Prophet logo

Q3 2026: Prophet Security Quarterly Threat Report

Download the Report:
Every alert in every customer environment, investigated in full, May through July 2026. 4.7 million questions asked, a median of 35 per investigation.

 

Identity was the target in roughly half of all confirmed malicious activity last quarter, and the strongest predictor of a successful account takeover was whether the attacker used a password or an already-authenticated session. Passwords ran into conditional access. Sessions walked past it.

Inside the report:

  • The full determination breakdown across 4.7 million questions asked of customer environments, at a median of 35 questions per investigation

  • A single account takeover reconstructed step by step, from the first login to the artifact that made a password reset irrelevant

  • Complete hardening recommendations for all four findings: session and token revocation, continuous access evaluation, cookie-store alerting, DMARC, agent-coverage reconciliation

  • How the AI SOC analyst reached each determination, including the questions that reframed the alert

  • Where AI developer tooling is now producing false positives that look like attacker tradecraft

  • Method and limitations in full, including what is excluded and why

*This report was produced from data pulled May–July 2026.

Get the Quarterly Threat Report

Here are our team's key takeaways from Prophet AI's work last quarter.

Previous scaling companies like: