Between May 1 and July 31, 2026, cybersecurity firm Prophet Security conducted an in-depth analysis of every alert generated within its customer environments, identifying four primary attack patterns responsible for confirmed malicious activity. The investigation, which involved asking 4.7 million questions of customer systems, revealed that approximately 7% of all alerts indicated genuine threats, with the remaining 93% being benign. A significant finding was that identity was the target in roughly half of all confirmed malicious incidents during this period.
The most prevalent method for attackers to compromise accounts was session hijacking, which constituted about 18% of confirmed malicious activity. This included token replay, MFA bypass, credential stuffing, and post-compromise persistence through inbox rules and OAuth consent grants. While attempts using passwords were frequently blocked by security controls like conditional access or phishing-resistant multi-factor authentication (MFA), attacks leveraging already-authenticated sessions consistently succeeded. These stolen session cookies bypassed standard authentication checks, allowing attackers continuous access to accounts, sometimes for weeks, even after accounts were disabled or passwords reset. The analysis also noted instances where MFA fatigue attacks were successful, with attackers repeatedly sending prompts until a user approved, or exploiting automatic unlock policies to register new devices.
The primary source of these stolen sessions was infostealers delivered via web browsers, accounting for approximately 23% of confirmed malicious activity. These infostealers affected about a quarter of the organizations investigated and were predominantly spread through compromised legitimate websites, malicious advertisements, sponsored search results, and fake CAPTCHA gates (known as ClickFix). Trojanized installers, often disguised as popular software, hardware diagnostic tools, or cracked applications, were a common initial foothold. Identified delivery tools included ClearFake and SocGholish, with payloads such as Lumma Stealer, Vidar, HijackLoader, and AsyncRAT. Even after the disruption of SocGholish infrastructure in June 2026, the underlying fake update technique persisted through other groups. These infostealers extracted authentication cookies from browser cookie stores, enabling attackers to replay sessions and bypass traditional authentication mechanisms.
Credential phishing represented the largest single category of confirmed malicious activity, making up about 28%. These highly targeted campaigns primarily aimed to steal credentials or sessions rather than deliver malware. Attackers frequently focused on individuals in financial roles, such as finance executives, collections, accounts payable, and treasury mailboxes, often using ACH-themed lures. Some campaigns targeted automated invoice-processing mailboxes, which lack human oversight. The phishing emails often originated from trusted infrastructure, including legitimate collaboration platforms and major cloud email services, and sometimes impersonated internal systems. Attackers employed modern tactics like Unicode characters in subject lines, newly registered or typosquatted domains, and tracking pixels. Standard email authentication checks were not always effective, with some spoofed messages bypassing SPF, DKIM, and DMARC to reach inboxes. The time taken to remove malicious emails varied significantly, from seconds in organizations with automated remediation to over a day in others.






