
LONDON, UK, Feb 21, 2024 IBM today released the 2024 X-Force Threat Intelligence Index highlighting an emerging global crisis as cybercriminals double down on exploiting user identities to compromise enterprises.
According to IBM X-Force, IBM Consulting's security services arm, cybercriminals last year generated more opportunities to log in to corporate networks through valid accounts, instead of hacking into them making this tactic a preferred weapon of choice for threat actors.
The X-Force Threat Intelligence Index is based on insights and observations from monitoring over 150 billion security events per day in more than 130 countries. In addition, data is gathered and analysed from multiple sources within IBM, including IBM X-Force Threat Intelligence, Incident Response, X-Force Red, IBM Managed Security Services, and data provided from Red Hat Insights and Intezer , which contributed to the 2024 report.
An emerging identity crisis
The report data revealed that exploiting valid accounts has become the path of least resistance for cybercriminals, with billions of compromised credentials accessible on the Dark Web.
According to the report, 50% of cyberattacks in the UK involved the exploitation of valid accounts as the initial access vector' and a further 25% of cases involved the exploitation of public-facing applications. Across Europe, X-Force observed a 66% year-on-year rise in attacks caused by the use of valid accounts contributing to Europe's prevalence as the most targeted region of 2023 and the record number of attacks that X-Force has ever reported regionally.
The criminal ecosystem was also quick to adapt to the use of valid accounts by attackers. In 2023, X-Force observed a 266% increase in infostealing malware, which is designed to steal personal and enterprise credentials, personally identifiable information, and banking and crypto wallet information.
This easy entry for attackers is harder to detect, eliciting a costly response from enterprises. According to X-Force, worldwide, major incidents caused by attackers using valid accounts were linked to nearly 200% more complex response measures by security teams than the average incident with defenders needing to distinguish between legitimate and malicious user activity on the network.
In fact, IBM's 2023 Cost of a Data Breach Report found that breaches caused by stolen or compromised credentials required roughly 11 months from detection to recovery the longest response lifecycle among all infection vectors.
Martin Borrett, Technical Director, IBM Security, UK, and Ireland (UKI) commented:
Our findings reveal that identity is increasingly being weaponised against enterprises, exploiting valid accounts and compromising credentials. It also shows us that the biggest security concern for enterprises stems not from novel or cryptic threats, but from well-known and existing ones.
Addressing cybersecurity challenges requires a strategic approach, emphasising the reinforcement of foundational security measures. Streamlining identity management through a unified Identity and Access Management (IAM) provider and strengthening legacy applications with modern security protocols are crucial steps in mitigating risks. Additionally, subjecting your system to rigorous stress tests by skilled offensive security teams proves invaluable in uncovering potential weaknesses. This insight is pivotal for crafting a robust incident response plan that engages all teams, from IT professionals to C-suite executives.
Julian David, CEO of techUK, added:
In an era marked by the growing sophistication of cybercriminals who exploit legitimate accounts to breach business defences, IBM's X-Force Threat Intelligence Index serves as a stark wake-up call.
The report underscores a troubling pattern where half of the cyberattacks in the UK rely on legitimate accounts for initial access, presenting significant challenges to businesses' recovery endeavours. To effectively combat this threat, businesses must adopt a strategic approach, integrating modern security protocols to mitigate risks and strengthen their defences against the ever-evolving landscape of cyber threats.
Further key UK findings include:
Malware made up 30% of security incidents observed in the UK.
Ransomware (30%) and cryptominers (20%) were the top malware types encountered in the country.
The impact of attacks was evenly distributed with extortion, digital currency mining and data leaks each making up 25% of total impacts in the UK.
This marks a shift from 2022, when half the cases X-Force observed in the UK involved extortion (57%) twice the global average followed by data theft (29%).
The professional, business and consumer services industry was the most targeted sector in the UK, representing 39% of cases.
Energy (30%) and finance & insurance (17%) were the second and third most targeted industries in UK, respectively.
Manufacturing was the most targeted industry in Europe, accounting for 28% of cases.
Europe overall experienced the highest percentage of incidents within the energy sector at 43%, as well as finance and insurance at 37%.
Major takeaways from the global report included:
Attacks on critical infrastructure reveal industry faux pas.
Worldwide, an alarming 69.6% of attacks that X-Force responded to were against critical infrastructure organisations, an alarming finding highlighting that cybercriminals are wagering on these high value targets' need for uptime to advance their objectives.
In 84% of attacks on critical sectors globally, compromise could have been mitigated with patching, multi-factor authentication, or least-privilege principals indicating that what the security industry historically described as basic security may be harder to achieve than portrayed.
Exploiting public-facing appl
Most recent headlines
01/04/2025
USHER's London takeover is in full swing. After kicking off his sold-out run of shows at the O2 Arena to rave reviews, the R&B icon joined forces with Spoti...
01/04/2025
Innovative program empowers partners with growth, efficiency and collaboration
Herndon, Va., April 1, 2025 ST Engineering iDirect, a global leader in satelli...
01/04/2025
MELBOURNE, Fla., April 1, 2025 - L3Harris Technologies (NYSE: LHX) will release its first quarter 2025 financial results before the market opens on Thursday, Ap...
01/04/2025
Calrec Craft Interview: Aston Fearon, Sound Supervisor In this craft interview, Aston Fearon speaks to us about how his career in sound started, projects he'...
01/04/2025
MONT-SAINT-GUIBERT, Belgium Telestream has integrated intoPIX's JPEG XS technology into Telestream's PRISM waveform monitors, which Telestream says will...
01/04/2025
BURLINGTON, Mass. Avid has signed a strategic collaboration agreement with Amazon Web Services (AWS), to deliver a cloud-based production framework that helps f...
01/04/2025
LONDON and NEW YORK The United Football League (UFL) has signed a new global partnership with sports broadcaster DAZN to broadcast every game of the UFL's 2...
01/04/2025
In a groundbreaking bid to streamline and democratize the production process, Netflix has laid out how it is developing a new Media Production Suite, that t...
01/04/2025
PHILADELPHIA Comcast Business has announced that it has completed its acquisition of Nitel, a U.S. managed services provider headquartered in Chicago, from inte...
01/04/2025
NEW YORK A team of research industry veterans, led by Tod Johnson have launched a new consumer insights and analytics platform, Tenetic, that offers both local ...
01/04/2025
V-Nova, a leading provider of compression solutions, today announced its inaugural participation in a patent pool, joining the Access Advance HEVC Patent Pool. ...
01/04/2025
Cinnafilm, a global leader in video optimization solutions, today announced that it will launch Tachyon LIVE, its groundbreaking live IP standards and format co...
01/04/2025
HighField AI, an advanced AI-powered solution designed to automate repetitive tasks within the media production workflow, today announced that it will demonstra...
01/04/2025
Globecast has expanded its use of Net Insight's Nimbra technology by deploying Nimbra Edge, significantly streamlining its media transport operations. This ...
01/04/2025
EdgePeak enables software architects and developers to design and build their own content delivery network (CDN) while reducing streaming costs, fighting video...
01/04/2025
Cinnafilm to preview the innovation at the 2025 NAB Show
Cinnafilm, a global leader in video optimization, has collaborated with NVIDIA to unveil a groundbreak...
01/04/2025
Leading video software provider Synamedia, will showcase its innovation-driven approach to solving the biggest challenges facing customers today and in the futu...
01/04/2025
AJA Debuts IP and 12G-SDI Innovations Ahead of NAB 2025
Brie Clayton April 1, 2025
0 Comments
New tools optimize media and entertainment and proAV wo...
01/04/2025
Bit Part Introduces bitbox mini, the Smallest and Lightest Solution for Ultra-Lo...
01/04/2025
IABM Unveils Bold Transformation at NAB Show, Prioritizing Member Value
Brie Clayton April 1, 2025
0 Comments
IABM is delivering a strategic transform...
01/04/2025
OOONA Introduces Multilingual QC Tool for Subtitling Workflows
Brie Clayton April 1, 2025
0 Comments
See OOONA on booth W4209 at the NAB Show, Las Veg...
01/04/2025
Adopting open standards, the solution aims to provide workflow standardisation, allowing for automation and other innovations across a diverse range of markets
...
01/04/2025
Submissions will be accepted up until 23:59 PST on 2nd April
By Jenny Priestley
Published: March 24, 2025 Updated: April 1, 2025
Submissions will be acc...
01/04/2025
The AI issue takes a look at how AI is reshaping broadcasting, including areas such as sports commentary and archiving and storage, plus we discover how Norways...
01/04/2025
Joining the company with more than two decades of experience forging and scaling alliances in the industry, Wastcoats role will support TVUs strategic developme...
01/04/2025
At the beginning of the year, Rich Welsh, senior vice president with Deluxe, was appointed the new president of Society of Motion Picture and Television Enginee...
01/04/2025
STAMFORD, Conn. and NEW YORK Charter's Spectrum pay TV operations are continuing its previously announced strategy of adding more streaming services to its ...
01/04/2025
HUNT VALLEY, Md. Sinclair, Inc. and its subsidiary, ONE Media Technologies, have announced that members of their leadership team will be participating in multip...
01/04/2025
01 04 2025 - Media release Bus Stop Films' first feature Boss Cat to begin production in June
Boss Cat cast (L-R): Olivia Hargroder, Penny Downie and Juli...
01/04/2025
PremiumBeat - Flexible, Unlimited Music For Creators
Brie Clayton March 31, 2025
0 Comments
Back in November of 2024, PremiumBeat made a bold move tha...
01/04/2025
MLB 2025: TNT Sports Chooses Remote Production for MLB Tuesday,' Upgrades C...
01/04/2025
SVG All-Stars: Francisco Contreras, Executive Director, Field Operations, FOX Sp...
01/04/2025
MILTON drones get a boost with Rohde & Schwarz SIGINT integration Rohde & Schwarz and MILTON have partnered to integrate advanced signals intelligence technol...
01/04/2025
Rohde & Schwarz presents comprehensive R&S ELEKTRA portfolio for reproducible, s...
01/04/2025
Create Complex Compositions with Unlimited Layers with FOR-A MixBoard Powered by ClassX...
01/04/2025
Article courtesy of Digital Production Germany
Read the article
Digital Production Germany magazine editor, Bela Beier, recently talked to Nara's Steve Br...
01/04/2025
Article courtesy of Digital Media World
Read the article
Light Iron uses Nara to handle file navigation, content streaming and information sharing workflow ef...
01/04/2025
Article courtesy of British Cinematographer
Read the article
DoP Don Burgess, VFX supervisor Kevin Baillie and colourist Maxine Gervais pulled their talents t...
01/04/2025
Polesi ski made a name for himself early in his career. Renowned for his attention to detail and ability to mix his creative and technical skills, Polesi ski st...
01/04/2025
visionOS 2.4 is available today, bringing the first set of powerful Apple Intelligence features that help users communicate, write, and express themselves on Ap...
01/04/2025
Facebook
Twitter
LinkedIn
Defence Science and Technology Agency (DSTA) and...
31/03/2025
Ready, set, Party Time!' SBS News empowers young voters with a new politica...
31/03/2025
31 January, 2024
Company News
Tokyo, January 31, 2024 - Hitachi, Ltd. (TSE:6501) today announced the following executive
changes to improve corporate value....
31/03/2025
MELBOURNE, Fla., March 31, 2025 - L3Harris Technologies (NYSE: LHX) has complete...
31/03/2025
Vice Admiral Jan Willem Hartman, commander of the Dutch Materiel and IT Command, and Chris Aebli, President, Tactical Communications, L3Harris Technologies, sig...
31/03/2025
The L3Harris team visited HMS GLASGOW, the first T26 Global Combat Ship, current...
31/03/2025
SEATTLE As the WNBA prepares to kick off the 2025 season, the Seattle Storm WNBA team has announced a multi-year deal with Sinclair's KOMO and KUNS station...
31/03/2025
Digital Nirvana, a provider of leading-edge AI-powered media solutions, today announced a global Alliance Partnership with Avid to bring advanced AI metadata c...
31/03/2025
BeckTV, a premier systems integrator for the broadcast media industry, today announced that Kate Gazdic has joined the company as a senior procurement specialis...
31/03/2025
MainConcept, a leading provider of video and audio codecs, has announced a series of key codec advancements that enable customers to realize significant time an...