Key Findings
Highly interactive voice phishing accounted for 11% of intrusions, making it the second-most common initial infection vector.
The high tech sector accounted for 17% of incidents.
Prior compromise accounted for 10% of initial infection vectors globally, ranking third-most common.
Exploits remained the most common initial infection vector for the sixth consecutive year, accounting for 32% of intrusions.
Email phishing accounted for 6% of intrusions in 2025.
Mean time to exploit vulnerabilities was -7 days, indicating exploitation routinely occurs before patches are released.
Organizations first detected evidence of malicious activity internally 52% of the time in 2025, up from 43% in 2024.
Median dwell time for cyber espionage incidents and North Korean IT worker incidents was 122 days.
Global median dwell time was 14 days, up from 11 days.
Prior compromise was the top initial infection vector in ransomware operations at 30%, up from 15% in 2024.
Median time between initial access and hand-off to a secondary threat group was 22 seconds in 2025, down from more than 8 hours in 2022.
BRICKSTORM achieved dwell times of nearly 400 days.
The financial sector accounted for 14.6% of incidents.