CrowdStrike's 2026 Global Threat Report put the fastest recorded eCrime breakout at 27 seconds. That is the interval between an attacker gaining initial access and moving laterally into the rest of the environment. The average sits at 29 minutes, down 65% in a single year. (Source: CrowdStrike 2026 Global Threat Report)
Neither number is a scare tactic. They are a planning constraint. If breakout is measured in minutes and your containment path runs through a queue somebody reviews on Monday, you do not have a response capability. You have a record of what happened.
We are exhibiting at SecTor in Toronto from October 6 to 8, and this is the problem we want to talk about on the floor.
The clock starts at a login, not a breach
The framing that gets people stuck is thinking about break-ins. Most intrusions are not break-ins anymore.
Palo Alto Networks' Unit 42 examined more than 750 major incident response engagements across more than 50 countries. Identity weaknesses played a material role in almost 90% of investigations, and 65% of initial access was identity-driven: stolen credentials, MFA bypass, misconfigured access. In the same body of work, the fastest observed intrusion went from initial compromise to confirmed data exfiltration in 72 minutes, 4 times faster than the previous year. (Source: Unit 42 Global Incident Response Report 2026)
An attacker holding valid credentials does not trip the controls built to stop intruders, because those controls are not watching people who appear to belong. That is the whole advantage, and it is why the clock is so short.
Multi-factor authentication is not the finish line
The common objection at this point is that MFA covers it. It covers a great deal, and it does not cover relay.
An adversary-in-the-middle page sits between the user and the real service, passing traffic both directions in real time. The user enters a password, the proxy forwards it. The service issues its challenge, the proxy relays it back. The user supplies a one-time code or approves a push, and the proxy passes that along too. Authentication succeeds, because everything the service asked for was genuinely provided by the legitimate user. Then the service issues a session cookie and the proxy captures it.
From that point the attacker holds an authenticated session and needs neither the password nor the second factor again. Any method whose output can be handed to a third party can be relayed, which is what phishing-resistant means in practice: bound cryptographically to the domain making the request, so a proxy standing in the middle cannot replay it elsewhere.
This is not artisanal work. Microsoft Threat Intelligence documented Tycoon2FA, a phishing-as-a-service platform selling kits that impersonate enterprise sign-in pages using exactly this technique. Microsoft's Digital Crimes Unit worked with Europol to disrupt it in March 2026. Associated email volume fell 15% over the rest of the month, and the platform adapted rather than closed, shifting hosting providers and moving more than 41% of its domains to a .RU top-level domain within weeks. (Source: Microsoft Threat Intelligence, Q1 2026 email threat landscape)
Disruption of criminal infrastructure buys time. It does not retire the technique.
The lure got cheap and the shape changed
Two things happened to the front of the chain at the same time.
The lure stopped requiring skill. In a controlled study of 101 participants from Harvard Kennedy School, fully AI-automated spear phishing achieved a 54% click-through rate, matching human experts and beating a 12% control group by 350%. The economic analysis found automation can improve attacker return on investment by up to 50 times. (Source: Heiding et al., arXiv 2412.00586)
And the delivery mechanism moved to formats that sit outside text-based scanning. Microsoft detected roughly 8.3 billion email phishing threats in the first quarter of 2026, with volume holding roughly flat while composition shifted underneath it. QR code phishing grew 146% across the quarter to 18.7 million attacks in March, with 70% of them arriving inside PDF attachments. CAPTCHA-gated phishing more than doubled in March to 11.9 million attacks, where the CAPTCHA exists to stop automated scanners from reaching the content behind it. Credential phishing reached 94% of payload-based attacks while malware delivery fell to roughly 5%. (Source: Microsoft Threat Intelligence, Q1 2026 email threat landscape)
That last figure is the one worth sitting with. When the objective is a valid session rather than code execution, there is often no binary to detonate, no process to observe, and nothing for a sandbox to convict.
What we are presenting at SecTor
An attack has to clear every stage to succeed. We cover all of them, and the division of work is straightforward.
At the inbox. Legacy email security was built before AI made every phishing email unique. Our partner StrongestLayer runs AI-native email security that reasons about a message's sender, intent, and infrastructure the way an analyst would, then explains the verdict. Paired with our own Email Protection, it addresses the lures that never repeat, including QR-delivered attacks and business email compromise.
At the login. Microsoft 365 auditing surfaces suspicious sign-ins and risky changes to access. Dark web monitoring flags credentials already circulating. Password vaulting keeps them out of easy reach.
In the 27 seconds. Qi XDR correlates signals across endpoints, network, and cloud so a compromise that cleared the inbox still surfaces. Endpoint Protection and Response isolates compromised devices and shuts down lateral movement. Behind it sits a security operations centre staffed 24 hours a day and one named team accountable for the outcome.
That is the argument. Security and IT run under one model, so there is no vendor gap between detection and response and nobody to point at when something needs handling.
Two things you can do at the booth
We wrote the identity half of this up properly. The Second Factor is a research brief on what survives MFA and what stops it, sourced entirely to named primary reports. Every figure in it is traceable, and we left out several widely circulated statistics that are not.
We will also book a free proof of concept against your own mail flow and show you what is getting through today. It deploys in 15 minutes over API with no MX changes, uses read-only access, changes nothing for your users, and you can revoke it in one click.
Find us at SecTor, October 6 to 8, at the Metro Toronto Convention Centre.
If you have not registered yet, our sponsor code QUICKINTEL takes $200 CAD off a Briefings Pass or gets you a Business Pass at no cost: https://blackhat.com/sector/registration.html
Quick Intelligence is a Canadian full suite MSSP and MSP. We have operated since 2011, run a security operations centre 24 hours a day, and hold a Net Promoter Score of 85.
Experience technology humanized.