Intel Node
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements where initial access could be determined. Phishing has not been the top vertical for initial access since Q2 2025.
Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements where initial access could be determined.  Phishing has not been the top vector for initial access since Q2 2025. Public administration and health care tied as the most targeted industry verticals, each accounting for 24 percent of all engagements. This is the third consecutive quarter where public administration has been the most targeted industry vertical.
   Pre-ransomware incidents made up just 18 percent of engagements this quarter, and we did not observe any ransomware deployment due to early and swift mitigation from Cisco Talos Incident Response (Talos IR).