CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

One Click to Compromise: ThreatLabz 2026 Phishing and Initial Access Report

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6249

As cited

Copy frozen at (site build).

threat intel

One Click to Compromise: ThreatLabz 2026 Phishing and Initial Access Report

Zscaler's ThreatLabz released its 2026 Phishing and Initial Access Report, analyzing large-scale telemetry on how attackers are evolving phishing campaigns. Despite a 20% year-over-year decline in phishing volume, threat actors are shifting to highly targeted, personalized lures delivered over encrypted channels (95.2% over TLS/SSL), combined with adversary-in-the-middle and browser-in-the-middle techniques that capture credentials and multifactor authentication (MFA) codes in real time. The report highlights that artificial intelligence (AI) site builders have generated over 413,000 phishing site instances, with cloud infrastructure enabling attackers to conduct reconnaissance at scale, including 121,000+ distinct AWS-hosted IPs probing customer environments.

Why it matters: Security teams must assume phishing will succeed and implement zero-trust access controls, encrypted traffic inspection, and deception-based detection to catch reconnaissance early, prevent session compromise despite MFA, and contain lateral movement when initial access is achieved.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

One Click to Compromise: ThreatLabz 2026 Phishing and Initial Access Report

Zscaler's ThreatLabz released its 2026 Phishing and Initial Access Report, analyzing large-scale telemetry on how attackers are evolving phishing campaigns. Despite a 20% year-over-year decline in phishing volume, threat actors are shifting to highly targeted, personalized lures delivered over encrypted channels (95.2% over TLS/SSL), combined with adversary-in-the-middle and browser-in-the-middle techniques that capture credentials and multifactor authentication (MFA) codes in real time. The report highlights that artificial intelligence (AI) site builders have generated over 413,000 phishing site instances, with cloud infrastructure enabling attackers to conduct reconnaissance at scale, including 121,000+ distinct AWS-hosted IPs probing customer environments.

Why it matters: Security teams must assume phishing will succeed and implement zero-trust access controls, encrypted traffic inspection, and deception-based detection to catch reconnaissance early, prevent session compromise despite MFA, and contain lateral movement when initial access is achieved.

VendorsAmazon Web Services
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary