Site navigation

Report: Half of All Enterprise Passwords Vulnerable to Cracking

Tom Quinn

,

enterprise cybersecurity, enterprise password,
“We must operate under the assumption that adversaries already have access,” said Dr. Süleyman Ozarslan, Picus Security.

Credentials are becoming easy to steal, and hackers almost impossible to stop, according to a new report from Picus Security, which has identified some significant blind spots among enterprise security systems.  

The security firm’s latest Blue Report investigated more than 160 million attack simulations across real environments, and found that security gaps led to 19% resulting in full domain admin compromise, and another 22% allowing administrator access.  

While that shows some improvement on previous studies, Picus’ testing uncovered some serious and persistent vulnerabilities across enterprise networks. 

Among the most troubling, password cracking attempts were successful in almost half (46%) of all tests, almost double the previous year’s rate. 

That risk is compounded by attacks utilising Valid Accounts Technique T1078, where attackers use legitimate, stolen credentials like known passwords to gain unauthorised access and escalate privileges, which the study found worked across 98% of IT environments.

Tech firms miss half of all threats

Picus said that the results suggest threat actors with stolen credentials are practically unstoppable, with such techniques among the most reliable ways for them to bypass traditional defences undetected. 

However, these detection issues go much deeper than stolen credentials. The data shows that nearly half of all attacker behaviours go unlogged, with alert scores being as low as 13% for the banking and financial services sector, meaning that only around one in ten attacks triggered any alarm.

Organisations working in the tech sector didn’t fare much better, with an alert rate of just 17% and a log score of 47%, evidence that half of all attacks go unnoticed for firms generally considered the most adept at cyber defence.  

Overall, the report found that the average prevention scores fell across the board, down from 69% last year to 62% for 2025, suggesting that many organisations are struggling to keep up with the growing sophistication of attackers’ tactics, and that previously effective controls may be losing their edge. 

That is perhaps most visible in malware prevention. While malware-based threats are among the oldest and most widely recognised attack vectors, Picus found that malware prevention across networks had slipped to 60%, down from 71% in 2024.

Despite the familiarity of malware, and the constant warnings from security professionals, the report claims that many organisations are ‘dropping the ball’ on its detection. 

Data exfiltration is getting worse

Perhaps as a consequence of underlying problems in detection and prevention, attackers are having more success with data exfiltration than ever before.

Picus found that data exfiltration prevention is now near zero, with only 3% of data theft attempts blocked, down almost three times from 2024 levels, which means that for the third year in a row, data exfiltration remains the least prevented attack vector.

That is especially troubling given the recent spike in ransomware attacks. The now notorious Scattered Spider, for example, had a prevention score of only 50% even with so much attention being paid to their specific tactics.

Meanwhile, groups like BlackByte see even more success, with just 26% of their attacks prevented, even after gaining some notoriety in the security community. 

Picus warned that in spite of the growing prevalence of infostealers and double extortion ransomware tactics, most organisations still lack the ability to detect and prevent the transfer of sensitive data by such groups.

The report argues that even as awareness of adversary behaviour has increased thanks to the spotlight placed on the likes of Scattered Spider, many common threat tactics are persistently ‘under-prevented’.


Recommended reading


Following the MITRE ATT&CK framework, Picus found that low-noise ‘Discovery’ tactics are still the least prevented (29.75%), featuring behaviours such as account enumeration, host discovery, and network scanning activities that frequently go unnoticed. 

However, Execution (37.21%), Impact (37.84%), and Persistence (40.10%) tactics also ranked among the least prevented. These involve actions like script execution, payload deployment, service abuse, and sabotage, all difficult to catch without tight endpoint controls.

“We must operate under the assumption that adversaries already have access,” said Dr. Süleyman Ozarslan, co-founder of Picus Security. 

“An ‘assume breach’ mindset pushes organisations to detect the misuse of valid credentials faster, contain threats quickly and limit lateral movement — which requires continuous validation of identity controls and stronger behavioural detection.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data