Wil Santiago, Wil Santiago, chief security and trust officer at Blackpoint Cyber Wil Santiago, chief security and trust officer at Blackpoint Cyber, joins In The Channel to discuss the findings of the company’s 2026 Annual Threat Report – research grounded in thousands of real incidents investigated by Blackpoint’s security operations centre, not surveys. The headline finding: attackers are no longer trying to break in. They’re logging in. Using stolen credentials and commodity remote management tools, threat actors are walking through the front door, hiding in plain sight, and operating with system-level privileges – sometimes for days before anyone notices. Santiago walks through the key trends the SOC identified across 2025: ClickFix and fake CAPTCHA campaigns accounted for more than half of all identifiable incidents, with attackers abusing trusted infrastructure including Azure Blob storage and Cloudflare to deliver payloads. RMM abuse showed up in roughly 30 per cent of triaged incidents – threat actors installing their own version of the same tools MSPs use legitimately, then living off the land with god-mode access. And Adversary-in-the-Middle attacks are now routinely hijacking authenticated sessions even when MFA is in place, by abusing OAuth token handling. The conversation also covers Blackpoint’s detection philosophy: behavioral context over malware signatures. Understanding what normal looks like in an environment – who uses what tool, at what time, from where – is what allows the SOC to catch attackers before they act. It’s a philosophy that is producing results: Blackpoint disrupted 56 per cent of incidents before a payload was ever deployed. Santiago’s closing recommendation for MSPs is straightforward: start with an RMM audit. Know every remote management tool deployed across every endpoint and server you manage. You cannot protect what you don’t know exists. The 2026 Annual Threat Report is available for download on the Blackpoint Cyber website. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. Wil Santiago is Chief Security and Trust Officer at Blackpoint Cyber, an MDR provider whose SOC monitors and responds to threats in real time across a large base of MSPs and their clients. And unlike a lot of threat research that’s survey-based or derived from external reporting, what Blackpoint publishes comes from live incident data, thousands of actual threat responses they’ve worked through in the SOC. Their 2026 annual threat report has a thesis that cuts right through it. Attackers are no longer trying to break in, they’re logging in, using stolen credentials and legitimate IT tools, the same RMMs, the same cloud platforms that MSPs rely on every day, to walk through the front door, hide in plain sight, and work their way towards payday. It’s a theme we’ve been tracking at ChannelBuzz.ca. If you caught our conversation with Tony Anscombe from ESET, that one dug into the mechanics of how MSP tools are being weaponized against the very clients they’re supposed to protect. This conversation is the data layer behind that story, and the detection philosophy that Wil and the Blackpoint team have built to counter it. Their SOC is disrupting 56% of incidents before a payload even deploys. We talk about how. Let’s get right into it. My chat with Wil Santiago. Wil, thanks for taking the time, I appreciate it. Wil Santiago: Thank you, Robert. Robert Dutt: For people who know Blackpoint primarily as an MDR provider, but maybe haven’t dug into the research side, can you give us a quick sense of what your SOC is actually seeing day to day? When you say this report is based on thousands of real incidents, what does that mean in practical terms, in terms of how you gathered this data? Wil Santiago: That’s a great question, Robert. It really starts at the core of what we focus on at Blackpoint Cyber. In 2025, we focused a lot of our detection efforts in the cloud endpoints, but what we realized is that at the core, at that identity layer, that’s the most important thing. But what we’re protecting at Blackpoint is the identity. What we observed in 2025 is this interesting shift where, yes, there’s vulnerabilities, there will continue to be vulnerabilities. However, threat actors don’t necessarily need to weaponize those vulnerabilities to gain access into an environment. They’re not really targeting customers or companies with any specific new zero-day technology or exploits that are novel. They’re just logging in using stolen passwords. We’re still at that pivotal point, but we’re still talking about the same things we’ve been talking about, password reuse, making sure you’re protecting yourself from phishing emails, so on and so forth. But the reality is that threat actors are getting in. They’re stealing credentials and they’re using legitimate tools to just log in, walking through the front door. Robert Dutt: Yeah, the headline from the report was very catchy with the attackers are no longer trying to break in. They’re just logging in, as you say. And that framing echoes what we’ve seen in other reports elsewhere. People are calling 2025 the year of the abuse of trust in terms of security trends, but your numbers are operational and not survey-based. I’m curious what trusted compromise looks like from where you sit. Is there really a shift away from what you were seeing a couple of years ago or three years ago, or has this always been the playbook and we’re only now measuring it properly? Wil Santiago: Yeah, so if I compare back to, let’s say, 2022, I think we at Blackpoint would still see a trend, the threat actors gaining access into an environment, usually using some type of exploit at that time. You can point to a number of Microsoft Exchange exploits that happened during that time. The Hafnium group was doing a lot of Exchange exploits. The reality is there came a certain time where we were detecting Cobalt Strike, a malware commodity tool, every single day in Blackpoint Cyber’s SOC. And then eventually it became once a week, and then it became once a month. So then we started to think, well, what’s happening with the shift of tactics with the threat actors? And what we found is instead of installing Cobalt Strike, they started to install legitimate IT tools. And that’s the trust component. When they’re installing tools that you use internally, they now can abuse those tools the same way that you use those legitimately. And so we have these threat actors that not only are abusing legitimate tools, but like I said, they’re abusing legitimate identities. So when you have what I call the keys to the kingdom, the passwords, I am you. I am now Robert, for all intents and purposes for this sort of webinar. I think the interesting part that we’ve seen at Blackpoint is that threat actors have really, really focused on leave-behinds. And those leave-behinds are commodity remote management tools. Why do they do that? Because EDRs don’t know how to detect them as malicious, right? These are legitimate IT tools that are being used to service MSPs and their customers. And a threat actor just installs their version of the same exact tool that you’re using legitimately. Right? And so the trust component is you go to review your assets and you see ScreenConnect installed in your environments because you use ScreenConnect, right? But then when you start taking a closer look, you start to realize, wait a second, there’s four different ScreenConnect IDs on this one machine. Now we have a more of a problem, right? And so the attack is a little bit of an invisible signature detection because it’s an authorized tool, right? And so we really have to get to this layer of identifying threat actor activity with behavior context. If you’re an AnyDesk shop, then why do you have TeamViewer installed on your file server that’s publicly facing, right? Let’s start to ask those questions and dig into that a little bit. Robert Dutt: Your SOC found that fake CAPTCHA and ClickFix campaigns accounted for, I think it was 50-odd percent of identifiable incidents. That’s a majority of attacks being driven by a technique that essentially requires the victim to step on the link to execute it themselves. Why is that scaling so fast right now? And especially for an MSP who tends to think, you know, my technicians are too smart to do that. What’s kind of the honest answer for what they need to be looking for and protecting against? Wil Santiago: Yeah. And, you know, ClickFix is such an easy attack when you really get into the root of what it does. But it starts with social engineering. You’re enticing someone, again, just like with phishing, to visit something that you’re going to tell them to do an action. And most of the time, they’re going to do that action. Now, why this is so effective is we’re seeing techniques that really enable the threat actor to deliver the payload. And how do they do that? Search engine optimization, right? These SEO links at the top, when you go look for an OBS installer, because you need your camera to look well, or you get a Google sponsor result. Threat actors are just buying those sponsored results and delivering their payloads on there. You click on it thinking you’re going to download OBS, and then it tells you, hey, wait a second, you have to make sure that you are human. Verify that we’re used to verifying we’re humans to download something. So we go and we click it. But then it says, hey, open up your Windows Run command and maybe run this command on us, on your computer for us. And what happens? Threat actors go and they put the commands on a website. They have t