (AiTM) and device code phishing are used. To build trust, attackers often use compromised email accounts belonging to business partners or register deceptively similar domains. This makes phishing emails appear legitimate at first glance, increasing the likelihood that links will be clicked and authentication processes triggered. Depending on the compromised identity, attackers then use the hijacked account for further phishing attacks, data exfiltration, or targeted internal phishing. The goal is often to expand their presence within the company and lay the groundwork for more complex follow-up attacks.
Here’s how it happened: In a rather sophisticated attack that began with the compromise of an employee’s personal email account, the attacker was able to identify an email containing the MFA registration QR code. The attacker used this QR code to register the MFA themselves. Since the same password was used for both personal and business accounts, and the QR code came from the business email address, it was easy for the attacker to take over the employee’s business account unimpeded.
Furthermore, the InfoGuard CSIRT has also recorded incidents involving malicious LNK files that were sent to the victim via a ZIP file. In one specific case, the attacker posed as a recruiting firm and tricked the victim into opening the files that were sent. This initially compromised the victim’s device. Subsequently, the attack escalated into a full-scale compromise of the company via ransomware.
The lack of multi-factor authentication remains a particularly critical factor in ransomware incidents. According to our statistics, it was a decisive factor in six out of ten cases investigated—with a correspondingly high potential for damage to the affected companies.
Of particular concern here are unprotected VPN access points, exposed firewall management interfaces, exposed remote desktop protocols, and logins to data exchange platforms where sensitive information is also hosted.
Info-stealers, which are often run on personal devices, also pose a threat that is difficult to control. In the absence of appropriate detection or mitigation technologies, they can often steal login credentials for business accounts without being detected. We observed such cases in compromised business software, open-source software, cracked commercial software, game mods, compromised NPM packages, and ClickFix, among others.
In the incidents we investigated, we also repeatedly identified compromised technical user accounts, such as those for scanners or printers. These are often protected only by weak passwords and are compromised through brute-force attacks.
Furthermore, multi-factor authentication is often not configured for such accounts. Combined with inadequate access control policies, they can still be exploited to gain remote access or access to exposed corporate portals. Another gap involves the lack of logs from edge devices. Without central correlation of these logs with other infrastructure and security logs, the detection of brute-force attacks is limited.
Product manufacturers, security researchers, and threat actors are increasingly using AI to search for vulnerabilities. For companies, this intensifies the tension between rapid implementation and thorough testing of critical security patches. Patch management is thus under pressure: Critical entry points must be closed quickly, while at the same time the risk of operational impact must be kept as low as possible.
The focus is on edge devices such as firewalls, VPN appliances, and MDM solutions. In addition, cybercriminals exploit vulnerabilities in externally exposed applications —such as data exchange platforms or content management systems (CMS)—with the goal of infiltrating corporate environments.
IT infrastructures are constantly changing: new requirements, updates, redesigns, cloud migrations, and hybrid architectures increase complexity. The more complex an infrastructure becomes, the more vulnerable it is to potential misconfigurations.
Such misconfigurations are often difficult to identify. However, regular configuration reviews, continuous configuration monitoring, and recurring product training to refresh expertise are not standard practice in all companies or easily implementable.
As a result, established risk exposure management is becoming increasingly widespread; it uses various approaches to assess a company’s exposure and helps identify misconfigurations before attackers can exploit them.
Supply chain incidents pose a significant risk of damage. Often, malware is installed with administrator privileges, allowing attackers to gain direct, highly privileged local access in the event of a successful compromise.
Most supply chain incidents could be traced back to either compromised software vendors or software from untrusted sources. Threat actors bundled legitimate software with additional malware and then distributed it.
In connection with compromised software vendors, the InfoGuard CSIRT handled incidents involving Axios and the Trivy Network Scanner, among others. In one of these cases, the attacker used remote access to move laterally within the customer’s infrastructure before being detected and stopped.
Regarding software from untrusted sources, we also recorded a case involving a compromised Windows 11 image. This was advertised via a link posted on GitHub and could subsequently be downloaded through popular file-sharing platforms.
Last year, we already handled an incident involving the RVTools software. This year, the same software was again offered for download on a file-sharing platform and, upon execution, installed a Python backdoor as a Windows service.
In another incident, a residential proxy was installed alongside the K-Lite Codec software. This was not discovered until criminal activities were carried out via this proxy, prompting local authorities to contact the affected company.
Public LLMs such as ChatGPT, Claude, and DeepSeek are increasingly becoming part of everyday work. At the same time, governance for their use is not yet sufficiently established in many companies. This also increases the risk that business, customer, or personal data will unintentionally end up in public LLMs.
If a company detects indications of a potential data leak, it must specifically assess the impact and determine whether this triggers any data protection reporting or disclosure obligations. This also applies to unusually high upload volumes: In such cases, the key questions are what information was transferred and whether sensitive business or customer data is affected.
In Switzerland, the FDPIC specifies how to handle data breaches and the associated reporting obligations; in the EU, the GDPR governs the handling of personal data breaches.
Clear areas of action can be derived from the analyzed cyber incidents to reduce risks in a more targeted manner and effectively align one’s own cyber defense.
The following eight recommendations address the most common attack patterns and vulnerabilities identified in the semi-annual analysis and translate them into concrete security measures.
Multi-factor authentication (MFA) should be mandatory for all externally accessible access points, cloud services, administrative accounts, and critical applications. Exceptions, outdated authentication methods, and unprotected service accounts weaken the entire security architecture.
Traditional push notifications or SMS offer only limited protection against modern phishing and social engineering attacks. For privileged and particularly vulnerable user accounts, phishing-resistant methods such as FIDO2 security keys, passkeys, or certificate-based authentication should be used.
Effective patch management requires clear responsibilities, a comprehensive overview of assets, and binding deadlines. Systems particularly exposed to the internet—such as VPN gateways, firewalls, hypervisors, and central management platforms—must be prioritized and, if necessary, updated outside of regular cycles.
In addition to known vulnerabilities, companies must continuously assess their actual attack surface. This includes exposed systems, cloud resources, identities, misconfigurations, third parties, and unknown assets. It is crucial to prioritize based on actual business risk rather than solely on technical scores.
Administrators, developers, and support staff are attractive targets because their accounts grant extensive access. Awareness measures should therefore be technical, role-based, and practical. Topics such as fake support requests, tampered software packages, OAuth authorizations, info-stealers, and the misuse of administrative tools must be addressed specifically.
Software vendors, external service providers, and open-source components expand an organization’s attack surface. Companies should minimize third-party access, verify software sources, inventory dependencies, and monitor privileged installations. Trust alone is not a security control.
EDR, NDR, and other detection technologies are only effective if they cover all relevant systems. Servers, clients, cloud workloads, container hosts, build systems, hypervisors, and critical management platforms must not remain blind spots. Actual coverage should be regularly reviewed and technically tested.
Today, attacks regularly cross the boundaries between on-premises systems, cloud services, and identities. Therefore, relevant logs must be collected centrally and correlated with one another. Only by linking endpoint, network, identity, cloud, and application data is it possible to detect complete attack chains rather than isolated individual events.
Use the “InfoGuard Threat Intelligence Insights” white paper to compare the findings of the semi-annual analysis with your own threat landscape and to prioritize relevant cyber risks and protective measures in a targeted manner.
The nearly 150 cyber incidents examined in the first half of 2026 demonstrate how dynamically attack techniques are evolving—and how crucial it remains to consistently secure known entry points.
Four key areas for action can be derived from the analyzed cyber incidents:
Effectively protect identities.
Identify exposed systems and misconfigurations early on.
Monitor software supply chains.
Correlate relevant signals across the entire infrastructure.
What matters here is not so much the number of individual security measures as their prioritization based on actual risk. Insights from real-world cyber incidents help identify blind spots and deploy existing resources where they yield the greatest security benefits.
For effective cyber defense, you need to know which risks are actually relevant to your company. 24/7 monitoring and incident response provide the necessary visibility and deliver insights to prioritize security measures based on risk and refine them in a targeted manner.
Don’t miss out on relevant developments in cybersecurity. With our blog updates, you’ll regularly receive in-depth analysis of new cyber threats, current security risks, and key trends.
Caption: AI-generated image