Site navigation

Report: 46% of Enterprise Passwords Vulnerable to Cracking

Graham Turner

,

valid credentials attack
The key findings of a new report reveal a decline in the ability of security controls to stop cyber-attacks, with prevention rates falling and attackers increasingly bypassing defences using valid credentials.

Picus Security has warned that defensive effectiveness against cyber-threats is slipping, as its latest Blue Report shows a decline in prevention rates and growing attacker success.

Based on more than 160 million real-world attack simulations in live production environments, the Blue Report 2025 found that while cyber-attacks continue to grow in volume and sophistication, the ability of security controls to stop them is deteriorating.

In 46% of environments tested, at least one password hash was successfully cracked – up from 25% in 2024 – while data exfiltration attempts were blocked only 3% of the time, down from 9% last year.

The report noted that infostealer malware has tripled in prevalence, and attackers are increasingly using valid logins to bypass defences. Attacks using valid credentials succeeded 98% of the time, making the technique one of the most reliable ways to evade detection.

“We must operate under the assumption that adversaries already have access,” said Dr. Süleyman Ozarslan, co-founder of Picus Security and VP of Picus Labs.

“An ‘assume breach’ mindset pushes organisations to detect the misuse of valid credentials faster, contain threats quickly, and limit lateral movement — which requires continuous validation of identity controls and stronger behavioural detection.”

The Blue Report also highlighted persistent challenges in stopping ransomware. BlackByte was identified as the hardest strain to prevent, with a prevention effectiveness rate of just 26%. BabLock and Maori followed at 34% and 41% respectively.


Recommended reading


Detection also remains a weak point.

Discovery techniques such as System Network Configuration Discovery and Process Discovery scored below 12% in prevention effectiveness. Logging coverage held steady at 54%, yet only 14% of attacks generated alerts — a shortfall Picus attributed to gaps in detection rule configuration, logging, and system integration.

Overall prevention effectiveness dropped from 69% in 2024 to 62% in 2025, reversing gains made last year. According to Picus, the findings illustrate how quickly security controls can degrade without ongoing oversight and validation.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data