AI is shrinking attack timelines, identity is now a primary attack vector, and extortion is moving beyond encryption – these are just some of the headline findings from Unit 42’s Global Incident Response Report.
The Palo Alto Network researchers analysed over 750 major cyber incidents across 50 countries in every major industry in their report, which found a striking shift in the speed and methods used by threat actors.
Attackers needed only 72 minutes to move from initial access to data exfiltration in the fastest cases observed by Unit 42, which is four times faster than last year. AI is being employed across various cyber-attack methods, from phishing and reconnaissance, to scripting and operational execution.
The research’s findings on identity attacks coincides with recent patterns showing it’s a growing vulnerability, with identity weaknesses playing a part in about 90% of all of Unit 42’s investigations. Attackers are exploiting stolen credentials to infiltrate systems laterally without triggering security alerts.
Attackers are still exploiting the supply chain; 23% of incidents saw third-party vendors leveraged by attackers.
Complexity is increasing, with 87% of intrusions analysed by Unit 42 showing activity across more than one attack surface, with coordinated activity across different vectors and networks.
Modern attacks are coinciding with everyday workflows more and more, with nearly 48% of cyber incidents including some form of browser-based activity, from email, SaaS use, and web access.
Recommended reading
- Does Identity Security Have a “Post-Login” Problem?
- Comment | Identity, Not Surveillance, is Facial Recognition’s Future
- Report: Just 1% of Firms Are Prepared for the AI Identity Surge
Intriguingly, attackers are abandoning encryption, with a 15% decrease in encryption-based extortion. Attackers instead go straight for disruption and data theft to create immediate pressure on victims, whilst avoiding traditional detection.
Though attacks are getting more sophisticated and complex, over exposure of systems seems to be the real death nail in defense.
Tool sprawl and a myriad of vendors creates overcomplicated defence spectrums, leaving gaps of exposure and making consistency difficult.
These disconnected surfaces mean that attack signals can be missed – even if a detection system blares the alarms, security teams can miss this if they look at the wrong source.
With these expansive defence controls, one identity compromise can allow attackers to penetrate deeper into a system, escalating their privileges and the damage of their attack.





