IT Brief Canada - Technology news for CIOs & IT decision-makers
Canada
Attackers exploit trusted credentials in email fraud surge

Attackers exploit trusted credentials in email fraud surge

Mon, 27th Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Attackers are increasingly breaching organisations by abusing trusted identities and credentials rather than breaking through perimeter defences, according to LevelBlue's latest incident response briefing. It found business email compromise was the most common incident type.

Business email compromise accounted for 45% of incidents examined during the quarter across LevelBlue's global incident response work.

The findings point to a shift in how attackers gain and maintain access. Rather than relying only on malware or vulnerability exploitation to establish a foothold, threat actors are making greater use of stolen credentials, OAuth tokens, API keys and machine identities that many businesses already trust inside their systems.

That trend was especially visible in email fraud cases. In every business email compromise incident where multi-factor authentication had been deployed, attackers still managed to bypass it.

LevelBlue linked that result to phishing kits that can intercept authenticated session tokens, as well as social engineering methods that persuade users to approve third-party applications. Attackers also increasingly avoid repeated authentication checks by operating through valid tokens, authorised apps and connected services once access has been granted.

Phishing route

Phishing remained the leading initial intrusion vector, accounting for 65% of intrusions in the dataset. External remote services such as remote desktop protocol and virtual private networks ranked second at 9%, while valid accounts and credential abuse made up 7%.

One campaign highlighted in the research was the return of so-called ClickFix social engineering. In these attacks, victims see fake CAPTCHA, Cloudflare or error-fix prompts and are tricked into pasting malicious commands into their own machines. That allows attackers to sidestep some email security filters because the user executes the payload.

Cloud intrusions also rose sharply, becoming the third most common incident type. The increase was driven largely by software supply chain attacks and the misuse of non-human identities tied to vendor integrations and software-as-a-service platforms.

According to the briefing, these incidents can let attackers skip several stages of a conventional network intrusion. By compromising a trusted integration, they can inherit access that places them deep inside a customer environment from the outset, reducing the lateral movement and privilege escalation needed to reach their objective.

Supply chain risk

The report cited the Klue compromise as an example of that pattern. In that incident, compromised API credentials were used to gain unauthorised access to Salesforce-connected integration services and potentially other third-party software services, affecting hundreds of organisations.

LevelBlue said the same model of attack has been seen more broadly in incidents involving OAuth tokens, API keys and service accounts. Because these forms of access often operate without fresh user logins, they can evade controls designed primarily around human authentication.

The briefing also found that commonly exploited vulnerabilities were concentrated in internet-facing edge systems. Eight of the nine most frequently observed vulnerabilities affected perimeter devices, including virtual private network, firewall and security appliances, with several involving authentication bypass or unauthenticated remote code execution.

Among the vulnerabilities listed were flaws affecting Ivanti Endpoint Manager Mobile, Fortinet FortiAnalyser, FortiWeb and FortiOS, a Windows Netlogon vulnerability, and a Cisco ASA remote access issue. The pattern suggests attackers still place high value on tools that can provide valid access to exposed infrastructure.

Faster attacks

Beyond the method of entry, attackers are moving faster once inside. Average dwell time fell compared with the previous quarter, while the proportion of cases resolved within three to 10 days rose from 23% to 42%. The share of incidents lasting 31 days or more fell from 38% to 23%.

That shift may reflect both quicker attacker activity and faster detection by victims and response teams. Even so, shorter dwell times make defence harder because attackers can reach exfiltration or fraud stages before internal teams have time to respond.

Sector data also showed clear business patterns. Financial services remained the most targeted industry at 28% of cases, while education and research rose to 13% and legal and professional services increased to 11%.

By company size, organisations with revenue between USD $1 million and USD $100 million represented the largest share of incidents. The report said this points to continued pressure on mid-market businesses, which attackers may view as valuable targets with fewer resources than larger enterprises.

Other techniques seen repeatedly across incidents included the use of AnyDesk and PsExec for persistence, credential theft tools such as Mimikatz for privilege escalation, and GraphAPI activity during data access and exfiltration. Overall, the quarter's investigations pointed to a threat landscape in which trusted access, rather than brute-force intrusion, is increasingly the route attackers use to get what they want.