Mandiant says human and architecture failures, not AI, still drive most breaches

Attackers now hand off access in 22 seconds and work to block recovery, Mandiant’s Joe Mehegan said at a Rubrik summit.
By admin
Oct 9, 2026, 1:51 PM

The M-Trends 2026 report from Mandiant, a part of Google Cloud, draws on more than 500,000 hours of incident response work in 2025 to offer insight into current and emerging cyber threats. During a session at data security company Rubrik’s Healthcare Summit 2026, Rubrik healthcare CTO Josh Howell sat down with Joe Mehegan, practice leader for North America security architecture and remediation at Mandiant, to talk about the findings in the latest M-Trends report and how healthcare leaders can respond to an increasingly AI-fueled threat landscape.

Attackers are moving faster and focusing on recovery denial

Mandiant observed a surge in voice-based phishing (vishing) and an increase in blind spot exploitation. Vishing was the second most common way attackers got in, accounting for 11 percent of cases where Mandiant could identify the entry point. Mehegan noted that as endpoint detection and response (EDR) tools have improved, attackers have “moved more toward targeting unmonitored edge appliances and hypervisor layers that don’t necessarily have the level of monitoring that endpoints typically have.”

Once threat actors gain that initial access, they move faster. Their victims’ defense windows are collapsing. In 2022, the median time between a threat actor’s initial access and hand-off to a second threat group was more than eight hours. In 2025, it was 22 seconds.

Attackers’ approach to extortion is also changing. Healthcare consistently ranks near the top of the industries attackers target. Data exfiltration and file encryption remain central to ransomware, and threat actors are now adding recovery denial.

Adversaries understand that healthcare organizations need to be able to provide patient care. “They are looking to dismantle an organization’s ability to recover their systems, leaving an organization no viable, technical choice but to pay the ransom,” Mehegan said.

AI is going to help attackers scale their efforts

Mandiant did not find AI to be the primary force driving breaches in its research for this report, but it is gaining steam.

“The overwhelming majority of breaches are still driven fundamentally by human and architecture failures: misconfigurations on the identity side, unmonitored hypervisors, live voice phishing rather than novel AI exploits,” Mehegan said during the session. “Frontline research from our Google Threat Intel group indicates the baseline is evolving quickly.”

Mandiant is observing adversaries beginning to use AI for social engineering and gaining initial access. Over the next 12 months, Mandiant anticipates threat actors will expand their use of voice cloning, malware evasion tooling and just-in-time polymorphic malware.

“That malware is increasingly querying LLMs to dynamically rewrite code and generate new routines,” Mehegan said. He expects to see more of it.

While AI can be a tool for novel exploits, it will also help threat actors do more with less.

“AI is likely to allow one or two attackers to scale in a way that wasn’t previously economical or easy to achieve,” Mehegan said. “One or two attackers could have the efficiency of say five or six or more, depending on the AI tools they use.”

Communication is critical to a successful recovery

Electronic medical records (EMRs) are top-of-mind for healthcare organizations. If a cyberattack takes down the EMR, patient care becomes much harder to deliver. But it isn’t the only critical system to think about.

When Howell talks to health systems, “The focus starts out as the EMR as the single biggest, most important thing that they will want back, but when we debate and talk about it, sometimes we arrive at there are other things that may be more critical early…like email,” he said.

Without the ability to communicate, organizations face an even longer, and more expensive, road to recovery.

“We recommend having an out-of-band, or out-of-plane, communications infrastructure ready to go,” Mehegan said.

Security leaders have to figure out how to move toward active resilience

That ability to communicate in the aftermath of a breach is a critical piece of achieving what Mehegan refers to as “active resilience.”

“When we refer to active resilience…we are talking about architecturally decoupling restoration,” he said. “Recovery paths, backup storage, hypervisor management planes are strictly separate from production AD [Active Directory].”

By focusing on this kind of resilience, healthcare organizations can isolate a breach, contain lateral movement and independently restore operations. “The outcome here is sovereign recovery and business continuity,” Mehegan said.


Show Your Support

Subscribe

Newsletter Logo

Subscribe to our topic-centric newsletters to get the latest insights delivered to your inbox weekly.

Enter your information below

By submitting this form, you are agreeing to DHI’s Privacy Policy and Terms of Use.