x.com/shashj/status/2082456664171565182
1 correction found
malicious emails and phishing are still the most common way of illicitly entering an organisation's network.
Recent major incident reports do not show phishing/email as the single top entry route anymore. Verizon’s 2026 DBIR says vulnerability exploitation is now the #1 breach entry point, and Palo Alto’s 2026 Unit 42 report says phishing is tied with vulnerability exploitation rather than leading it.
Full reasoning
This claim is too strong for mid-2026. Recent large-scale incident reports do not show email phishing as the single most common way attackers first get into organizations.
- Verizon’s 2026 Data Breach Investigations Report, published May 19, 2026 and summarizing 2025 breach data, says vulnerability exploitation is now the top breach entry point. Verizon states that "using software flaws (31%)" is the top entry point and that "Nearly a third (31%) of all breaches start with vulnerability exploitation," adding that this is the first time it has become the biggest point of entry.
- Palo Alto Networks’ 2026 Unit 42 Global Incident Response Report also contradicts the post’s wording that phishing is the most common route. Unit 42 says "Phishing and vulnerability exploitation are the most common initial access vectors, with each accounting for 22%" of 2025 incidents. That means phishing is not uniquely the leading vector there either; at best it is tied.
So the post’s statement that malicious emails/phishing are "still the most common way" overstates the evidence. Current major industry datasets show that phishing is no longer clearly the single top initial-access method, and in Verizon’s dataset it has been overtaken by vulnerability exploitation.
2 sources
- Breach entry point, 2026 DBIR finds | About Verizon
At a glance: Vulnerabilities top entry point: Using software flaws (31%) has surpassed stolen credentials for the first time... Key findings: Nearly a third (31%) of all breaches start with vulnerability exploitation in an AI world... this is the first time in 19 years that it has surpassed stolen credentials as the biggest point of entry.
- 2026 Unit 42 Global Incident Response Report - Palo Alto Networks
Phishing and vulnerability exploitation are the most common initial access vectors, with each accounting for 22% of the initial access across 2025 incidents.