Celebrating India’s independence, enterprise and progress
news

2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics

Apr 17, 2025 · Source: cision
2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics
  • Nearly half of all cyberattacks resulted in stolen data or credentials
  • Identity abuse was the preferred entry point
  • Asia Pacific represented more than one-third of attacks in 2024

ARMONK, N.Y., April 17, 2025 -- IBM (NYSE: IBM) today released the 2025 X-Force Threat Intelligence Index highlighting that cybercriminals continued to pivot to stealthier tactics, with lower-profile credential theft spiking, while ransomware attacks on enterprises declined. IBM X-Force observed an 84% increase in emails delivering infostealers in 2024 compared to the prior year, a method threat actors relied heavily on to scale identity attacks.

IBM X-Force Threat Index

The 2025 report tracks new and existing trends and attack patterns – pulling from incident response engagements, dark web and other threat intelligence sources.

Some key findings in the 2025 report include:

  • Critical infrastructure organizations accounted for 70% of all attacks that IBM X-Force responded to last year, with more than one quarter of these attacks caused by vulnerability exploitation.
  • More cybercriminals opted to steal data (18%) than encrypt it (11%) as advanced detection technologies and increased law enforcement efforts pressure cybercriminals to adopt faster exit paths.
  • Nearly one in three incidents observed in 2024 resulted in credential theft, as attackers invest in multiple pathways to quickly access, exfiltrate and monetize login information.

"Cybercriminals are most often breaking in without breaking anything – capitalizing on identity gaps overflowing from complex hybrid cloud environments that offer attackers multiple access points," said Mark Hughes, Global Managing Partner of Cybersecurity Services at IBM. "Businesses need to shift away from an ad-hoc prevention mindset and focus on proactive measures such as modernizing authentication management, plugging multi-factor authentication holes and conducting real-time threat hunting to uncover hidden threats before they expose sensitive data."

Patching Challenges Expose Critical Infrastructure Sectors to Sophisticated Threats

Reliance on legacy technology and slow patching cycles prove to be an enduring challenge for critical infrastructure organizations as cybercriminals exploited vulnerabilities in more than one-quarter of incidents that IBM X-Force responded to in this sector last year.

In reviewing the common vulnerabilities and exposures (CVEs) most mentioned on dark web forums, IBM X-Force found that four out of the top ten have been linked to sophisticated threat actor groups, including nation-state adversaries, escalating the risk of disruption, espionage and financial extortion. Exploit codes for these CVEs were openly traded on numerous forums —fueling a growing market for attacks against power grids, health networks and industrial systems. This sharing of information between financially motivated and nation-state adversaries highlights the increasing need for dark web monitoring to help inform patch management strategies and detect potential threats before they are exploited. 

Automated Credential Theft Sparks Chain Reaction

In 2024, IBM X-Force observed an uptick in phishing emails delivering infostealers and early data for 2025 reveals an even greater increase of 180% compared to 2023. This upward trend fueling follow-on account takeovers may be attributed to attackers leveraging AI to create phishing emails at scale.

Credential phishing and infostealers have made identity attacks cheap, scalable and highly profitable for threat actors. Infostealers enable the quick exfiltration of data, reducing their time on target and leaving little forensic residue behind. In 2024, the top five infostealers alone had more than eight million advertisements on the dark web and each listing can contain hundreds of credentials. Threat actors are also selling adversary-in-the-middle (AITM) phishing kits and custom AITM attack services on the dark web to circumvent multi-factor authentication (MFA). The rampant availability of compromised credentials and MFA bypass methods indicates a high-demand economy for unauthorized access that shows no signs of slowing down.

Ransomware Operators Shift to Lower-Risk Models

While ransomware made up the largest share of malware cases in 2024 at 28%, IBM X-Force observed a reduction in ransomware incidents overall compared to the prior year, with identity attacks surging to fill the void.

International takedown efforts are pushing ransomware actors to restructure high-risk models towards more distributed, lower-risk operations. For example, IBM X-Force observed previously well-established malware families including ITG23 (aka Wizard Spider, Trickbot Group) and ITG26 (QakBot, Pikabot) to either completely shut down operations or turn to other malware, including the use of new and short-lived families, as cybercrime groups attempt to find replacements for the botnets that were taken down last year.

Additional findings from the 2025 report include:

  • Evolving AI threats. While large-scale attacks on AI technologies didn't materialize in 2024, security researchers are racing to identify and fix vulnerabilities before cybercriminals exploit them. Issues like the remote code execution vulnerability that IBM X-Force discovered in a framework for building AI agents will become more frequent. With adoption set to grow in 2025, so will the incentives for adversaries to develop specialized attack toolkits targeting AI, making it imperative that businesses secure the AI pipeline from the start, including the data, the model, the usage, and the infrastructure surrounding the models.
  • Asia and North America most attacked regions. Collectively accounting for nearly 60% of all attacks that IBM X-Force responded to globally, Asia (34%) and North America (24%) experienced more cyberattacks than any other region in 2024.
  • Manufacturing felt the brunt of ransomware attacks. For the fourth consecutive year, manufacturing was the most attacked industry. Facing the highest number of ransomware cases last year, the return on investment for encryption holds strong for this sector due to its extremely low tolerance for downtime.
  • Linux threats. In collaboration with Red Hat Insights, IBM X-Force found that more than half of Red Hat Enterprise Linux customers' environments had at least one critical CVE unaddressed, and 18% faced five or more vulnerabilities. At the same time, IBM X-Force found the most active ransomware families (e.g., Akira, Clop, Lockbit, and RansomHub) are now supporting both Windows and Linux versions of their ransomware.

Additional Resources

  • Download a copy of the 2025 IBM X-Force Threat Intelligence Index.
  • Sign up for the 2025 IBM X-Force Threat Intelligence webinar on Tuesday, April 22nd at 11:00 am ET.
  • Connect with the IBM X-Force team for a personalized review of the findings.
  • Read more about the report's top findings in this IBM blog.

About IBM 

IBM is a leading provider of global hybrid cloud and AI, and consulting expertise. We help clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs, and gain a competitive edge in their industries. Thousands of governments and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM's hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently, and securely. IBM's breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and consulting deliver open and flexible options to our clients. All of this is backed by IBM's long-standing commitment to trust, transparency, responsibility, inclusivity, and service. Visit www.ibm.com for more information. 

Media Contact

Michele Brancati

IBM

mbrancati@ibm.com

IBM Corporation logo.

Photo - https://mma.prnewswire.com/media/2666805/IBM_X_Force_Threat_Index.jpg

Logo - https://mma.prnewswire.com/media/2319830/IBM_LOGO_1.jpg

Cision View original content:https://www.prnewswire.co.uk/news-releases/2025-ibm-x-force-threat-index-large-scale-credential-theft-escalates-threat-actors-pivot-to-stealthier-tactics-302430898.html

Comments (0)

Login to join the conversation

Login / Register

No comments yet. Be the first to comment!

More to Read

VICTORINOX INDIA WELCOMES ABHAY DEOL AS A FRIEND OF THE BRAND
news
Aug 15, 2026 1 min

VICTORINOX INDIA WELCOMES ABHAY DEOL AS A FRIEND OF THE BRAND

SHARED VALUES. AUTHENTICITY. CHARACTER. MUMBAI, India , Aug. 15, 2026 -- Victorinox India today announced actor Abhay Deol as a Friend of the Brand for its watch portfolio for the coming 18 months . Known for his authenticity, independent spirit and thoughtful approach to life, Deol reflects values that have guided Victorinox for more than 140 years. The association will bring Abhay Deol across Victorinox s watch portfolio, all collections including I.N.O.X., Maverick, Concept One Solar, Air Pro, Dive Pro and Concept One Automatic . Throughout this term, Deol will feature across all media touch touchpoints including digital, outdoor and retail touchpoints, celebrating a shared commitment to character, quality and enduring craftsmanship.

77 DAYS TO GO: 7 WONDERS OF FUTURE CITIES COUNTS DOWN TO START OF VOTING
news
Aug 15, 2026 1 min

77 DAYS TO GO: 7 WONDERS OF FUTURE CITIES COUNTS DOWN TO START OF VOTING

DUBAI, UAE , Aug. 15, 2026 -- 7 Wonders of Future Cities today marks 77 days until global voting begins on www.7wondersfc.com on 31 October 2026. The day, also known as World Cities Day, will be when the public can start choosing amongst the participating cities and developments, to become historically recognised as the leading representatives of the future of urban life. According to Jean-Paul de la Fuente, Chairman of the 7 Wonders of Future Cities campaign, Public participation, global visibility and the status of our recognised brand can transform urban vision into a shared cause, and we are seeing this already with motivating engagement from participating cities and developments from all over the world.

TestMu AI Unveils the Fifth Edition of the TestMu Conference in 2026
news
Aug 14, 2026 1 min

TestMu AI Unveils the Fifth Edition of the TestMu Conference in 2026

The world s largest virtual agentic engineering and quality conference returns with a focus on autonomous quality, agentic workflows, and AI-native testing strategies SAN FRANCISCO and NOIDA, India , Aug. 14, 2026 -- TestMu AI (formerly LambdaTest), the world s first Agentic AI-powered Quality Engineering platform, is excited to unveil the 5th edition of its flagship TestMu Conference, taking place virtually from August 19 21, 2026. This year s event is expected to host over 75,000 developers, builders, and quality engineers from more than 120 countries, making it the world s largest virtual conference dedicated to agentic engineering and quality.

Michael Owen Joins ehamarkets as Global Brand Ambassador
news
Aug 14, 2026 1 min

Michael Owen Joins ehamarkets as Global Brand Ambassador

HONG KONG and NEW YORK , Aug. 14, 2026 -- ehamarkets today announced a global brand partnership with England football legend and 2001 Ballon d Or winner Michael Owen, who has joined the brand as its Global Brand Ambassador. Owen said he was drawn to ehamarkets focus on technology, reliability and a simpler trading experience. I m delighted to join ehamarkets as its Global Brand Ambassador. I like the way ehamarkets uses technology to make trading simpler and more efficient. It s exciting to be part of a brand that is building a modern trading experience for people around the world.

RemotePeople Completes 2026 SOC 2 Type II Audit Across Security, Availability, and Confidentiality
news
Aug 14, 2026 1 min

RemotePeople Completes 2026 SOC 2 Type II Audit Across Security, Availability, and Confidentiality

The New York-headquartered global Employer of Record renews its SOC 2 Type II attestation for a full 12-month period, adding to its ISO 27001 and GDPR certifications and its recent A+ platform security rating from Astra Security. NEW YORK , Aug. 14, 2026 -- RemotePeople, a global provider of Employer of Record (EOR), payroll, and recruitment services operating in more than 150 countries, today announced the successful completion of its 2026 SOC 2 Type II audit , covering the Security, Availability, and Confidentiality Trust Service Criteria. The independent examination was performed by INTERCERT CPA LLC in accordance with AICPA SSAE 21 attestation standards and covered a continuous 12-month observation period from May 31, 2025 to May 30, 2026.

Bybit TradFi Perpetuals Extend 24/7 Exposure to Over 200 Global Equities and Pre-IPO Assets
news
Aug 14, 2026 1 min

Bybit TradFi Perpetuals Extend 24/7 Exposure to Over 200 Global Equities and Pre-IPO Assets

DUBAI, UAE , Aug. 14, 2026 -- Bybit , the world s second-largest cryptocurrency exchange by trading volume, is pleased to announce TradFi Perpetual Contracts now offer over 200 curated TradFi-themed listings , marking one of the highest quality coverage of TradFi derivatives exposure available on a crypto-native platform. The lineup now spans equities, ETFs, precious metals, indices, and oil, with coverage extending across premium US, Hong Kong, South Korean and other equities markets.

FERRERO GROUP TO ACQUIRE PURELY ELIZABETH, A LEADING U.S. MODERN WELLNESS BRAND
news
Aug 14, 2026 1 min

FERRERO GROUP TO ACQUIRE PURELY ELIZABETH, A LEADING U.S. MODERN WELLNESS BRAND

LUXEMBOURG and BOULDER, Colo. , Aug. 14, 2026 -- Ferrero Group today announced it has signed an agreement to acquire Purely Elizabeth, the high-growth modern wellness brand and a leading better-for-you food company based in the U.S. The acquisition further enhances Ferrero s relevance at the American breakfast table with Purely Elizabeth joining its portfolio. Following closing, Ferrero intends to support Purely Elizabeth s next phase of growth through continued product innovation, operational capabilities and expanded distribution, helping the brand reach more consumers while preserving its distinct identity and commitment to quality.

Deeper Insights, Better Analytics: Bybit Options Close the Data Gap Between Retail and Institutional Traders
news
Aug 14, 2026 1 min

Deeper Insights, Better Analytics: Bybit Options Close the Data Gap Between Retail and Institutional Traders

DUBAI, UAE , Aug. 14, 2026 -- Bybit , the world s second-largest cryptocurrency exchange by trading volume, announced a major upgrade to its Options Data section, introducing a suite of institutional-grade analytics to provide traders with a clearer view of volatility, positioning, and market structure. The redesigned page integrates institutional-grade analytics with a cleaner, more accessible interface for all users. Options trading has been gaining popularity among digital asset derivatives traders, as they increasingly move beyond simple long or short positions to alternative strategies that account for volatility, time decay, and risk management. Options give traders the right, but not the obligation, to buy or sell an asset at a set price before a set date.