Level Blue - stolen identities

LevelBlue TTP Briefing Finds Stolen Identities Are Outpacing Traditional Cyber Defenses

LevelBlue, the world’s largest pure-play provider of managed security services, has released its Q2 (April to June) 2026 Tactics, Techniques and Procedures (TTP) Briefing. The report reveals that attackers are increasingly relying on stolen identities rather than traditional intrusion techniques. This shift lets them gain and maintain access to organizational environments more easily.

The briefing is based on frontline incident response investigations conducted between April and June 2026. It provides insight into the tactics, techniques, and procedures threat actors are using to compromise organizations. The briefing also incorporates intelligence from SpiderLabs, strengthening visibility into emerging threats across today’s cyber landscape.

Devon Ackerman, Global Services Leader, Digital Forensics and Incident Response (DFIR) at LevelBlue, said, “Attackers are spending less time trying to break in and more time using identities organisations already trust. Once they have a valid account, session token or machine identity, they can often move through an environment without raising suspicion.”

“Traditional security controls remain important; however, organisations also need visibility into how identities and APIs are being used across their environments. Monitoring privileged access, cloud identities, and trusted integrations with third parties are becoming just as important as protecting the network perimeter,” Ackerman continued.

Why Are Attackers Targeting Stolen Identities?

Overall, business email compromise (BEC) remained the most common incident investigated, highlighting the continued value threat actors place on stolen identities.

The report found:

  • Business email compromise accounted for 45 percent of incidents.
  • Multi-factor authentication (MFA) was bypassed in every business email compromise incident where it had been deployed.
  • Cloud intrusion became the third most common incident type.
  • Attackers increasingly abused OAuth tokens, application programming interface (API) keys, and machine identities to gain access to cloud environments.

How Are Attackers Gaining Access?

Phishing continued to be the leading intrusion vector. In these attacks, threat actors combined social engineering and credential theft to establish initial access.

The report found:

  • Phishing and social engineering accounted for 65 percent of initial intrusion vectors.
  • External remote services accounted for 9 percent.
  • Valid accounts represented 7 percent of initial access methods.

ClickFix campaigns also re-emerged during the quarter, using fake CAPTCHA and error prompts to trick users into running malicious commands.

Are Software Supply Chain Attacks Changing the Threat Landscape?

Meanwhile, software supply chain attacks continued to evolve, with attackers increasingly targeting trusted third-party integrations instead of organizations directly.

The report highlights the growing abuse of OAuth applications, API keys, and machine identities to access connected cloud environments. For example, recent incidents, including the compromise of market intelligence platform Klue, demonstrate how a single trusted integration can create downstream risk for multiple organizations.

Are Attackers Moving Faster?

Attackers continued to reduce the time between initial access and achieving their objectives. As a result, organizations have less time to detect and contain malicious activity.

The report found:

  • Incidents resolved within three to 10 days increased from 23 percent in Q1 (January to March) to 42 percent in Q2.
  • Incidents lasting longer than 31 days fell from 38 percent to 23 percent.
  • Financial services remained the most targeted industry, followed by education and research, and legal and professional services.

To download the full Q2 2026 Tactics, Techniques and Procedures Briefing, click here. Additionally, for more information, visit LevelBlue.

About LevelBlue

LevelBlue reduces risk and builds lasting resilience so organizations can innovate and advance their mission with confidence. As the world’s largest pure-play managed security services provider, LevelBlue combines AI-powered security operations, advanced threat intelligence, and elite human expertise. Together, these deliver strategic advisory, managed security, offensive security, and incident response services. Learn more at LevelBlue.

Stay Informed With Cyber News Live

Cyber threats are constantly evolving, and staying informed is critical to protecting your organization.
Follow Cyber News Live for the latest cybersecurity news, threat intelligence, expert analysis, and practical guidance to help strengthen your cyber defenses.

Shopping Cart0

Cart

Login