{"id":117605,"date":"2025-04-20T07:10:02","date_gmt":"2025-04-20T06:10:02","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=117605"},"modified":"2025-04-20T08:09:57","modified_gmt":"2025-04-20T07:09:57","slug":"critical-infrastructure-accounted-for-70-attacks-that-ibm-x-force-responded-to","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2025\/04\/20\/critical-infrastructure-accounted-for-70-attacks-that-ibm-x-force-responded-to\/","title":{"rendered":"Critical infrastructure accounted for 70% attacks that IBM X-Force responded to"},"content":{"rendered":"\n<p>IBM released the <em>2025 X-Force Threat Intelligence Index<\/em>&nbsp;highlighting that cybercriminals continued to pivot to stealthier tactics, with lower-profile credential theft spiking, while ransomware attacks on enterprises declined. IBM X-Force observed an 84% increase in emails delivering infostealers in 2024 compared to the prior year, a method threat actors relied heavily on to scale identity attacks.<\/p>\n\n\n\n<p>The 2025 report tracks new and existing trends and attack patterns \u2013 pulling from incident response engagements, dark web and other threat intelligence sources.<\/p>\n\n\n\n<p>Some key findings in the 2025 report include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Critical infrastructure organisations accounted for 70% of all attacks that IBM X-Force responded to last year, with more than one quarter of these attacks caused by vulnerability exploitation.<\/li>\n\n\n\n<li>More cybercriminals opted to steal data, 18% than encrypt it, 11% as advanced detection technologies and increased law enforcement efforts pressure cybercriminals to adopt faster exit paths.<\/li>\n\n\n\n<li>The Middle East was the fourth most-targeted region globally in 2024, accounting for 10% of attacks, up from 7% in 2023. Saudi Arabia and the UAE were the most impacted.<\/li>\n\n\n\n<li>The finance and insurance sector remained the most targeted industry, representing 61% of incidents, reflecting the Middle East region\u2019s growing financial landscape and associated risks. Other targeted industries included energy, 17%, professional, business, and consumer services, 11%, transportation, 6%, and media, 6%.<\/li>\n<\/ul>\n\n\n\n<p>&#8220;As the Middle East continues to advance its digital transformation agendas, cybercriminals are adapting just as quickly- shifting to low-profile, identity-based attacks that are harder to detect,\u201d said Saad Toma, General Manager of IBM Middle East and Africa.<\/p>\n\n\n\n<p>\u201cWith sectors like finance, energy, and government increasingly targeted, organisations in the region must invest in intelligence-led security strategies that prioritise identity protection, continuous monitoring, and rapid incident response.\u201d<\/p>\n\n\n\n<p>Reliance on legacy technology&nbsp;and slow patching cycles prove to be an enduring challenge for critical infrastructure organisations globally and in the Middle East, where exploitation of public-facing applications represented 33% of initial access methods.<\/p>\n\n\n\n<p>In reviewing the common vulnerabilities and exposures, CVEs most mentioned on dark web forums, IBM X-Force found that four out of the top ten have been linked to sophisticated threat actor groups, including nation-state adversaries, escalating the risk of disruption, espionage and financial extortion.<\/p>\n\n\n\n<p>In 2024, IBM X-Force observed an uptick in phishing emails delivering infostealers and early data for 2025 reveals an even greater increase of 180% compared to 2023. This upward trend fuelling follow-on account takeovers may be attributed to attackers leveraging AI to create phishing emails at scale.<\/p>\n\n\n\n<p>Credential phishing and infostealers have made identity attacks cheap, scalable and highly profitable for threat actors. In the Middle East, malware-infostealers and recon, scanning tools each accounted for 50% of observed attacks, reinforcing a regional focus on stealth and information gathering. Infostealers enable the quick exfiltration of data, reducing their time on target and leaving little forensic residue behind.<\/p>\n\n\n\n<p>In 2024, the top five infostealers alone had more than eight million advertisements on the dark web and each listing can contain hundreds of credentials. Threat actors are also selling adversary-in-the-middle, AITM phishing kits and custom AITM attack services on the dark web to circumvent multi-factor authentication, MFA.<\/p>\n\n\n\n<p>While ransomware made up the largest share of malware cases in 2024 at 28%, IBM X-Force observed a reduction in ransomware incidents overall compared to the prior year, with identity attacks surging to fill the void.<\/p>\n\n\n\n<p>International takedown efforts are pushing ransomware actors to restructure high-risk models towards more distributed, lower-risk operations.<\/p>\n\n\n\n<p>For example, IBM X-Force observed previously well-established malware families including ITG23, aka Wizard Spider, Trickbot Group&nbsp;and ITG26, QakBot, Pikabot to either completely shut down operations or turn to other malware, including the use of new and short-lived families, as cybercrime groups attempt to find replacements for the botnets that were taken down last year.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>IBM released the 2025 X-Force Threat Intelligence Index&nbsp;highlighting that cybercriminals continued to pivot to stealthier tactics, with lower-profile credential theft spiking, while ransomware attacks on enterprises declined. IBM X-Force observed an 84% increase in emails delivering infostealers in 2024 compared to the prior year, a method threat actors relied heavily on to scale identity attacks. [&hellip;]<\/p>\n","protected":false},"author":59,"featured_media":117621,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[16003,14804,5,16061,15994,12449,54,13],"tags":[464,19532],"class_list":["post-117605","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-africa","category-cybersecurity","category-enterprise-security","category-europe","category-middle-east","category-north-america","category-research","category-top-stories","tag-ibm","tag-saad-toma"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/117605","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/59"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=117605"}],"version-history":[{"count":4,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/117605\/revisions"}],"predecessor-version":[{"id":117614,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/117605\/revisions\/117614"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/117621"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=117605"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=117605"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=117605"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}