Breaking News

Source

Key findings from the 2026 Public Sector M-Trends report and beyond

In 2026, the public sector is no longer defending a traditional perimeter. Instead, they are defending a complex web of interconnected trust relationships against adversaries that now operate at machine speed. We recently published the 2026 Public Sector Threat Landscape: M-Trends and Beyond report, which distills more than 500,000 hours of frontline incident investigations conducted by Mandiant in 2025, specifically tailored to the mission-critical needs of public sector leaders.

Key findings from the report and what they mean for the public sector

  • The vishing surge: Voice phishing (vishing) has surged to 11% of global infections. These highly effective social engineering attacks target government help desks to reset passwords or enroll unauthorized devices. This proves that the ‘human element’—the administrative trust placed in help desk staff and IT administrators—is now a primary vector for establishing initial access.
  • The persistence paradox: State-sponsored espionage actors are pursuing multi-year persistence, with some remaining undetected for over five years. This “persistence paradox” directly challenges standard 90-day telemetry retention policies, often leaving agencies unable to quantify the full impact of a breach.
  • The virtualization stack: Attackers are moving “down the stack” to target the virtualization management plane. Techniques like “snapshot mounting” allow attackers to bypass guest-level security tools, creating snapshots of domain controllers to steal databases offline.
  • The SaaS domino effect: At the state and local levels, the reliance on third-party cloud tools has turned integrations into threat vectors. Exploiting non-human identities (NHIs) like service accounts and OAuth tokens allows a single compromise to trigger a chain reaction across an entire agency network.

 

Read the full article

Key Points that Matter

  1. Initial access remains the defining moment of a cyberattack. Voice-based social engineering is increasingly used to bypass technical controls and gain a foothold inside organizations.
  2. AI is accelerating attacker speed, scale, and sophistication, making voice impersonation, vishing, and social engineering campaigns more convincing and more difficult for employees to detect.
  3. Protecting the human endpoint requires protecting the voice channel first. A multi-layered Voice Security strategy stops malicious calls before they reach employees, reducing cyber risk at the earliest point in the attack chain.

You Can Stop Voice-Based Threats

The Voice Channel has become the most exploited pathway for threat actors. Voice Security is no longer a nice to have, but a critical mandate.

Mutare’s Voice Security Platform defends the voice channel as critical infrastructure. Operating as a technical control at the network edge, it stops vishing, social engineering, spoofed calls, spam storms, and GenAI-powered attacks.

We understand that every organization is at a different stage of its Voice Security journey.
Some are just beginning to understand the risks. Others are evaluating solutions or validating technologies. Take a moment to check out Test Drive to choose your path towards understanding the voice security landscape and learning about a comprehensive defense solution.

Learn More About Voice Security

We’ve curated the latest information and events about Voice Security:

Articles

Voice Security Has Reached a Tipping Point

The 2026 Voice Threat Survey reveals why voice can no longer be treated as an overlooked communications channel. It has become one of the fastest-growing cyber threat vectors in the enterprise.

Events

WEBINAR: AI-Ready Voice Security

What was once limited to nuisance robocalls has evolved into a continuous stream of unwanted voice traffic, now amplified by automation, spoofing, and AI-driven attack campaigns.

ViVE, Feb 2026, Los Angeles, CA

Please join us in Los Angeles February 22-25 and connect with a member of the Mutare Team to discuss patient experience, patient care, and risk management.

Case Studies