IBM today released its 2024 X-Force Threat Intelligence Index, highlighting a significant rise in cyberattacks exploiting user identities. These identity-based attacks have become the preferred method for cybercriminals, leveraging compromised credentials to gain access to corporate networks. The report, based on monitoring over 150 billion security events daily across 130 countries, indicates a 71% spike in such attacks, particularly targeting critical infrastructure sectors.
“Identity is being used against enterprises time and time again,” stated Charles Henderson, Global Managing Partner, IBM Consulting, and Head of IBM X-Force. The findings show that breaches caused by stolen or compromised credentials take approximately 11 months to detect and recover from, the longest response time of any attack vector. This emphasises the importance of basic security measures like multi-factor authentication and regular patching, which could have mitigated nearly 85% of these attacks.
The report also notes a shift in ransomware tactics, with groups moving towards infostealers as larger organisations resist paying ransoms. Additionally, it predicts that as generative AI technologies become more ubiquitous, they will become a new target for cybercriminals, requiring proactive security measures.
This story is inspired by an IBM Newsroom article