• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX GLOBAL
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX GLOBAL
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

Cisco Talos report: Legitimate credentials remain a prime target for cybercriminals

by CXO Staff
September 9, 2025
in Future, News, Tech

Phishing remains the top initial access method, despite a 40 per cent decline from Q1 to Q2

Cisco Talos report: Legitimate credentials remain a prime target for cybercriminals

Cisco Talos’ Q2 2025 report reveals a notable shift in attacker objectives and methods. Although phishing activity declined by 40 per cent compared to Q1, it remained the leading initial access method for threat actors, with most campaigns focused on credential theft. Attackers increasingly relied on compromised internal or trusted business partner email accounts to deliver convincing messages that bypass security measures and gain victims’ trust.

This quarter, 75 per cent of observed phishing attacks originated from compromised internal or trusted business partner email accounts. Many users were tricked into entering their credentials and MFA tokens on sophisticated fake login pages, enabling attackers to steal valuable information for use in further attacks or for sale on underground markets.

Fady Younes, Managing Director for Cybersecurity, Cisco Middle East & Africa
Fady Younes, Managing Director for Cybersecurity, Cisco Middle East & Africa

New ransomware observations

Ransomware was responsible for 50 per cent of all incidents in Q2. Talos IR observed Qilin and Medusa ransomware for the first time, while also responding to previously seen Chaos ransomware.

In its first encounter with Qilin ransomware, Talos documented previously unseen tools and tactics. The Qilin attack began with stolen credentials, followed by lateral movement using remote access tools. Attackers employed a unique encryptor and new exfiltration techniques, including CyberDuck for data theft and Backblaze for command and control. They established persistence by creating automated processes to restart the ransomware after reboots and logins, resulting in extensive system damage and requiring a full rebuild and organisation-wide password resets.

Talos’ analysis further suggests that the Qilin group may be expanding its affiliate network or accelerating its operations.

Attacks using old scripting language

A concerning trend is the use of the outdated PowerShell v1.0 scripting language in a third of ransomware attacks, taking advantage of its lack of security features such as script logging and antivirus integration. Cisco Talos advises organisations to mandate PowerShell 5.0 or higher to mitigate these risks.

Education sector most targeted

The education sector emerged as the most targeted industry globally in Q2 2025, a significant change from the previous quarter. High levels of ransomware activity were also observed in manufacturing, construction, and public administration.

Multi-factor authentication: enable and monitor

Over 40 per cent of the second quarter’s incidents involved MFA issues, such as misconfiguration, absence, or bypass. Cisco Talos recommends enabling and closely monitoring MFA to prevent misuse and strengthen organisational security.

Fady Younes, Managing Director for Cybersecurity at Cisco Middle East, Africa, Türkiye, Romania and CIS, stated, “Cybercriminals are increasingly exploiting trust, whether through compromised partner accounts, misconfigured security tools, or outdated systems. The latest Talos findings underscore that credentials remain a prime target, and organisations must not only enable multi-factor authentication but also continuously validate and monitor its effectiveness. Building cyber resilience requires a proactive approach where people, processes, and technologies work together to minimise risk and strengthen defences against evolving threats.”

Tags: Cisco TalosCybersecurityreport
ShareTweet

Related Posts

FAB appoints Presight to advance AI-driven growth and operational intelligence
Future

FAB appoints Presight to advance AI-driven growth and operational intelligence

December 18, 2025

Presight has signed a contract with First Abu Dhabi Bank (FAB) to deploy advanced artificial intelligence (AI) and data analytics...

Western Digital to showcase high-capacity HDDs and smart video solutions at Intersec 2026
Business

Western Digital to showcase high-capacity HDDs and smart video solutions at Intersec 2026

December 18, 2025

At Intersec 2026 Dubai, Western Digital will showcase its range of high‑capacity hard disk drives (HDDs) and high‑performance storage platforms...

Discussion about this post

Latest Issue

FAB appoints Presight to advance AI-driven growth and operational intelligence

FAB appoints Presight to advance AI-driven growth and operational intelligence

December 18, 2025
Western Digital to showcase high-capacity HDDs and smart video solutions at Intersec 2026

Western Digital to showcase high-capacity HDDs and smart video solutions at Intersec 2026

December 18, 2025
Gartner identifies companies to beat in the ‘AI Vendor Race’

Gartner identifies companies to beat in the ‘AI Vendor Race’

December 18, 2025

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy
© 2025 – CXO Insight Middle East. All Rights Reserved.
Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Videos
  • GITEX GLOBAL
  • Digital Magazine

© 2025 - CXO Insight Middle East. All Rights Reserved.