SOC Insights Q1 2026: Identity Attacks, QR Code Phishing and the Latest Cyber Threat Trends

Executive Summary

Every quarter, MTI’s UK-based Security Operations Centre (SOC) investigates thousands of security alerts across public and private sector organisations.

While many attacks are successfully blocked before causing harm, the data provides valuable insight into how cyber threats are evolving and where organisations remain vulnerable.

This report analyses activity between 1 March and 1 June 2026. During this period, MTI’s SOC investigated 1,786 incidents, including 154 high-priority cases, revealing that identity, email and web-delivered threats remain the most common drivers of analyst review.

The majority of incidents were ultimately classified as benign positive or false positive. This is expected in a managed SOC environment, where broad detection coverage is designed to maximise visibility while skilled analysts determine whether activity is malicious, expected, misconfigured or already contained.

Across confirmed true positive incidents, several themes emerged. Phishing remained a recurring initial access vector, while threat intelligence and indicator-based detections repeatedly identified suspicious domains, compromised websites, and infrastructure associated with malware, command-and-control activity and botnets. Identity-related events, including failed authentication attempts, service principal activity, forwarding rules and suspected credential abuse, continued to require rapid correlation across sign-in, endpoint, email and network telemetry.

This quarter also reinforced the importance of distinguishing prevented activity from confirmed compromise. Several true positive detections had already been quarantined, blocked or remediated by existing security controls before wider impact occurred. These investigations demonstrate the value of skilled analyst triage, effective containment processes and timely incident response in reducing organisational risk.

MTI SOC Activity Snapshot

Period: 01 March 2026 – 01 June 2026 

Incidents Investigated – 1,786

High-Priority Incidents – 154

True Positive Incidents – 41

Benign Positive Closures – 944

False Positive Closures – 792

Most Common MITRE ATT&CK Techniques Observed Across the Investigation Dataset:

  • Valid Accounts (T1078)
  • Application Layer Protocol (T1071)
  • Account Manipulation (T1098)
  • Phishing (T1566)
  • Brute Force (T1110)
  • Automated Exfiltration (T1020)

All observations in this report are derived from aggregated investigations conducted by MTI’s Security Operations Centre. No individual customer environment is disclosed.

Key Findings from SOC Investigations

1. Identity-based activity remains a dominant investigation theme

Valid Accounts (T1078), Account Manipulation (T1098), Brute Force (T1110), and MFA-related activity appeared repeatedly, showing that attackers and suspicious access patterns continue to target identity as a primary route into cloud services.

2. Phishing continues to generate confirmed threat activity 

User-reported phishing, malicious URL clicks, campaign remediation alerts, spoofed sender detections, and QR-code themed email activity were all observed during the reporting period.

3. Threat intelligence detections remain valuable but require careful validation

Indicator matches against DNS, proxy, firewall, file hash, and endpoint events helped identify suspicious infrastructure, but analysts still needed to confirm whether connections were blocked, sinkholed, expected, or associated with active compromise.

4. Web compromise and fake verification lures are increasingly relevant

SOC investigations included suspicious web traffic linked to compromised sites, fake CAPTCHA-style lures, PDF conversion/download activity, and suspicious domains. These attacks rely heavily on user interaction rather than complex exploitation.

5. Prevented activity still requires investigation

Multiple confirmed incidents involved files quarantined by endpoint controls, URLs blocked by network controls, or emails removed after delivery. These outcomes reduce impact, but they still require triage to confirm scope, root cause, and residual risk.

6. Recurring detections creating tuning and reporting opportunities

High-volume recurring alert patterns, including spoofed sender and threshold-based detections, show the need for continuous tuning so that detection logic remains effective without overwhelming analysts or customers.

Organisations should also review whether Multi-Factor Authentication (MFA) alone provides sufficient protection against modern identity attacks. As discussed in our recent article on Continuous Access Evaluation (CAE), attackers are increasingly targeting session tokens rather than passwords, allowing them to bypass traditional authentication controls. Strengthening identity security therefore requires continuous session validation alongside robust MFA and Conditional Access policies.

Attack Pattern Observed Across Investigations

Across multiple incidents investigated this quarter, MTI SOC observed a recurring pattern involving user interaction, suspicious infrastructure, and identity validation. The stages below represent the common operational flow seen across the dataset rather than a single incident chain.

Stage 1 – Phishing, QR Codes, and User Interaction

What we observed 

Several investigations originated from suspicious email activity, including user-reported phishing, campaign remediation alerts, spoofed sender detections, malicious URL clicks, and QR-code themed messages. Some emails attempted to move users away from protected email controls by encouraging interaction with external websites or personal-device workflows.

Phishing themes observed included:

  • Document sharing and invoice-style messages
  • Delivery or tracking-themed lures
  • Spoofed or lookalike sender activity
  • QR-code-based phishing designed to move the user to a mobile device
  • Fake verification or CAPTCHA-style web prompts.

Why this matters

Phishing remains effective because it targets user trust, not just technical weakness. QR-code and fake verification techniques are particularly challenging because they can move the attack path outside traditional attachment and URL inspection workflows.

Stage 2 – Suspicious Web Traffic and Indicator-Based Detections

What we observed

A significant proportion of confirmed true positive activity involved threat intelligence or indicator-based detections across DNS, proxy, firewall, file hash, and endpoint telemetry. Analysts reviewed suspicious domains, compromised websites, botnet indicators, malware infrastructure, and command-and-control-style network events.

Examples of observed patterns included:

  • Blocked connections to known malicious or suspicious domains
  • Web proxy traffic to domains associated with command-and-control or malware activity
  • DNS events linked to suspicious scripts or compromised websites
  • File hash detections where files were quarantined as a precaution
  • Malicious or suspicious download pathways involving conversion tools or untrusted web services.

Why this matters

Indicator-based detections are valuable for identifying known-bad infrastructure, but they require context. A connection attempt may be blocked, sinkholed, or generated by a compromised website rather than an actively compromised endpoint. Effective investigation depends on correlating network, endpoint, identity, and user activity to determine impact.

Stage 3 – Identity Validation and Credential Abuse Risk

What we observed

The dataset included repeated investigation of identity-based alerts, including failed sign-ins, impossible travel, authentication method changes, service principal activity, forwarding rule creation, privileged account changes, and suspected Kerberos-related activity. Many of these were closed as benign after validation, but confirmed incidents show that identity telemetry remains one of the most important sources for early detection.

Analysts commonly validated:

  • Whether sign-in attempts came from known locations, VPN services, or expected travel
  • Whether authentication method changes were user-approved or administrative activity
  • Whether service principal access was expected for the application involved
  • Whether email forwarding rules had legitimate business justification
  • Whether suspicious endpoint or network events were followed by abnormal sign-in behaviour.

Why this matters

Once attackers obtain valid credentials or tokens, their activity can resemble legitimate user behaviour. Detecting and responding to identity compromise requires strong logging, conditional access, behavioural analytics, and the ability to take rapid containment actions such as session revocation, password reset, MFA re-registration, and mailbox rule removal.

SOC Analyst Perspective

From an operational standpoint, this quarter reinforces that SOC value is not measured only by the number of confirmed malicious incidents. The value is in the disciplined triage process that separates blocked activity, benign administrative actions, false positive indicators, misconfigurations, suspicious-but-contained events, and genuine compromise.

The highest operational risk continues to sit at the intersection of email, identity, endpoint, and web telemetry. A suspicious email alone may not prove compromise. A malicious URL click alone may be blocked. A failed sign-in alone may be noise. However, when these signals occur together, they can indicate a developing intrusion chain.

This is why mature SOC monitoring must correlate activity across multiple telemetry sources. The same investigation may require review of Microsoft Defender alerts, Sentinel incidents, firewall or proxy logs, email remediation events, endpoint detections, sign-in logs, and customer context.

Emerging Threat Trends to Watch

Based on patterns emerging across the SOC dataset and wider threat reporting, MTI SOC analysts are closely monitoring the following developments.

1. QR-code Phishing and Email-to-Mobile Attack Paths

Microsoft reported QR-code phishing as the fastest-growing email attack vector in Q1 2026. This aligns with SOC observations where QR-code themed phishing and URL-based lures required investigation.

2. Fake CAPTCHA and ClickFix-Style Social Engineering

Fake CAPTCHA and ClickFix-style attacks continue to evolve. These lures persuade users to complete steps that execute attacker commands or download payloads, reducing reliance on traditional exploit delivery.

3. Credential and Token Theft Ecosystems

Identity remains a high-value target. Infostealers, phishing kits, adversary-in-the-middle tooling, and session token theft continue to reduce the effectiveness of password-only controls.

4. Service Principal and Application Identity Abuse 

Browser extensions, SaaS integrations, and unapproved applications introduce additional opportunities for compromise when not properly governed. 

5. Exposure of Externally Reachable Services

Publicly exposed services and internet-facing infrastructure continue to create avoidable risk where patching, access control, and attack surface management are not tightly governed.

6. Vulnerability-Driven Exploitation of Linux and Infrastructure Platforms

CVE-2026-31431, known as Copy Fail, was observed in reporting during the period and reinforces the need to monitor high-impact vulnerability detections, even where activity is ultimately confirmed as authorised testing or blocked execution.

Security Recommendations

Based on the patterns observed across SOC investigations, organisations should prioritise the following defensive measures.

Strengthen phishing, QR-code, and URL protection

  • Apply advanced email filtering, Safe Links, Safe Attachments, impersonation protection, and post-delivery remediation where licensing allows.
  • Include QR-code phishing, fake CAPTCHA lures, and browser-based social engineering in user awareness and phishing simulation programmes.
  • Restrict access to newly registered, uncategorised, and low-reputation domains where business impact is acceptable.

Improve identity detection and response capability

  • Enforce phishing-resistant MFA for privileged and high-risk users where possible.
  • Monitor for impossible travel, unfamiliar locations, risky sign-ins, password spray, authentication method changes, and service principal anomalies.
  • Pre-approve rapid response actions such as session revocation, password reset, MFA re-registration, disabling accounts, and mailbox rule removal.

Govern browser, download, and application behaviour

  • Implement centralised browser management using Microsoft Edge, Chrome Enterprise, or equivalent controls.
  • Restrict unauthorised extensions and prevent users from installing alternative browsers that bypass policy.
  • Control downloads from untrusted websites and block execution from high-risk paths using endpoint controls and attack surface reduction rules.

Operationalise threat intelligence with context

  • Continue using threat intelligence to enrich DNS, proxy, firewall, endpoint, and file hash detections.
  • Tune high-volume indicators and recurring detections so analyst review remains focused on material risk.
  • Use sandboxing, reputation checks, endpoint history, and user context before classifying activity as compromise.

Reduce externally exposed attack surface

  • Review internet-exposed services and remove unnecessary public access.
  • Prioritise remediation of externally reachable systems with known exploited or high-impact vulnerabilities.
  • Ensure vulnerability management, asset management, and SOC detection processes share a consistent view of critical assets.

The Value of SOC Visibility

Operating a mature Security Operations Centre provides organisations with more than alert monitoring. It provides continuous visibility into how attacks develop across real environments and how controls perform under pressure.

Through its 24/7/365 UK-based SOC, MTI investigates high volumes of security alerts and incidents across regulated and commercial sectors. This operational visibility allows analysts to identify attacker behaviours, recurring detection gaps, and customer-specific risks that may not be visible from isolated tooling alone.

The March to June 2026 dataset shows the importance of full investigation ownership. Analysts validated suspicious activity, confirmed blocked or remediated events, identified true positive incidents, escalated customer action where required, and captured tuning opportunities to reduce future noise.

The result is faster triage, clearer security visibility, improved detection maturity, and stronger operational resilience over time.

Conclusion

The incidents investigated by MTI’s SOC between March and June 2026 highlight a consistent direction in the threat landscape. Attackers continue to rely on phishing, suspicious web infrastructure, credential abuse, and legitimate cloud access patterns to gain or attempt access to organisational environments.

At the same time, the dataset demonstrates the value of layered controls. Many true positive incidents were blocked, quarantined, removed, or contained before wider impact occurred. Effective defence therefore depends on both preventive technology and mature SOC investigation.

For organisations, the priority should be to strengthen identity controls, improve phishing and web protection, govern browsers and downloads, reduce public exposure, and maintain continuous monitoring across endpoint, identity, email, and network telemetry.

How Mature is Your Security Monitoring?

Every organisation generates thousands of security events every day, but not every organisation has the people, processes and visibility needed to distinguish genuine threats from background noise.

If you’d like to understand how your organisation’s monitoring capability compares with industry best practice, speak to MTI’s cyber security specialists.

About The Author

Josh King is a cyber security leader at MTI with more than twelve years’ experience across managed services, security operations, and cyber defence As head of MTI’s UK Security Operations Centre (SOC), he leads teams responsible for protecting organisations against an increasingly complex threat landscape. Combining deep technical expertise with hands-on leadership, Josh helps organisations strengthen their cyber resilience through proactive threat detection, incident response, and security best practices.