According to Red Canary‘s 2024 Threat Detection Report, the landscape of cyber-threats has seen a shift with cloud account vulnerabilities, leading to a 16-fold increase in attacks on cloud environments compared to the previous year.
The researchers identified a rise in detections associated with T1078.004: Cloud Accounts, a key technique outlined in the MITRE ATT&CK framework for cloud account compromises. This technique, which ranked a mere 46th place in 2022, climbed to the fourth most prevalent tactic employed by threat actors in 2023.
“The top 10 threats and techniques change minimally year over year, so the drift that we’re seeing in the 2024 report is significant. The rise of cloud account compromises from 46 to number 4 is unprecedented in our dataset–and it’s a similar story with email forwarding rules,” said Keith McCammon, chief security officer, Red Canary
The numbers come on the backdrop of organisations continuing to migrate their systems and data to the cloud, to which adversaries are capitalising, by adopting new strategies tailored to exploit weaknesses in cloud environments.
Notably, attackers have been observed leveraging short-term tokens to illicitly access and manipulate APIs, effectively circumventing traditional security measures. This method not only grants them unauthorised entry but also complicates detection efforts, as the malicious activity often mirrors the actions of authorised users.
According to the report, following initial access, attackers engage in systematic reconnaissance to identify potential vulnerabilities, paving the way for further exploitation. This reconnaissance phase serves as a precursor to various nefarious activities, including social engineering tactics aimed at manipulating help desk personnel or exploiting misconfigurations to access sensitive data.
Recommended reading
- Compromised Cloud Accounts Frequently Used in Illegal Crypto Mining
- Misconfigured Cloud Account Leaks Data on Half a Million People
- Cloud Backup Data: The Do’s and Don’ts for Ransomware Threats
In parallel to the surge in cloud-related threats, Red Canary’s report also underscores the evolving landscape of social engineering techniques used by malicious actors. Phishing campaigns, in particular, have evolved to bypass conventional email security measures, utilising tactics such as compressed archives, container files, and even non-email delivery vehicles like QR codes and SEO poisoning.
“The golden thread connecting these modes of attack is identity,” continued McCammon.
“To access cloud accounts and SaaS applications, adversaries must compromise some form of identity or credential, and one that is highly privileged can grant an adversary untold access to valuable accounts, underscoring the critical importance of securing corporate identities and identity providers.”





