LevelBlue has released its Q2 (April to June) 2026 Tactics, Techniques and Procedures (TTP) Briefing, reporting that attackers are increasingly relying on compromised identities rather than traditional intrusion techniques to gain and maintain access to organisational environments.
Based on incident response investigations conducted during April to June 2026, the report outlines tactics, techniques, and procedures used to compromise organisations. It also draws on intelligence from SpiderLabs.
Devon Ackerman, Global Services Leader, Digital Forensics and Incident Response (DFIR), LevelBlue, said, “Attackers are spending less time trying to break in and more time using identities organisations already trust. Once they have a valid account, session token or machine identity, they can often move through an environment without raising suspicion.
“Traditional security controls remain important; however, organisations also need visibility into how identities and APIs are being used across their environments. Monitoring privileged access, cloud identities, and trusted integrations with third parties are becoming just as important as protecting the network perimeter.”
Why are attackers targeting identities?
The briefing said business email compromise (BEC) remained the most common incident investigated, which it attributed to the ongoing value of compromised identities.

The report found:
- business email compromise accounted for 45 per cent of incidents
- multi-factor authentication (MFA) was bypassed in every business email compromise incident where it had been deployed
- cloud intrusion became the third most common incident type
- attackers increasingly abused OAuth tokens, application programming interface (API) keys and machine identities to gain access to cloud environments.
How are attackers gaining access?
The report said phishing remained the leading intrusion vector, with threat actors combining social engineering and credential theft to establish initial access.
The report found:
- phishing and social engineering accounted for 65 per cent of initial intrusion vectors
- external remote services accounted for 9 per cent
- valid accounts represented 7 per cent of initial access methods.
The briefing said “ClickFix” campaigns had re-emerged, using fake CAPTCHA and error prompts to trick users into running malicious commands.
Are software supply chain attacks changing the threat landscape?
The report said software supply chain attacks continued to evolve, with attackers increasingly targeting trusted third-party integrations rather than organisations directly.
It highlighted what it described as growing abuse of OAuth applications, API keys and machine identities to access connected cloud environments. It cited the compromise of market intelligence platform Klue as an example of how a single trusted integration can create downstream risk for multiple organisations.
Are attackers moving faster?
According to the briefing, attackers continued to reduce the time between initial access and achieving their objectives, narrowing the window for detection and containment.
The report found:
- incidents resolved within three to 10 days increased from 23 per cent in Q1 (January to March) to 42 per cent in Q2
- incidents lasting longer than 31 days fell from 38 per cent to 23 per cent
- financial services remained the most targeted industry, followed by education and research, and legal and professional services.
You can read the full report here.

