All Posts
Cyber Threat Intelligence
Operationalized Threat Intelligence
1
min read

Seven Controls That Would Have Stopped This Quarter's Biggest Breaches — And Why Most Orgs Still Lack Them

Published on
September 3, 2026
Table of Contents

July 2026 recorded 799 confirmed ransomware attacks, a 19% month-on-month increase, with financial services absorbing a 71% spike in that single month alone [1]. The NAIC's PeopleSoft systems were breached as part of what appears to be a broader campaign targeting that platform [2]. Nissan disclosed employee data was compromised through an Oracle zero-day [3]. A supply chain worm propagated across 444 npm packages, reaching a combined 2 billion monthly installs before defenders caught it [4]. These are not isolated failures. They share the same three gaps: unpatched internet-facing infrastructure, no supply chain integrity controls, and identity abuse going undetected.

The speed problem compounds all of it. A 2026 adversary tracking report puts average eCrime breakout time at 29 minutes, with the fastest recorded case at 27 seconds [5]. Global median dwell time, meanwhile, rose to 14 days in 2025, driven by actors operating from unmonitored edge devices [6]. Defenders have 14 days on average to find an intruder who can move laterally in under 30 minutes from first access. That asymmetry is the operating environment for Q3.

Here are the seven controls the evidence says would have changed the outcome.

Control 1: Phishing-Resistant MFA

Credential theft remains the preferred entry point. Voice phishing surged to the second most common initial access vector in 2025 at 11% of investigated incidents, behind only exploits at 32% [6]. The migration away from email phishing (down from 14% to 6% year-over-year) reflects attacker adaptation, not reduced volume [6]. SMS and time-based one-time password (TOTP) MFA fail against device code phishing and real-time proxy attacks. In 2025, 67% of organizations experienced at least one successful account takeover, and 59% of those compromised accounts had MFA enabled [7]. The MFA was present; it was the wrong kind. The New York State Department of Financial Services (NYDFS) made the same diagnosis in May 2026, recommending "phishing-resistant MFA methods such as authenticator applications with number matching or hardware tokens" [8]. FIDO2 hardware tokens and passkeys are operationally deployable now. The question is priority, not feasibility.

Control 2: Identity Threat Detection and Response (ITDR)

82% of detections in 2025 were malware-free, up from 51% in 2020 [5]. Endpoint antivirus is therefore blind to most intrusions. Attackers are using valid credentials, remote monitoring and management (RMM) tools, and built-in system utilities, none of which generate traditional malware signatures. Huntress documented a campaign that used a fake Bank of America email to install an RMM tool and operate undetected through legitimate remote access channels [9]. Identity threat detection and response (ITDR) closes this gap by monitoring authentication infrastructure, detecting impossible travel, token abuse, and privilege escalation that endpoint controls never see. Valid account abuse accounted for 35% of cloud incidents in 2025 [5]. No endpoint agent catches a stolen token used from a known cloud provider IP.

Control 3: Immutable, Segmented Backup Architecture

Ransomware operators have explicitly retargeted recovery. A 2026 incident response report stated directly: "Ransomware operators have shifted their primary objective from data theft to deliberate recovery denial, systematically targeting backup infrastructure, identity services, and virtualization management planes." [6] INC Ransom, tracked this quarter, uses Veeam credential dumping for backup destruction prior to encryption [1]. Flat backup environments connected to the production domain are co-encrypted. The operative control is immutable off-network backups with tested restore procedures. NYDFS made this concrete in May 2026: entities "should test the integrity, immutability, and restorability of backups, including validation of recovery time objectives." [8] Tested means the restore was executed, not scheduled. Most organizations conflate backup existence with recovery capability.

Control 4: AI Application Inventory and Prompt Governance

The average organization runs 10 AI applications per month, many outside formal approval processes [10]. High-risk generative AI prompts doubled over the past year within enterprise environments [10]. This is an uncontrolled data exfiltration surface. The "Bissa Scanner" campaign stole AI credentials from more than 30,000 exposed .env files, with AI accounts representing the most stolen credential type in that operation [10]. Shadow AI creates two compounding risks: sensitive data entered into unapproved external models, and AI credentials becoming high-value theft targets. The control is a formal AI application inventory, data loss prevention (DLP) policies applied to AI traffic, and prompt governance that classifies what data can enter which tools. This is not speculative future-state work. It is a current gap with current exploitation.

Control 5: Third-Party Access Governance

The NAIC breach was described as part of a broader campaign targeting PeopleSoft users [2]. Third-party access and shared platforms create correlated exposure. NYDFS issued prescriptive third-party service provider (TPSP) guidance in October 2025, stating explicitly that "covered entities may not delegate responsibility for compliance with the Cybersecurity Regulation to an affiliate or a TPSP" [11]. The same regulator fined PayPal $2 million in January 2025, the first enforcement action under the revised Part 500, after a misclassified system change bypassed mandatory security reviews and enabled credential stuffing to expose Social Security Numbers [12]. The pattern is consistent: vendor access reviewed at onboarding but not continuously monitored, contracts lacking breach notification requirements, and offboarding that leaves access tokens active. NYDFS signaled in both October 2025 and May 2026 guidance that TPSP deficiencies will be examined and enforced [8], [11]. For regulated entities, this is no longer discretionary.

Control 6: Continuous Vulnerability Management on Edge Devices

Cyber espionage actors operated with a 122-day median dwell time in 2025, exploiting unmonitored edge devices as persistent footholds [6]. Zero-day exploitation prior to public disclosure increased 42% year-over-year [5]. The Nissan breach exploited an Oracle zero-day [3]; the NAIC incident compromised PeopleSoft in what appears to be a coordinated campaign against that platform [2]. CVE-2025-31324 in SAP NetWeaver and CVE-2025-61882 in Oracle EBS were among the top exploited vulnerabilities in 2025 incident response investigations [6]. The math is simple: a 122-day espionage dwell time against an adversary who can establish a foothold in 27 seconds [5] means that periodic patch cycles are structurally incompatible with current threat tempo. Continuous vulnerability scanning on internet-facing assets, with defined SLAs tied to CISA's Known Exploited Vulnerabilities (KEV) catalog, is the minimum viable response [13].

Control 7: AI-Augmented Detection Engineering

74% of cybersecurity teams report AI is already changing team size and role structures [14]. The skills gap now dominates workforce concerns at 60%, a 20-percentage-point differential over headcount shortages [14]. Expert and senior roles represent 72% of reported recruitment difficulties, and 55% of senior hires take 6 months or longer to fill [14]. Detection coverage cannot scale through headcount alone under those conditions. AI-assisted rule generation, triage automation, and detection tuning are compensating controls for the skills gap, not future options. The same threat research that documents 89% year-over-year increases in AI-enabled attacks [5] also shows attackers using AI to iterate tools faster than human developers can respond [15]. Detection engineering that relies entirely on manual analyst output is already outpaced.

Why Most Orgs Still Lack These Controls

The structural explanation has three components. First, the skills gap is real and documented: only 38% of organizations provide comprehensive AI security training despite 54% reporting governance policies exist [14]. The policies exist on paper; the capability to implement them does not. Second, AI-enabled attack volume increased 89% year-over-year [5], compressing the window between vulnerability disclosure and active exploitation. Third, internet crime losses exceeded $16 billion in 2024, a 33% year-over-year increase, with phishing, extortion, and personal data breaches as the top complaint categories [16]. The losses are accumulating faster than control implementation.

Tool sprawl adds operational drag. Organizations with 50-plus security tools often have coverage gaps precisely because integration and tuning require the senior analysts they cannot hire. The result is controls that exist in procurement records but not in active detection coverage.

What to Do This Quarter

Sequence matters. Phishing-resistant MFA and backup immutability are the highest-leverage starting points because credential theft and recovery denial appear in the majority of ransomware chains tracked this quarter [1], [6]. Both are implementable without multi-year programs. ITDR and continuous edge device scanning address the 82% malware-free detection problem and the 122-day espionage dwell time, respectively [5], [6]. They require tooling investment but no new architecture.

AI application inventory and third-party access governance are urgent specifically for financial services. NYDFS's May 2026 guidance explicitly cites geopolitical events and frontier AI model releases as triggers for heightened threat environments requiring stronger defensive measures [8]. That language functions as an enforcement signal. Regulated entities should treat the NYDFS guidance as the forcing function it is designed to be, not as advisory reading.

AI-augmented detection engineering is the longest-lead item but cannot be deferred indefinitely. A 2026 workforce survey found only 17% of organizations have a comprehensive AI security and governance framework [14]. Building detection capability on a foundation of manual analyst output, against adversaries iterating with AI tools, is not a stable equilibrium. The quarter's breach record makes that plain.

References

  1. Comparitech, "Ransomware July 2026: 799 Attacks, Finance Up 71%, 146 Active Groups," 2026-08. [Online]. Available: https://www.comparitech.com/news/ransomware-roundup-july-2026/ [Accessed 03 Sep. 2026].
  2. National Association of Insurance Commissioners (NAIC), "An Important Update on the NAIC's Security Incident," National Association of Insurance Commissioners (NAIC), 2026-06-17. [Online]. Available: https://content.naic.org/about/security-update [Accessed 2026-08-18].
  3. California Office of the Attorney General (OAG), "Data Breach Report sb24-625558 – Nissan," California Office of the Attorney General, 2024. [Online]. Available: https://oag.ca.gov/ecrime/databreach/reports/sb24-625558 [Accessed 2025].
  4. Aikido, "Keyv and friends compromised in active Shai-Hulud supply chain attack," 2026-08-04. [Online]. Available: https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack [Accessed 03 Sep. 2026].
  5. CrowdStrike, "CrowdStrike 2026 Global Threat Report: Year of the Evasive Adversary," CrowdStrike, 2026. [Online]. Available: https://www.crowdstrike.com/en-us/global-threat-report/ [Accessed 03 Sep. 2026].
  6. Mandiant / Google Threat Intelligence Group (GTIG), "Special Report: M-Trends 2026," Mandiant, 2026. [Online]. Available: https://cloud.google.com/security/resources/m-trends [Accessed 03 Sep. 2026].
  7. Proofpoint, Inc., "2026 AI-Era Ransomware Report," 2026-04-01. [Online]. Available: https://www.proofpoint.com/us/resources/threat-reports/ai-era-ransomware-report [Accessed 03 Sep. 2026].
  8. New York State Department of Financial Services (NYSDFS), "Industry Letter: Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment," New York State Department of Financial Services, May 21, 2026. [Online]. Available: https://www.dfs.ny.gov/industry-guidance/industry-letters/20260521-guidance-on-measures-reg-entities-should-consider-in-a-hcte [Accessed 2026].
  9. Huntress, "Bank Spam and RMM: A Phishing Campaign Leveraging Remote Monitoring and Management Tools," Huntress, UNKNOWN. [Online]. Available: https://www.huntress.com/blog/bank-spam-rmm [Accessed 2025].
  10. Check Point Research, "AI Security Report 2026," Check Point Research, 2026. [Online]. Available: https://pages.checkpoint.com/ai-security-report-2026.html [Accessed 03 Sep. 2026].
  11. New York State Department of Financial Services (NYDFS), "Industry Letter: Guidance on Managing Risks Related to Third-Party Service Providers," New York State Department of Financial Services, 21-Oct-2025. [Online]. Available: https://www.dfs.ny.gov/reports_and_publications/press_releases/pr20251014 [Accessed 2025].
  12. Frankfurt Kurnit Klein & Selz (Technology Law Blog), "Consent Order: In the Matter of PayPal, Inc.," New York State Department of Financial Services, 2025-01-23. [Online]. Available: https://www.dfs.ny.gov/system/files/documents/2026/07/ea20250123-paypal-inc.pdf [Accessed 03 Sep. 2026].
  13. CISA (Cybersecurity & Infrastructure Security Agency), "CISA Adds Five Known Exploited Vulnerabilities to Catalog," Cybersecurity & Infrastructure Security Agency, March 20, 2026. [Online]. Available: https://www.cisa.gov/news-events/alerts/2026/03/20/cisa-adds-five-known-exploited-vulnerabilities-catalog [Accessed 2026].
  14. SANS | GIAC, "2026 Cybersecurity Workforce Research Report: The Evolving Cyber Workforce: AI, Compliance, and the Battle for Talent," SANS Institute / GIAC, 2026. [Online]. Available: https://www.sans.org/white-papers/2026-cybersecurity-workforce-research/ [Accessed 03 Sep. 2026].
  15. ReliaQuest, "Ransomware and Cyber Extortion in Q2 2026," 2026-Q2. [Online]. Available: https://reliaquest.com/blog/threat-spotlight-ransomware-and-cyber-extortion-in-q2-2026/ [Accessed 03 Sep. 2026].
  16. Federal Bureau of Investigation (FBI), "FBI Releases Annual Internet Crime Report," FBI National Press Office, 23-Apr-2025. [Online]. Available: https://www.fbi.gov/news/press-releases/fbi-releases-annual-internet-crime-report [Accessed 2025].

How Anomali Can Help

The seven controls highlighted in these breaches map directly to unified telemetry, pre-built detections, and vulnerability prioritization through curated threat feeds.

  • Anomali's Unified Security Data Lake normalises telemetry across cloud, endpoint, network, and identity, providing the correlated visibility needed to detect the attack patterns described in this article without vendor lock-in.
  • Anomali provides out-of-the-box detections aligned to MITRE ATT&CK, covering the TTPs described above so teams can deploy coverage for these techniques without writing rules from scratch.
  • Anomali's vulnerability prioritisation intelligence maps CVEs like those described above to known exploitation activity, helping teams prioritise the patches that matter most before adversaries exploit them.

Does your current stack provide the seven breach-stopping controls described above?

Talk to Anomali.

FEATURED RESOURCES

September 3, 2026
Cyber Threat Intelligence
Operationalized Threat Intelligence

Seven Controls That Would Have Stopped This Quarter's Biggest Breaches — And Why Most Orgs Still Lack Them

Read More
September 1, 2026
Anomali Cyber Watch

Anomali Cyber Watch: SLEEPWALKER Passive Backdoor, GPUThor Attack Bypasses NVIDIA, Enabling Privilege Escalation and DoS; Fire Ant, TACACS Credential Harvester and more

SLEEPWALKER Passive Backdoor Uses Custom Bytecode Language and Six Covert Transports; GPUThor: Non-Uniform Rowhammer Attack Bypasses ECC on NVIDIA GPUs, Enabling Privilege Escalation and DoS; Fire Ant Pivots to Trusted Infrastructure, Deploying Router Implants and TACACS Credential Harvester; Stolen Claude Sessions Let Attackers Bypass Passwords and Two-Factor Authentication; WordlistLoader and SynkLoader Combine Social Engineering With Defense Evasion; SharePoint Authentication Bypass and RCE Flaws Chained for Unauthenticated Code Execution
Read More
August 27, 2025
Cyber Threat Intelligence
Operationalized Threat Intelligence

Chinese-Made Components in Military Drones: What the MoD Data Breach Near-Miss Reveals About Hardware Supply Chain Risk

Royal Navy K3 Scout cameras signaled a Chinese IP despite passing NDAA checks. Why hardware supply chain risk hides below tier-1 compliance.
Read More
Explore All