eCommerceNews Australia - Technology news for digital commerce decision-makers
Australia
Business email compromise tops LevelBlue cyber incidents

Business email compromise tops LevelBlue cyber incidents

Fri, 24th Jul 2026 (Yesterday)
Mark Tarre
MARK TARRE News Chief

LevelBlue has released its Q2 2026 Tactics, Techniques and Procedures Briefing, which found that business email compromise remained the most common cyber incident investigated.

The findings point to a shift in attacker behaviour away from traditional break-in methods and toward the use of compromised identities, session tokens, and machine credentials. Threat actors are increasingly exploiting accounts and integrations that organisations already trust, allowing them to move through systems with less chance of detection.

Based on incident response investigations carried out between April and June, business email compromise accounted for 45 per cent of incidents. In every business email compromise case where multi-factor authentication had been deployed, attackers were still able to bypass it.

Cloud intrusion ranked as the third most common incident type during the period. Attackers were also making wider use of OAuth tokens, application programming interface keys, and machine identities to gain access to cloud environments.

Identity focus

The report identifies identity as a central point of weakness for many organisations. Rather than relying only on malware or direct attacks on network perimeters, threat actors are using stolen credentials and trusted connections to gain persistence and expand access.

Devon Ackerman, Global Services Leader, Digital Forensics and Incident Response, LevelBlue, said: "Attackers are spending less time trying to break in and more time using identities organisations already trust. Once they have a valid account, session token or machine identity, they can often move through an environment without raising suspicion."

He said this requires a broader security approach beyond network-focused controls. "Traditional security controls remain important; however, organisations also need visibility into how identities and APIs are being used across their environments. Monitoring privileged access, cloud identities, and trusted integrations with third parties is becoming just as important as protecting the network perimeter."

Entry methods

Phishing and social engineering remained the leading route for initial access, accounting for 65 per cent of intrusion vectors in the cases reviewed. External remote services made up 9 per cent, while valid accounts accounted for 7 per cent.

The briefing also noted a return of ClickFix campaigns, in which fake CAPTCHA tests and fabricated error prompts are used to persuade users to run malicious commands. The technique reflects a wider pattern in which attackers rely on deception and user action rather than more visible technical exploits.

Software supply chain attacks also continued to evolve during the quarter. Instead of targeting a victim directly, attackers increasingly focused on third-party software relationships and connected services, particularly those linked through OAuth applications, API keys, and machine identities.

LevelBlue cited the compromise of market intelligence platform Klue as an example of how one trusted integration can create downstream risk for several organisations. Such incidents show how a single weak point in a connected environment can open access well beyond the original target.

Faster attacks

The data also suggests that attackers are reaching their objectives more quickly once they gain entry. Incidents resolved within three to 10 days rose to 42 per cent in the second quarter, up from 23 per cent in the first quarter.

By contrast, incidents lasting longer than 31 days fell to 23 per cent from 38 per cent in the previous quarter. That shift indicates a narrower window for security teams to identify unusual behaviour and contain activity before damage spreads.

Financial services remained the most targeted industry in the quarter, followed by education and research, and legal and professional services. Those sectors often hold sensitive financial, intellectual property, or client data, making them frequent targets for identity-led intrusions and fraud attempts.

The briefing also drew on intelligence from SpiderLabs, expanding visibility into current threat activity. Combined with frontline investigations, the report offers a picture of an environment in which trust itself has become a key attack surface.

The figures suggest that many of the tools designed to improve efficiency and connectivity, including cloud services and third-party integrations, are also creating more pathways for misuse when identity controls fail.