Cynet’s 1H 2026 CyOps ECHO Report identifies stolen identities, remote-access gateways and trusted administrative tools as increasingly important elements of cyberattack chains, challenging organisations to strengthen both prevention and recovery capabilities.
The report, based on incidents investigated by Cynet’s CyOps incident response team, found that 80% of host breaches began with a stolen identity. Identity-focused incidents outnumbered host-breach cases by a ratio of 1.6:1, indicating that attackers are increasingly seeking to misuse legitimate access rather than rely primarily on the exploitation of software vulnerabilities.
“Attackers are increasingly shifting away from breaking security controls and focusing on abusing them as designed,” said Mackenzie Brown, vice-president of threat intelligence at Cynet. “With more advanced AI models lowering the barrier to entry for novice adversaries, and increasing the speed for sophisticated threat actors, closing the gap between how fast attackers move and how fast organisations can respond is imperative for security.”
Cynet documented attack chains involving email bombing, impersonation of internal IT or help-desk staff through Microsoft Teams, and the use of remote-support tools including Quick Assist, AnyDesk, ScreenConnect and RemSupp. Victims were persuaded to accept a remote session, after which attackers could deploy payloads, escalate privileges, access credentials and move laterally through the environment.
The report also highlighted token abuse in Microsoft Entra ID environments. In these attacks, a session token can replace the victim’s password, while automated scripts reduce the need for continued human interaction or repeated multifactor authentication prompts.
Although identity was the most common initial access route, SSL-VPN appliances remained among the most damaging. They accounted for 27% of host breaches in Cynet’s incident-response caseload, with attackers in some ransomware cases crossing the network edge before on-host detection signals were generated.
“Threat actors targeting individual users in more sophisticated ways call for security teams to double down on verification and authentication,” said Brown. He recommended phishing-resistant authentication, help-desk verification procedures, user-agent analytics and shorter session-token lifetimes for high-value tenants.
The findings have direct implications for cyber recovery in Asia during 2026 and 2027. INTERPOL recorded more than 135,000 ransomware-related attacks across Asia and the South Pacific in 2024, while system intrusions accounted for approximately 80% of regional data breaches. Malware was present in 83% of breaches and ransomware in 51%.
As identity compromise and abuse of legitimate tools become more prominent, recovery strategies are likely to place greater emphasis on isolating clean copies, validating identities and sessions, hunting for persistence and testing recovery procedures against compromised credentials—not merely restoring systems from backup.
For Asian organisations, this will make continuous identity monitoring, immutable recovery and rehearsed incident response increasingly central to operational resilience.








