CyberheistNews Vol 16 #35 [New Report] Phishing Is Still the No. 1 Initial Threat Access Vector

KnowBe4 Team | Sep 1, 2026
Cyberheist News

CyberheistNews Vol 16 #35  |   September 1st, 2026

[New Report] Phishing Is Still the No. 1 Initial Threat Access Vector

Phishing is still the top initial access vector, accounting for more than half of cyberattacks observed during Q2 2026, according to a new report from Cisco Talos.

"Phishing was the primary means of gaining initial access this quarter, appearing in over half of all Cisco Talos Incident Response (Talos IR) engagements – an increase from approximately a third of engagements last quarter," the researchers write.

"Attackers continued to innovate their delivery methods to evade defenses, deploying QR code-embedded PDFs to bypass traditional email gateways and hosting links on trusted cloud platforms.

"We also saw a spike in authentication abuse this quarter — observed in 65 percent of engagements compared to 35 percent last quarter — with attackers frequently bypassing or defeating multi-factor authentication (MFA) using adversary-in-the-middle (AitM) proxies, session-token theft, MFA fatigue attacks and self-enrolled devices, amongst other methods."

Talos highlights a sophisticated QR code phishing campaign that's targeting Australians in order to steal Microsoft 365 credentials. "Starting in April, we observed a persistent QR code phishing campaign targeting primarily Australian organizations that leverages compromised Microsoft 365 accounts to harvest credentials and propagate the attack via internal contact lists," the researchers write.

"The campaign, which remained ongoing as of late June 2026, employs auto generated, victim-tailored PDF documents containing QR codes that direct to adversary-controlled M365 credential harvesting pages. If credentials are successfully captured, the adversary attempts access to the victim's Microsoft account and conducts various post-compromise actions including creating email inbox rules for defense evasion, leveraging SharePoint to host malicious documents and sending additional internal and external phishing emails to continue the compromise chain."

Threat actors also continue to find ways to bypass multifactor authentication (MFA), with a 30% increase in authentication abuse in Q2 2026.

"Authentication abuse was the most prevalent security weakness this quarter, observed in 65 percent of engagements — up sharply from 35 percent last quarter," Talos says. "Adversaries consistently defeated or bypassed MFA using AitM proxies and session-token theft, MFA fatigue attacks, registration of attacker controlled devices for authentication and legacy authentication protocols that circumvent MFA altogether."

Blog post with links:
https://blog.knowbe4.com/report-phishing-remains-the-primary-initial-access-vector

Personalized Security Awareness Training Proven to Reduce Risk by 87%

68% of breaches still involve a human element. As attackers use AI to create hyper-personalized attacks, even your most security-conscious users can be fooled. Yet they're still getting the same generic training that ignores those real-world risks.

Join us for a live demo to see how our AI-Native Security Awareness Training helps you close the gap. Training that adapts to each user's actual risk, content you can build in minutes instead of months and defenses built for the way people are attacked today.

See how you can:

  • Change behavior with training tailored to each user's role, behavior and risk level
  • Prepare your workforce for real threats like vishing, deepfakes and AI-generated phishing
  • Create custom content unique to your policies and workflows in minutes with generative AI
  • Deliver real-time coaching the moment risky behavior happens, before it becomes a mistake
  • Reduce Phish-prone™ Percentage from an industry average of 33.1% to 4.1% in one year (87% reduction in human risk)

See how training that adapts in real time can close the gap that generic training leaves open.

Date/Time: Wednesday, September 9, @ 2:00 PM (ET)

Save My Spot:
https://info.knowbe4.com/sat-demo-month3?partnerref=CHN

Attackers Use Vishing Attacks to Distribute New Android Malware

Attackers are distributing a new Android malware called "WindRelay" via phone based social engineering attacks, according to researchers at Group-IB. The attackers call the victims, impersonating bank employees and instruct them to install a malicious app.

In one instance observed by Group-IB, the scammers carried out the entire attack in just thirteen minutes.

"In one 13-minute phone call, the victim installed a RAT onto their own device — everything after that was performed by the fraudster," Group-IB says. "By the end of the call, the fraudster had taken out a loan in the victim's name through remote access to the victim's mobile app, and was streaming their card data to a fake merchant terminal.

"Every transaction was approved using the PIN the victim had entered themselves. The victim stayed on a live call with the fraudster for the entire incident."

The use of a single phone call allows the attackers to maintain a sense of urgency and complete the scam before the victim has a chance to collect themselves. The attack chain proceeds as follows:

  1. "The fraudster called the victim posing as a bank employee, claiming a problem with their bank card.
  2. The victim installed the first app — a RAT, labeled with the victim's own name — after being guided to do so by the fraudster on the call.
  3. Using the RAT's remote access features, the fraudster then installed a second app — the NFC relay malware — without needing any additional input or action from the victim.
  4. Once remote access was in place, the fraudster also took the opportunity to issue a loan in the victim's name. Our investigation indicates that this was likely an add-on to maximize the payout, not a separately planned step.
  5. The victim tapped their card to their phone and entered their PIN, as instructed."

AI-native security awareness training can give your employees a healthy sense of suspicion so they can recognize social engineering tactics. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 orgs worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce workforce risk.

One more thing. The workforce changed. Half of it doesn't have a badge. KnowBe4 empowers all of it, the people and the agents working alongside them. KnowBe4 empowers the digital workforce, humans and AI agents.

Blog post with links:
https://blog.knowbe4.com/attackers-use-vishing-attacks-to-distribute-new-android-malware

Email Security Kit: Resources for Redefining Your Defense

91% of cybersecurity leaders say their email security lets too many threats through.

While phishing remains the entry point for 70% of breaches, the gap between traditional email security and modern adversarial tactics is widening. This oversight leaves your workforce vulnerable to threats that bypass standard filters.

This kit cuts through the marketing hype, helping you navigate the needed transition from legacy systems to an integrated approach to cloud email security.

Here’s what you’ll get:

  • Report: 2026 Phishing Threat Trends Report, Vol. 7
  • Infographic: Humans + AI: Better Than Your SEG
  • Webinar: Moving Beyond Traditional Email Security
  • Whitepaper: From Legacy to ICES: Separating Marketing Hype from Proven Email Defense
  • Whitepaper: Critical Capabilities When Evaluating Integrated Cloud Email Security
  • Infographic: KnowBe4 Integrates with Microsoft

Download Now:
https://info.knowbe4.com/email-security-kit?utm_source=chn_email&utm_medium=email&utm_campaign=dg-ces-campaign-26&utm_content=ces_kit

Report: AI Chatbots Are More Effective at Building Trust Than Human Scammers

A study has found that AI chatbots can be more effective at social engineering than human scammers, WIRED reports. The researchers looked at a form of romance scam commonly known as "pig butchering," in which scammers spend weeks or months building a relationship with the victim before tricking them into sending money for a phony investment scheme.

"[The researchers] found that for the relationship-establishing stages of the scam—the stage that in real-world scams typically represents the longest part of the interactions with the victim, often stretching to months—an AI chatbot performed remarkably effectively, successfully impersonating a human and by some measures outperforming the real human 'scammers' in their experiment," WIRED says.

Since the majority of the scam consists of non-malicious conversations, the researchers found that even legitimate AI chatbots could be used to automate the trust-building stage. Once the scammer is ready to ask for money, a human operator takes over.

Yisroel Mirsky, a computer science professor at Ben-Gurion University who led the research, stated, "By having the full first stage of the scam performed automatically with LLMs at scale, you bring the victim up to this point where they have a very high level of trust. Then by transitioning it over to the human scammer at the end, this completely bypasses any vendor safeguards. 

"With relatively little effort, we're able to make an agent that can outperform a human at building this exploitable emotional trust."

Notably, when the participants in the study were informed that one of the conversations they were having was with an AI chatbot, nearly all of them were able to identify which conversation it was. Before they were told, however, only one participant suspected that they were talking to an AI.

One of the researchers, Gilad Gressel, noted, "That's exactly how scams are, actually. Once the scam victim realizes what's going on, it's obvious. But when you're in the illusion of it, you just don't see it."

WIRED has the story:
https://www.wired.com/story/ai-scammers-are-better-at-building-trust-than-humans/

Identify Weak User Passwords In Your Organization With the Newly Enhanced Weak Password Test

Cybercriminals never stop looking for ways to hack into your network, but if your users' passwords can be guessed, they've made the bad actors' jobs that much easier.

Verizon's Data Breach Investigations Report showed that 81% of hacking-related breaches use either stolen or weak passwords.

The Weak Password Test (WPT) is a free tool to help IT administrators know which users have passwords that are easily guessed or susceptible to brute force attacks, allowing them to take action toward protecting their organization.

Weak Password Test checks the Active Directory for several types of weak password related threats and generates a report of users with weak passwords.

Here's how Weak Password Test works:

  • Connects to Active Directory to retrieve password table
  • Tests against 10 types of weak password related threats
  • Displays which users failed and why
  • Does not display or store the actual passwords
  • Just download, install and run. Results in a few minutes!

Don't let weak passwords be the downfall of your network security. Take advantage of KnowBe4's Weak Password Test and gain invaluable insights into the strength of your password protocols.

Download Now:
https://info.knowbe4.com/free-cybersecurity-tools/weak-password-test-chn


Let's stay safe out there.

Warm regards,

Stu Sjouwerman, SACP
Executive Chairman
KnowBe4, Inc.

PS: Yours Truly in Forbes: "AI Agents Speak With Confidence, But They Need Provenance"
https://www.forbes.com/councils/forbestechcouncil/2026/08/26/ai-agents-speak-with-confidence-but-they-need-provenance/

Quotes of the Week  
"In any moment of decision, the best thing you can do is the right thing, the next best thing is the wrong thing, and the worst thing you can do is nothing."
- Theodore Roosevelt (1858-1919)

"Nothing has such power to broaden the mind as the ability to investigate systematically and truly all that comes under thy observation in life."
- Marcus Aurelius - Roman Emperor (121-180 AD)

Thanks for reading CyberheistNews

You can read CyberheistNews online at our Blog
https://blog.knowbe4.com/cyberheistnews-vol-16-35-new-report-phishing-is-still-the-no-1-initial-threat-access-vector

Security News

Report: The Average Cost of Cyber Insurance Claims Surged by 100% Last Year

The average cost of cyber insurance claims surged last year, though the volume of claims dropped, according to a new report from insurance provider Chubb.

For large companies in the United States, the cost of claims associated with cyberattacks rose by 100% in 2025 compared to 2024. A similar trend was observed in Europe, with a 98% increase.

Cyber-related claims for large firms rose from an average of $2.2 million in 2024 to more than $4.4 million in 2025. The increase was largely due to increasing disruption by ransomware attacks and subsequent litigation, exacerbated by extortion gangs intentionally leaking data to increase pressure on their victims.

"A cyber incident is no longer just a technical failure to be remediated: it is frequently a trigger for legal action shortly after an incident," the report says. "Over the past 30 years, privacy and data protection laws have been enacted at an extraordinary pace, increasing the complexity of compliance and the frequency of privacy litigation.

"The gap between a breach and the first class-action filing has diminished, with litigation often ensuing within days, with varying allegations irrespective of the size of the entity or any controls perceived to be lacking."

Social engineering fraud played a large role in cyberattacks during 2025, with small and medium-sized businesses particularly vulnerable to these attacks. The report notes that attackers are using AI to automate cyber operations, so organizations should prepare for faster and more sophisticated attacks.

"The same AI technology that has enabled faster and more thorough detection of cyber incidents has fundamentally altered the velocity of incidents: By incorporating agentic and autonomous AI into malware, bad actors are now compromising multiple systems in a matter of minutes – all but eliminating the opportunity for manual intervention," Chubb says.

"Bad actors' use of advanced AI, such as Large Language Models (LLMs) is increasing at nearly the same pace as AI adoption by everyday consumers." KnowBe4 empowers your workforce to make smarter security decisions every day.

Infosecurity Magazine has the story:
https://www.infosecurity-magazine.com/news/cyber-insurance-losses-increase/

New Phishing Kit Uses AI to Fully Automate Vishing Attacks

A new phishing kit is using generative AI to fully automate voice phishing (vishing) attacks, according to researchers at Group-IB. The phishing platform, called "Balonx," includes a module dubbed "CallFlow" that the researchers say "represents a fundamental evolution" in the phishing-as-a-service market.

This module uses four commercial AI services to conduct the attacks: OpenAI's GPT-4o-mini, ElevenLabs's AI voice generator, OpenAI Voice and OpenAI Whisper.

"When CallFlow contacts a victim, the conversation is conducted entirely by the LLM speaking through the synthetic voice of a fabricated bank rep named Carolina (the ElevenLabs voice profile)," Group-IB says. "The victim's spoken responses are transcribed in real time by OpenAI Whisper, which feeds the transcript back to GPT-4o-mini to generate contextually appropriate follow-up responses.

"The interaction is indistinguishable from a human call-center operator to most victims." The Balonx phishing platform also allows human operators to monitor the attacks in real time, so they can step in if the AI runs into problems.

"The administrative interface of the CallFlow panel displays an operational dashboard showing active calls, daily call volume, success rates, calls in queue, active campaigns, total phone records in the database and average call duration," Group-IB says.

"Investigation of the panel revealed targeted campaigns for several banks alongside a database of telephone numbers specifically related to one bank brand account, suggesting this database serves as a primary call list for the automated vishing system."

Balonx is currently targeting users in Mexico, but Group-IB expects this AI-driven vishing model to go global very soon. "Vishing attacks have historically been limited by the availability of human operators," the researchers write.

"The CallFlow module eliminates that constraint entirely, enabling a single operator to run hundreds of simultaneous fraudulent calls without any human involvement in the conversation itself. As this architecture matures and spreads through criminal networks, financial institutions will face vishing attacks of unprecedented scale and linguistic quality."

One more thing. The workforce changed. Half of it doesn't have a badge.
KnowBe4 empowers all of it; The people and the agents working alongside them.
KnowBe4 empowers the digital workforce, humans and AI agents.

Group-IB has the story:
https://www.group-ib.com/blog/balonx-sistema-mexico-phaas/

What KnowBe4 Customers Say

"Bryan, Thank you for your follow-up. I appreciate you reaching out to see how our journey with KnowBe4 is going.

"Overall, we are off to an excellent start. We completed our first quarterly training campaign in June and achieved a 99% on-time completion rate. Our associates gave the courses an average rating of 4.8, with more than 45% providing feedback.

"Our CSM, Valentina has been a wonderful resource for us. She is knowledgeable and has been very responsive throughout our launch.

"Again, I appreciate your outreach, and we feel that KnowBe4 is an excellent SAT platform that will continue to meet our needs."

- O.J. – Information Security Program Manager

The 10 Interesting News Items This Week
  1. Ukraine to give Britain access to battlefield data to train AI:
    https://therecord.media/ukraine-uk-ai-drone-data

  2. FBI disrupts proxy network enabling Chinese espionage operations:
    https://www.bleepingcomputer.com/news/security/fbi-disrupts-proxy-network-enabling-chinese-espionage-operations/

  3. EU officials were targeted on WhatsApp, an internal document show:
    https://thenextweb.com/news/eu-officials-whatsapp-spearphishing-deepseek-chinese-hackers

  4. Fake Grand Theft Auto 6 demo delivers malware:
    https://allaboutcookies.org/fake-gta-6-demo-malware-steals-passwords

  5. Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects:
    https://www.infosecurity-magazine.com/news/interpol-operation-jackal-iv/

  6. Australia arrests alleged TeamPCP hackers behind supply-chain attacks:
    https://www.bleepingcomputer.com/news/security/australia-arrests-alleged-teampcp-hackers-behind-supply-chain-attacks/

  7. [Exclusive] NSA to host a hacker reunion in bid to rebuild secretive TAO unit:
    https://therecord.media/nsa-to-host-hacker-reunion-in-bid-to-rebuild-secretive-unit

  8. Nearly 700 rogue AI agents coordinated in the Hugging Face attack:
    https://www.bleepingcomputer.com/news/security/nearly-700-rogue-ai-agents-coordinated-in-the-hugging-face-attack/

  9. New phishing kit uses social engineering to unlock stolen iPhones:
    https://socradar.io/blog/anonymouskit-ai-phaas-supply-chain/

  10. Tech support scammers post listings on trusted websites:
    https://www.malwarebytes.com/blog/scams/2026/08/fake-listings-can-turn-trusted-platforms-into-scam-springboards

Cyberheist 'Fave' Links
This Week's Links We Like, Tips, Hints and Fun Stuff

Topics: Cybercrime

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, email and collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.