Unit 42 Global Incident Response Report 2026: What It Means for Houston Businesses
How Attackers Are Using Stolen Credentials and Why It’s Harder to Catch Them – The Breach Window Shrank 75% Last Year, Your Response Plan Didn’t
Palo Alto Networks' Unit 42 spent a year on 750+ real incidents. The attackers were not geniuses - they found soft spots first. Here is what that means for a Houston business running lean.
The most important finding in the Unit 42 2026 report is not that attacks are getting worse - it is that more than nine in ten of them walked through a door the business left open.
Palo Alto Networks' Unit 42 team responded to more than 750 major cyber incidents across every major industry and more than 50 countries, and documented it all in its Global Incident Response Report 2026. The headline is not exotic zero-days or nation-state wizardry. In over 90% of breaches, preventable gaps made the intrusion possible - limited visibility, controls applied inconsistently, and identity systems carrying years of unearned trust. For Houston and Katy businesses running with lean IT or none at all, that is not just an inconvenience; the data says it is a direct liability. Here are the four trends that matter most and what to do about each.
How Is AI Changing the Speed of Attacks?
AI is not making attackers smarter - it is making them faster and more scalable.
The fastest quarter of attacks reached data exfiltration in 72 minutes in 2025, down from 285 minutes a year earlier - a 75% cut in the window you have to detect and respond.
That collapsing timeline is the whole point. Attackers now use AI to write convincing phishing, generate malware scripts, automate reconnaissance, and even run ransom negotiations with no human in the loop - the report documented an unsophisticated actor using an AI chatbot to script a professional extortion demand, deadlines and all. Scanning for newly disclosed vulnerabilities begins within 15 minutes of a CVE announcement, often before defenders have finished reading the advisory, and North Korean operators used AI-generated deepfakes to pass remote-hiring processes at U.S. companies for direct insider access.
Why Is Identity the Attacker's Front Door?
Attackers do not need to break in when they can simply log in.
Identity-based attacks were a factor in nearly 90% of Unit 42 investigations, with 65% of all initial access coming through phishing, stolen credentials, brute force, or misconfigured access.
Identity-based phishing alone tied software vulnerabilities for the top initial-access spot at 22%, and previously compromised credentials - old breach passwords sold on dark-web markets - accounted for another 13%. The deeper problem is identity sprawl. Unit 42 analyzed more than 680,000 cloud identities and found 99% had excessive permissions, many unused for 60 days or more. We see this constantly with Houston businesses that grew quickly or changed vendors without a proper access audit: service accounts never cleaned up, former-employee logins never deactivated, third-party integrations still holding admin access from a project that wrapped two years ago. MFA is the floor, not the ceiling - session-token theft and adversary-in-the-middle attacks bypass it, so identity needs governance, not just a second login step.
How Did Your Vendors Become an Attack Vector?
The apps and integrations connected to your systems carry access you forgot you granted.
SaaS data was involved in 23% of cases in 2025, up from just 6% in 2022, as third-party integrations and forgotten OAuth grants became a favored path in.
When you connect a third-party app through OAuth - the "log in with Google" style of permission - it keeps whatever access you first approved, often more than it needs and usually forgotten. Remote monitoring and management tools, the same kind managed IT providers use, showed up in 39% of the command-and-control techniques Unit 42 observed. One case saw attackers compromise a sales-tool integration and use valid OAuth tokens to reach customer data, with traffic that looked like normal automation. More than 60% of vulnerabilities in cloud applications live in transitive libraries - packages pulled in automatically by other packages your team never chose. For any Houston SMB using Microsoft 365, Salesforce, QuickBooks Online, or SaaS add-ons, dormant, over-permissioned connectors are sitting in your environment right now, and most businesses have no idea how many.
Do You Know What's Connected to Your Microsoft 365?
CinchOps inventories your SaaS integrations, removes dormant OAuth grants, and cleans up the over-permissioned identities the Unit 42 report says drive most breaches.
Talk to CinchOps
How Has Ransomware Changed - and Why Is It Worse?
Encryption is down, but extortion and data theft are up - and they target your backups.
Only 78% of extortion cases involved encryption in 2025, down from consistently above 90%, because attackers learned they can just steal the data and threaten to publish it.
That decline is not good news. Data theft appeared in more than half of extortion cases and holds steady whether or not encryption happens. Median initial ransom demands rose from $1.25 million to $1.5 million, and median actual payments nearly doubled from $267,500 to $500,000. Most telling for recovery planning: in 26% of extortion cases, attackers targeted and impaired backups specifically to remove the victim's ability to recover without paying, and browser activity was involved in 48% of all investigations. The disruption goes well past the ransom - manufacturing, distribution, and order processing were shut down for extended periods across cases in the report, hitting revenue and customer relationships in ways that are hard to fully quantify.
The single most useful line in this whole report is that 90% of these breaches were preventable. That is not a doom statistic - it is a to-do list. The businesses that get hurt are not unlucky; they are the ones nobody was auditing, patching, or watching. That part you can change.
Closing the Preventable Gaps Unit 42 Documented
CinchOps closes exactly the gaps this report names - excessive permissions, unpatched systems, dormant integrations, and limited visibility - with identity audits, automated patching, and continuous monitoring for Houston-area businesses. It is part of our cybersecurity and managed IT services.
Explore CinchOps cybersecurity →How CinchOps Helps Secure Your Business
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, focused on closing the preventable gaps behind 90% of breaches.
CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. Almost everything the Unit 42 report describes is fixable with the right proactive partner:
- Identity and access audits. We clean up excessive permissions, dormant accounts, and stale integrations that create lateral-movement paths.
- MFA hardening. We go past basic MFA to phishing-resistant methods and conditional-access policies that weigh session risk.
- Patch management. With attackers scanning within 15 minutes of a CVE, automated patching of internet-facing systems is a core function, not an afterthought.
- Monitoring and resilient backups. Continuous visibility across endpoints, cloud, and identity, plus isolated, tested backups built to survive the attacks that target recovery.
The gap between a detected threat and a contained breach is now measured in minutes, not days. If you run a business in Houston, Katy, or Sugar Land and are not sure where your exposures are, talk to CinchOps for an honest assessment before an attacker finds them first.
Frequently Asked Questions
What is the Unit 42 Global Incident Response Report 2026?
It is an annual report from Palo Alto Networks' Unit 42 team based on responding to real cyber incidents. The 2026 edition analyzed more than 750 major incidents across over 50 countries and found that more than 90% of breaches came from preventable gaps rather than sophisticated attacks.
How fast do cyberattacks move in 2026?
The fastest quarter of attacks reached full data exfiltration in just 72 minutes, down from 285 minutes the prior year - a 75% reduction. For a Houston SMB without active monitoring, that window is effectively zero, which is why proactive detection matters so much.
What is the most common way attackers get into a small business?
Identity-based attacks were a factor in nearly 90% of Unit 42 investigations, and 65% of initial access was identity-driven. Phishing and software vulnerabilities each accounted for 22%. In most cases attackers logged in with credentials that were not properly protected rather than breaking in.
Does multi-factor authentication stop these attacks?
MFA is necessary but not complete. The report documented session-token theft and adversary-in-the-middle techniques that bypass standard MFA. Closing the gap requires phishing-resistant authentication plus regular identity and access audits to remove excessive permissions and dormant accounts.
Why do attackers target backups during ransomware?
A business with working backups has less reason to pay. Unit 42 found attackers impaired backups in 26% of extortion cases, specifically to remove recovery options before the victim realized an attack was underway. Isolated, tested backups are what keep you from having to pay.