TL;DR
- Identity attacks jumped back up to 68.1% of Expel SOC incidents in Q2 2026, reversing the dip we saw last quarter
- Endpoint incidents dropped to 29.8% overall, but targeted attacks spiked in June, driven almost entirely by Microsoft Teams phishing
- The rate of identity attacks not being stopped by existing security controls crossed 50% in both May and June, with instances where malicious activity occurred ticking up month over month
Q2 2026 incident overview: identity, endpoint, and cloud
In Q2 2026 (April–June), identity was the top attack surface again for Expel’s SOC. 68.1% of the incidents Expel investigated targeted identity, up from 58.7% in Q1 2026. Endpoint incidents dropped to 29.8% of total incidents, down from 38.4% last quarter. Cloud infrastructure incidents held steady at 2.1% of the total.
After a few quarters of endpoint incidents climbing and identity incidents easing off, Q2 2026 snapped back to the older pattern of identity-led attacks.
Rates of attacker success against identities in Q2 2026
Throughout the quarter, we observed that the chances as to whether an attacker to be blocked from accessing an account were nearly even. 51.3% of credential attacks in Q2 2026 were blocked outright. 40.4% resulted in access with no confirmed malicious activity. 8.3% resulted in access followed by malicious activity.
May and June 2026 both saw the success rates cross 50% of identity incidents, with malicious follow-on activity ticking up month over month.
Why endpoint attacks shifted in Q2 2026: Microsoft Teams phishing
On endpoints, malware still leads at 52.7% of incidents in Q2 2026. The bigger shift is targeted attacks, which jumped from the teens in April and May to 38.4% of endpoint incidents in June. Microsoft Teams phishing drove most of that spike.
Here’s how the attack works: threat actors exploit a default Microsoft Teams setting that lets external organizations message internal users, then impersonate IT support. They either ask the target to install “IT tools” or offer to fix a spam-bombing problem the target didn’t cause. Either way, the payload is a remote access tool, and the goal is ransomware. Expel classifies these as targeted attacks because the actors pick specific organizations and hit them repeatedly, sometimes over several weeks.
How attackers compromised cloud infrastructure in Q2 2026
Cloud infrastructure incidents in Q2 2026 were mostly unauthorized access resulting from misconfigurations and default passwords (48.4%) and exposed cloud secrets (29%). Supply chain incidents spiked to 9.7% of cloud incidents in May 2026, driven by MiniShai Hulud, a newly observed npm/PyPI worm named for its resemblance to the original Shai Hulud attack, though it’s not connected to it. Cloud secrets exposure and unauthorized access both remain elevated compared to earlier 2026 quarters.
Q2 2026 takeaways for security teams
Identity’s climb doesn’t mean endpoint risk went away, and Teams phishing isn’t a one-off tactic. It’s showing up daily across Expel’s customer base, and it’s worth a dedicated detection and response plan heading into Q3.
For the full historical dataset, see Expel’s quarterly threat intelligence report.
Frequently asked questions
What was the top attack surface in Q2 2026?
Identity was the top attack surface in Q2 2026, accounting for 68.1% of incidents investigated by Expel’s SOC, up from 58.7% in Q1 2026.
How common was Microsoft Teams phishing in Q2 2026?
Microsoft Teams phishing drove most of the jump in targeted endpoint attacks in Q2 2026, which climbed from the teens in April and May to 38.4% of endpoint incidents in June.
What is Mini Shai Hulud?
Mini Shai Hulud is a supply chain worm targeting the npm and PyPI ecosystems, first observed by Expel’s SOC in May 2026. It’s named for its resemblance to the original Shai Hulud supply chain attack but isn’t connected to it.
How did cloud infrastructure attacks change in Q2 2026?
Unauthorized access (48.4%) and exposed cloud secrets (29%) remained the top two cloud infrastructure threats in Q2 2026, while supply chain incidents spiked to 9.7% in May due to the MiniShai Hulud worm.
