Report by CrowdStrike
2025 Global Threat Report
Key Findings
The average eCrime breakout time dropped to 48 minutes, with the fastest recorded at 51 seconds.
79% of attacks to gain initial access are now malware-free.
Access broker advertisements surged 50% YoY.
Valid account abuse is the primary initial access tactic, accounting for 35% of cloud incidents in H1 2024.
China's cyber espionage attacks increased by 150%, with targeted attacks in financial services, media, manufacturing, and industrial sectors soaring up to 300%.
Voice phishing (vishing) increased by 442% between H1 and H2 2024 due to AI-driven phishing and impersonation tactics.
New and unattributed cloud intrusions increased by 26% YoY.
52% of vulnerabilities observed were related to initial access.
40% of incidents involving DPRK-nexus adversary FAMOUS CHOLLIMA involved insider threat operations.