Skip to Content Facebook Feature Image

2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics

Business

2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics
Business

Business

2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics

2025-04-17 17:45 Last Updated At:18:05

ARMONK, N.Y., April 17, 2025 /PRNewswire/ -- IBM (NYSE: IBM) today released the 2025 X-Force Threat Intelligence Index highlighting that cybercriminals continued to pivot to stealthier tactics, with lower-profile credential theft spiking, while ransomware attacks on enterprises declined. IBM X-Force observed an 84% increase in emails delivering infostealers in 2024 compared to the prior year, a method threat actors relied heavily on to scale identity attacks.

The 2025 report tracks new and existing trends and attack patterns – pulling from incident response engagements, dark web and other threat intelligence sources.

Some key findings in the 2025 report include:

"Cybercriminals are most often breaking in without breaking anything – capitalizing on identity gaps overflowing from complex hybrid cloud environments that offer attackers multiple access points," said Mark Hughes, Global Managing Partner of Cybersecurity Services at IBM. "Businesses need to shift away from an ad-hoc prevention mindset and focus on proactive measures such as modernizing authentication management, plugging multi-factor authentication holes and conducting real-time threat hunting to uncover hidden threats before they expose sensitive data."

Patching Challenges Expose Critical Infrastructure Sectors to Sophisticated Threats
Reliance on legacy technology and slow patching cycles prove to be an enduring challenge for critical infrastructure organizations as cybercriminals exploited vulnerabilities in more than one-quarter of incidents that IBM X-Force responded to in this sector last year.

In reviewing the common vulnerabilities and exposures (CVEs) most mentioned on dark web forums, IBM X-Force found that four out of the top ten have been linked to sophisticated threat actor groups, including nation-state adversaries, escalating the risk of disruption, espionage and financial extortion. Exploit codes for these CVEs were openly traded on numerous forums —fueling a growing market for attacks against power grids, health networks and industrial systems. This sharing of information between financially motivated and nation-state adversaries highlights the increasing need for dark web monitoring to help inform patch management strategies and detect potential threats before they are exploited. 

Automated Credential Theft Sparks Chain Reaction
In 2024, IBM X-Force observed an uptick in phishing emails delivering infostealers and early data for 2025 reveals an even greater increase of 180% compared to 2023. This upward trend fueling follow-on account takeovers may be attributed to attackers leveraging AI to create phishing emails at scale.

Credential phishing and infostealers have made identity attacks cheap, scalable and highly profitable for threat actors. Infostealers enable the quick exfiltration of data, reducing their time on target and leaving little forensic residue behind. In 2024, the top five infostealers alone had more than eight million advertisements on the dark web and each listing can contain hundreds of credentials. Threat actors are also selling adversary-in-the-middle (AITM) phishing kits and custom AITM attack services on the dark web to circumvent multi-factor authentication (MFA). The rampant availability of compromised credentials and MFA bypass methods indicates a high-demand economy for unauthorized access that shows no signs of slowing down.

Ransomware Operators Shift to Lower-Risk Models
While ransomware made up the largest share of malware cases in 2024 at 28%, IBM X-Force observed a reduction in ransomware incidents overall compared to the prior year, with identity attacks surging to fill the void.

International takedown efforts are pushing ransomware actors to restructure high-risk models towards more distributed, lower-risk operations. For example, IBM X-Force observed previously well-established malware families including ITG23 (aka Wizard Spider, Trickbot Group) and ITG26 (QakBot, Pikabot) to either completely shut down operations or turn to other malware, including the use of new and short-lived families, as cybercrime groups attempt to find replacements for the botnets that were taken down last year.

Additional findings from the 2025 report include:

Additional Resources

About IBM 
IBM is a leading provider of global hybrid cloud and AI, and consulting expertise. We help clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs, and gain a competitive edge in their industries. Thousands of governments and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM's hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently, and securely. IBM's breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and consulting deliver open and flexible options to our clients. All of this is backed by IBM's long-standing commitment to trust, transparency, responsibility, inclusivity, and service. Visit www.ibm.com for more information. 

Media Contact
Michele Brancati
IBM
mbrancati@ibm.com

** The press release content is from PR Newswire. Bastille Post is not involved in its creation. **

2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics

2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics

2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics

2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics

Next Article

The MarTech Summit Hong Kong, 8 July 2025 at The Ritz-Carlton

2025-05-03 00:17 Last Updated At:00:35

HONG KONG, May 2, 2025 /PRNewswire/ -- Hello Hong Kong! We're excited to announce the return of The MarTech Summit to Hong Kong for the 4th consecutive year! This time, we're taking it up a notch at a new premium venue â€” the iconic Diamond Ballroom, The Ritz-Carlton Hong Kong, offering stunning harbour views.

Join us on 8 July 2025 as we explore this year's theme:
"Charting MarTech From Practicality to Real Impact".

Get ready for a high-impact, one-day summit bringing together 200+ senior marketers and 30+ industry-leading speakers for focused networking, knowledge exchange, and actionable insights.

What's in Store?

Key topics include:

Hear from Industry Leaders
Gain insights from speakers representing innovative and leading brands such as Polaroid, GoGoX, Shake Shack, Atlas, M+, South China Morning Post, Black Sheep Restaurants, CHARGESPOT, foodpanda, GP Batteries, and Trip.com Group.

Explore the Speaker Line-up: https://themartechsummit.com/hongkong#speakers

You'll also be networking with senior executives from top companies like Cathay Pacific, HSBC, J.P. Morgan, Nike, Colgate, Shell, Hong Kong Disneyland, Vogue, Shangri-La, and many more—ensuring a dynamic mix of thought leadership and industry presence.

Why Attend?

New Venue, Enhanced Experience
Network amidst the luxury of The Ritz-Carlton, with harbour views setting the stage for impactful conversations.

High-Impact, One-Day Event
Focused content, senior-level attendees, no distractions—just pure learning and networking.

Regional Relevance
A bespoke agenda crafted for the challenges and opportunities in Hong Kong and the Greater Bay Area, while keeping a global outlook.

Connect with Decision-Makers
With 85% of attendees holding senior leadership roles, engage with those shaping the future of MarTech.

Advance Your Professional Development
Walk away with strategies to drive measurable impact in your organisation.

Highlights from 2024
Last year, at the Kowloon Shangri-La, we welcomed over 250 senior marketers30+ speakers, and hosted 14 MarTech exhibitors. Leaders from Cathay Pacific, HSBC, IKEA, Chanel, Shell, P&G, FedEx, Dyson, Manulife, and many more joined us for a day of cutting-edge discussions.

Key moments included:

With 80%+ senior leadership attendance and 60% from enterprises with 1,001+ employees, 2024 proved that The MarTech Summit Hong Kong is the go-to platform for serious MarTech professionals.

Don't Miss Out!
Register by 31 May 2025 to enjoy a 40% Super Early Bird Discount!

Secure your pass now: https://themartechsummit.com/hongkong-registration

Venue: Diamond Ballroom, The Ritz-Carlton Hong Kong

Be part of an exclusive MarTech experience—where strategic insights meet premium networking in one of Hong Kong's most prestigious venues.

PR Newswire is the official Media Partner of The MarTech Summit Hong Kong

Interested in partnering? Contact us at sponsor@themartechsummit.com

Group rates auto-apply for 3+ attendees! For enquiries: marketing@themartechsummit.com

** The press release content is from PR Newswire. Bastille Post is not involved in its creation. **

The MarTech Summit Hong Kong, 8 July 2025 at The Ritz-Carlton

The MarTech Summit Hong Kong, 8 July 2025 at The Ritz-Carlton

Recommended Articles
Hot · Posts