Verizon's 2026 DBIR found ransomware in 48% of breaches.
Exploited vulnerabilities are now the top way in, per the same report. But email is still a delivery path for malware, and it's the one I see every day.
So when a malicious attachment gets caught, the case isn't closed. It's half open. The questions I want answered:
- Who else received the same message or a variant?
- What got it past the first layer, if anything?
- Did anyone open it before it was caught?
- Is this one email, or the first wave of a campaign?
The near miss is free intelligence. It shows you exactly what the attacker tried, without the cost of it working.
Teams that only investigate successful attacks are learning the most expensive way possible.