
LONDON, UK. Apr. 17, 2025 -- IBM (NYSE: IBM) today released the 2025 X-Force Threat Intelligence Index, which reveals the UK remained the most-attacked country in Europe, accounting for 25% of monitored incidents in the region. The report highlights that cybercriminals continued to pivot to stealthier tactics, with lower-profile credential theft spiking, while ransomware attacks on enterprises declined. Globally, IBM X-Force observed an 84% increase in emails delivering infostealers in 2024 compared to the prior year, a method threat actors relied heavily on to scale identity attacks.
The 2025 report tracks new and existing trends and attack patterns pulling from incident response engagements, dark web and other threat intelligence sources.
Some key global findings in the 2025 report include:
Critical infrastructure organisations accounted for 70% of all attacks that IBM X-Force responded to last year, with more than one quarter of these attacks caused by vulnerability exploitation.
More cybercriminals opted to steal data (18%) than encrypt it (11%) as advanced detection technologies and increased law enforcement efforts pressure cybercriminals to adopt faster exit paths.
Nearly one in three incidents observed in 2024 resulted in credential theft, as attackers invest in multiple pathways to quickly access, exfiltrate and monetise login information.
Cybercriminals are most often breaking in without breaking anything capitalising on identity gaps overflowing from complex hybrid cloud environments that offer attackers multiple access points, said Mark Hughes, Global Managing Partner of Cybersecurity Services at IBM. Businesses need to shift away from an ad-hoc prevention mindset and focus on proactive measures such as modernising authentication management, plugging multi-factor authentication holes and conducting real-time threat hunting to uncover hidden threats before they expose sensitive data.
Georgie Cohen, UKI Cybersecurity Services Leader at IBM Consulting, commented: "While this year's Index places Europe third behind North America and Asia, the UK faces the harshest impact in Europe from cyberattacks. As cybercriminals continue to refine their strategies to maximise damage, complacency is not an option. By analysing the key trends outlined in the X-Force Index, we can anticipate emerging threats and stay ahead in the fight against cybercrime."
Patching Challenges Expose Critical Infrastructure Sectors to Sophisticated Threats
Reliance on legacy technology and slow patching cycles prove to be an enduring challenge for critical infrastructure organisations, as cybercriminals exploited vulnerabilities in more than one-quarter of incidents that IBM X-Force responded to on this sector last year.
In reviewing the common vulnerabilities and exposures (CVEs) most mentioned on dark web forums, IBM X-Force found that four out of the top ten have been linked to sophisticated threat actor groups, including nation-state adversaries, escalating the risk of disruption, espionage and financial extortion. Exploit codes for these CVEs were openly traded on numerous forums fueling a growing market for attacks against power grids, health networks and industrial systems. This sharing of information between financially motivated and nation-state adversaries highlights the increasing need for dark web monitoring to help inform patch management strategies and detect potential threats before they are exploited.
Automated Credential Theft Sparks Chain Reaction
In 2024, IBM X-Force observed an uptick in phishing emails delivering infostealers and early data for 2025 reveals an even greater increase of 180% compared to 2023. This upward trend fueling follow-on account takeovers may be attributed to attackers leveraging AI to create phishing emails at scale.
Credential phishing and infostealers have made identity attacks cheap, scalable and highly profitable for threat actors. Infostealers enable the quick exfiltration of data, reducing their time on target and leaving little forensic residue behind. In 2024, the top five infostealers alone had more than eight million advertisements on the dark web and each listing can contain hundreds of credentials. Threat actors are also selling adversary-in-the-middle (AITM) phishing kits and custom AITM attack services on the dark web to circumvent multi-factor authentication (MFA). The rampant availability of compromised credentials and MFA bypass methods indicates a high-demand economy for unauthorised access that shows no signs of slowing down.
Ransomware Operators Shift to Lower-Risk Models
While ransomware made up the largest share of malware cases in 2024 at 28%, IBM X-Force observed a reduction in ransomware incidents overall compared to the prior year, with identity attacks surging to fill the void.
International takedown efforts are pushing ransomware actors to restructure high-risk models towards more distributed, lower-risk operations. For example, IBM X-Force observed previously well-established malware families including ITG23 (aka Wizard Spider, Trickbot Group) and ITG26 (QakBot, Pikabot) to either completely shut down operations or turn to other malware, including the use of new and short-lived families, as cybercrime groups attempt to find replacements for the botnets that were taken down last year.
Additional findings from the 2025 report include:
Evolving AI threats. While large-scale attacks on AI technologies didn't materialize in 2024, security researchers are racing to identify and fix vulnerabilities before cybercriminals exploit them. Issues like the remote code execution vulnerability that IBM X-Force discovered in a framework for building AI agents will become more frequent. With adoption set to grow in 2025, so will the incentives for adversaries to develop specialized attack toolkits targeting A
More from IBM
06/05/2025
LONDON, UK, May 6, 2025 /PRNewswire/ -- Today at the company s annual THINK event, IBM (NYSE: IBM) is unveiling new hybrid technologies that break down the long...
02/05/2025
Data Communications Company has announced its partnership with IBM to modernise ...
17/04/2025
LONDON, UK. Apr. 17, 2025 -- IBM (NYSE: IBM) today released the 2025 X-Force Thr...
08/04/2025
ARMONK, N.Y., April 8, 2025 /PRNewswire/ -- IBM (NYSE: IBM) today announced the IBM z17, the next generation of the company s iconic mainframe, fully engineered...
19/03/2025
London, UK March 19, 2025 Finastra, a global provider of financial services software applications, and IBM (NYSE: IBM) today unveiled their collaboration on...
06/02/2025
Oxford, U.K., 6 February 2025 New research from Oxford Economics, published to...
16/01/2025
LONDON, U.K., January 16, 2025 - IBM (NYSE: IBM) today announced its intent to a...
15/01/2025
London, 15 January, 2025 Frontline emergency services will benefit from a new communications network that will modernise how they work together, as the govern...
06/01/2025
London, 6 January 2025 IBM today announced that Leon Butler has been named General Manager, IBM in the UK and Ireland. He succeeds Dr Nicola Hodson, who will ...
09/12/2024
LONDON, UK, 9 Dec, 2024: IBM (NYSE: IBM) has unveiled breakthrough research in optics technology that could dramatically improve how data centers train and run ...
05/11/2024
ording to observations in the 2024 IBM X-Force Threat
Intelligence Index.
The...
04/11/2024
Dublin and London, 4 November, 2024 IBM today announced that Nathan Cullen has been appointed Country General Manager and Technology Leader, IBM Ireland. He s...
13/08/2024
LONDON, August 13, 2024 /PRNewswire/ -- Two IBM-developed algorithms (NYSE: IBM)...
30/07/2024
LONDON, UK, 30 July, 2024 -- IBM (NYSE: IBM) today released its annual Cost of a Data Breach Report revealing the average cost of a data breach in the UK reache...
09/07/2024
IBM announced it has acquired SiXworks Limited (Ltd.), a UK-based consultancy serving the UK defence sector and specialising in digital transformation in highly...
17/06/2024
LONDON, June 17, 2024 /PRNewswire/ -- IBM (NYSE: IBM) and The All England Lawn T...
29/05/2024
LONDON, UK, 29 May 2024 A new study by the IBM (NYSE: IBM) Institute for Busin...
23/05/2024
IBM Security's Martin Borrett shares his thoughts on how cybersecurity will be impacted in the age of generative AI. Please see the full article here in AI ...
12/05/2024
IBM UK & Ireland Chief Executive, Dr Nicola Hodson, recently sat down with Daily...
30/04/2024
Dr. Nicola Hodson, Chief Executive, IBM UK & Ireland introduces the UK findings of an IBM study on female leadership in the age of AI
Advances in Artificial In...
25/04/2024
LONDON, UK, April 25, 2024 IBM (NYSE: IBM) today announced new storage capabilities that give clients choice and control in the data center to maximise perfor...
05/04/2024
Madrid, Spain April 5, 2024 The President of the Government, Pedro S nchez, ...
26/03/2024
London, UK, March 26, 2024 Today, IBM (NYSE: IBM) announced the EMEA geography winners of the 2024 IBM Partner Plus Awards, which celebrate IBM partners who a...
21/02/2024
LONDON, UK, Feb 21, 2024 IBM today released the 2024 X-Force Threat Intelligen...
06/02/2024
LONDON, U.K., February 6, 2024 IBM (NYSE: IBM) today announced IBM LinuxONE 4 ...
18/01/2024
Today, IBM is announcing that it has signed a definitive agreement to acquire application modernization capabilities from Advanced, bringing a combination of ta...
10/01/2024
LONDON and ARMONK, N.Y., January 10, 2024 New research commissioned by IBM (NYSE: IBM) found that more than a third of UK organisations with over 1,000 employ...
13/12/2023
LONDON, UK, December 13, 2023 - Today, IBM (NYSE: IBM) signed a contract with the NATO Communications and Information Agency (NCI Agency) to help strengthen the...
05/12/2023
LONDON, UK, 5 December, 2023 Amazon Web Services, Inc. (AWS), an Amazon.com co...
30/11/2023
LONDON, UK, Nov 30, 2023 IBM (NYSE: IBM) today announced new efforts that apply its geospatial AI technologies, including IBM's geospatial foundation mode...
22/11/2023
DUBLIN, 22 November, 2023 - To help close the global artificial intelligence (AI...
08/11/2023
Wednesday 8 November, London: Today, IBM launched its new report Leadership in ...
27/10/2023
Arvind Krishna, Chairman and CEO of IBM, met recently with one of the UK's leading business editors in New York for a major profile interview.
The Sunday T...
18/10/2023
LONDON, UK, October 18, 2023: IBM (NYSE: IBM) today announced an expansion of it...
13/09/2023
LONDON, UK, September 13, 2023 IBM (NYSE: IBM) today announced its role as an Associate Pathway Partner of the 2023 United Nations Climate Change Conference (...
17/08/2023
LONDON, UK, August 17, 2023 - Today, IBM (NYSE: IBM) is expanding its collaborat...
14/08/2023
LONDON, UK, August 14, 2023 - Executives in the UK estimate that 41% of their wo...
24/07/2023
LONDON, UK. 24 July 2023 IBM Security today released its annual Cost of a Data Breach Report,1 which revealed that UK organisations pay an average of £3.4m fo...
20/07/2023
The Crown Commercial Service (CCS) has announced a new 3-year Memorandum of Unde...
18/07/2023
LONDON, UK; July 18, 2023London, UK; July 18, 2023 - IBM (NYSE:IBM) today announ...
27/06/2023
LONDON, UK, June 27, 2023 A new study by the IBM (NYSE: IBM) Institute for Bus...
21/06/2023
LONDON, U.K. and ARMONK N.Y., June 21, 2023 IBM (NYSE: IBM) and The All Englan...
19/05/2023
IBM Consulting has been selected to revolutionise Diageo's IT environment by...
23/04/2023
You may have seen recent media coverage relating to the Confederation of British Industry (CBI), the largest business association in the UK.
IBM agrees with th...
17/04/2023
LONDON, UK, April 17, 2023 - A new global IBM (NYSE: IBM) Institute for Business...
03/04/2023
IBM is pleased to see the UK government making progress on its plans to develop a pro-innovation approach to AI regulation. Like similar approaches in Singapore...
14/03/2023
LONDON, UK, March 1, 2023 - IBM (NYSE: IBM) announced today that it is accepting...