Sony Pixel Power calrec Sony

IBM Report: Cybercriminals Intensify Attacks on User Identities in the UK, Complicating Recovery Efforts for Enterprises

21/02/2024

LONDON, UK, Feb 21, 2024 IBM today released the 2024 X-Force Threat Intelligence Index highlighting an emerging global crisis as cybercriminals double down on exploiting user identities to compromise enterprises.

According to IBM X-Force, IBM Consulting's security services arm, cybercriminals last year generated more opportunities to log in to corporate networks through valid accounts, instead of hacking into them making this tactic a preferred weapon of choice for threat actors.

The X-Force Threat Intelligence Index is based on insights and observations from monitoring over 150 billion security events per day in more than 130 countries. In addition, data is gathered and analysed from multiple sources within IBM, including IBM X-Force Threat Intelligence, Incident Response, X-Force Red, IBM Managed Security Services, and data provided from Red Hat Insights and Intezer , which contributed to the 2024 report.

An emerging identity crisis

The report data revealed that exploiting valid accounts has become the path of least resistance for cybercriminals, with billions of compromised credentials accessible on the Dark Web.

According to the report, 50% of cyberattacks in the UK involved the exploitation of valid accounts as the initial access vector' and a further 25% of cases involved the exploitation of public-facing applications. Across Europe, X-Force observed a 66% year-on-year rise in attacks caused by the use of valid accounts contributing to Europe's prevalence as the most targeted region of 2023 and the record number of attacks that X-Force has ever reported regionally.

The criminal ecosystem was also quick to adapt to the use of valid accounts by attackers. In 2023, X-Force observed a 266% increase in infostealing malware, which is designed to steal personal and enterprise credentials, personally identifiable information, and banking and crypto wallet information.

This easy entry for attackers is harder to detect, eliciting a costly response from enterprises. According to X-Force, worldwide, major incidents caused by attackers using valid accounts were linked to nearly 200% more complex response measures by security teams than the average incident with defenders needing to distinguish between legitimate and malicious user activity on the network.

In fact, IBM's 2023 Cost of a Data Breach Report found that breaches caused by stolen or compromised credentials required roughly 11 months from detection to recovery the longest response lifecycle among all infection vectors.

Martin Borrett, Technical Director, IBM Security, UK, and Ireland (UKI) commented:

Our findings reveal that identity is increasingly being weaponised against enterprises, exploiting valid accounts and compromising credentials. It also shows us that the biggest security concern for enterprises stems not from novel or cryptic threats, but from well-known and existing ones.

Addressing cybersecurity challenges requires a strategic approach, emphasising the reinforcement of foundational security measures. Streamlining identity management through a unified Identity and Access Management (IAM) provider and strengthening legacy applications with modern security protocols are crucial steps in mitigating risks. Additionally, subjecting your system to rigorous stress tests by skilled offensive security teams proves invaluable in uncovering potential weaknesses. This insight is pivotal for crafting a robust incident response plan that engages all teams, from IT professionals to C-suite executives.

Julian David, CEO of techUK, added:

In an era marked by the growing sophistication of cybercriminals who exploit legitimate accounts to breach business defences, IBM's X-Force Threat Intelligence Index serves as a stark wake-up call.

The report underscores a troubling pattern where half of the cyberattacks in the UK rely on legitimate accounts for initial access, presenting significant challenges to businesses' recovery endeavours. To effectively combat this threat, businesses must adopt a strategic approach, integrating modern security protocols to mitigate risks and strengthen their defences against the ever-evolving landscape of cyber threats.

Further key UK findings include:

Malware made up 30% of security incidents observed in the UK.

Ransomware (30%) and cryptominers (20%) were the top malware types encountered in the country.

The impact of attacks was evenly distributed with extortion, digital currency mining and data leaks each making up 25% of total impacts in the UK.

This marks a shift from 2022, when half the cases X-Force observed in the UK involved extortion (57%) twice the global average followed by data theft (29%).

The professional, business and consumer services industry was the most targeted sector in the UK, representing 39% of cases.

Energy (30%) and finance & insurance (17%) were the second and third most targeted industries in UK, respectively.

Manufacturing was the most targeted industry in Europe, accounting for 28% of cases.

Europe overall experienced the highest percentage of incidents within the energy sector at 43%, as well as finance and insurance at 37%.

Major takeaways from the global report included:

Attacks on critical infrastructure reveal industry faux pas.

Worldwide, an alarming 69.6% of attacks that X-Force responded to were against critical infrastructure organisations, an alarming finding highlighting that cybercriminals are wagering on these high value targets' need for uptime to advance their objectives.

In 84% of attacks on critical sectors globally, compromise could have been mitigated with patching, multi-factor authentication, or least-privilege principals indicating that what the security industry historically described as basic security may be harder to achieve than portrayed.

Exploiting public-facing appl
LINK: https://uk.newsroom.ibm.com/IBM-Report-Cybercriminals-Intensify-Attack...
See more stories from ibm

Europe Stories

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

04/08/2026

Dalet Announces Commercial Availability of Dalia, Bringing Media-Aware Agentic AI to Enterprise Productions

Dalet, a leading technology and service provider for media-rich organizations, t...

04/07/2026

Detective Conan: Fallen Angel of the Highway Opens in Dolby Cinemas Across Japan, Presented in Dolby Atmos and Dolby ...

April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

21/05/2026

Create, Control, and Personalize Your Listening Across Every Moment

Spotify has always been about helping you find something you want to listen to. And over the years, we've learned your taste and the moments that matter to ...

21/05/2026

You Know Every Song. We Saved You Two Tickets. Introducing Reserved.

Getting concert tickets today can feel like a race you're set up to lose. You show up at the right time, refresh endlessly, and still miss out. Too often, ...

21/05/2026

Books on Spotify: New Updates for Listeners and Authors

In 2022, Spotify entered a new chapter by introducing audiobooks to our platform. Since then, we've grown our catalog to include more than 700,000 titles, e...

21/05/2026

Investor Day 2026 Remarks From Spotify Co-CEOs Alex Norstrm and Gustav Sderstrm

Opening remarks ALEX Good morning everyone, I'm Alex [Norstr m]. GUSTAV And I'm Gustav [S derstr m]. ALEX Whether you've been following our j...

21/05/2026

Spotify's 2026 Investor Day Recap: Raising Ambition for the Next Era of Media

Today, Spotify hosted our third Investor Day in New York City, offering the fina...

21/05/2026

Spotifys Investor Day 2026: Ambitioniert in die nchste ra der Medien

Spotify hat heute seinen dritten Investor Day in New York City veranstaltet und der Finanzwelt tiefere Einblicke in das Gesch ft, die Produktstrategie und die l...

21/05/2026

Rcapitulatif de l'Investor Day 2026 de Spotify : Des ambitions renouveles pour la prochaine re des mdias

Aujourd'hui, Spotify a organis son troisi me Investor Day New York. En pl...

21/05/2026

Il riepilogo dell'Investor Day 2026 di Spotify: eleviamo le ambizioni per la prossima era dei media

Oggi, a New York City, Spotify ha presentato il suo terzo Investor Day, offrendo...

21/05/2026

Resumen del Investor Day 2026 de Spotify: elevando la ambicin para la prxima era de los medios

Hoy Spotify celebr su tercer Investor Day en Nueva York, donde ofrecimos a la c...

21/05/2026

Rangkuman Investor Day Spotify 2026: Meningkatkan Ambisi untuk Era Media Berikutnya

Hari ini, Spotify menyelenggarakan Investor Day yang ketiga di New York City, me...

21/05/2026

2026 (Investor Day):

2026 : (Investor Day) , , . ...

21/05/2026

2026 :

20 2026 ...

21/05/2026

Resumo do Investor Day 2026 do Spotify: elevando a ambio para a prxima era da mdia

Hoje, o Spotify realizou seu terceiro Investor Day em Nova York, oferecendo co...

21/05/2026

2026: Spotify

Spotify Investor Day ...

21/05/2026

Spotify'n 2026 Investor Day zeti: Medyann Yeni a in Byk Hedefler

Spotify bug n, 20'nci y l d n m m z kutlad m z bu y lda, finans camias na, i modelimiz, r n stratejimiz ve uzun vadeli vizyonumuz hakk nda daha detayl ...

21/05/2026

Cinematic Motion & Ethereal Flows for Sonuscore's The Score

Two new Story Packs join orchestral instrument line-up Sonuscore have just introduced two new additions to The Score, marking the instrument's first maj...

21/05/2026

Heavyocity release Oblivion Drums

30,000 samples, 99 presets & 504 loops Heavyocity are well known for their hard-hitting cinematic instruments, and their latest release is no exception to t...

21/05/2026

Rohde & Schwarz AI powered voice to data: The future of air traffic control takes flight at Airspace World 2026

Rohde & Schwarz AI powered voice to data: The future of air traffic control take...

21/05/2026

How to watch all 10 Premier League matches live in first-of-its-kind day on Sky Sports

Thursday 21 May 2026 How to watch all 10 Premier League matches live in first-o...

21/05/2026

Take Five with Faith

Tell us a little bit about your job I mainly work across paid and organic social, PPC, and SEO. The role is really varied, which I love. If you weren't a D...

21/05/2026

RT 2FM announces winner of nationwide search for next superstar DJ

Dublin DJ RKM333 wins 2FM competition and a coveted slot at this year's Forbidden Fruit Festival 2FM's search for the next big Irish DJ concluded this ...

20/05/2026

Spotify House Returns to CMA Fest With 3 Days of Nonstop Country Music

For the seventh year, Spotify is returning to CMA Fest with Spotify House, the festival's premiere destination for fans. We're taking over downtown Nash...

20/05/2026

Aero 2 from Acustica Audio

Amp-simulation software expanded Acustica Audio's latest release greatly expands on their amp-simulation platform, turning it into a complete amplifica...

20/05/2026

Arturia update the KeyLab Mk3

MainStage integration, Analog Lab improvements & more Arturia have just announced the release of an update that brings an assortment of new features to thei...

20/05/2026

SGL Carbon holds successful Annual General Meeting with strong approval of proposed resolutions

At the Annual General Meeting held on May 20, 2026, the shareholders of SGL Carb...

20/05/2026

Rohde & Schwarz and INFOZAHYST: A strategic alliance set to redefine modern defense

Rohde & Schwarz and INFOZAHYST: A strategic alliance set to redefine modern defe...

20/05/2026

Dolby Recognized as 2025 Supplier of the Year and Overdrive Award Winner by General Motors

May 20 2026, 06:00 (PDT) Dolby Recognized as 2025 Supplier of the Year and Over...

20/05/2026

Two cooks shortlisted for the final of RT Today's TV Home Cook Competition

Mayo's Dee Freney and Margaret Leahy from Galway have reached the final of RT Today's TV Home Cook competition. Both contestants will cook again live...

20/05/2026

RT IN FULL BLOOM AT BORD BIA BLOOM 2026 WITH LIVE BROADCASTS, MUSIC, CHAT AND MUCH MORE

RT IN FULL BLOOM AT BORD BIA BLOOM 2026 WITH LIVE BROADCASTS, MUSIC, CHAT AND M...

19/05/2026

Young Journalist' finalists visit London for training and networking

The winner of Thomson Foundation's Young Journalist of the Year 2025, Tracy Bonareri Onchoke, and runner up Wangu Kanuri enjoyed a three-day trip to London ...

19/05/2026

Building a More Trusted Podcast Experience for Creators and Listeners

Podcasting continues to evolve, and so does Spotify. As we build what comes next, one thing remains constant: This is a medium built on connection. It lives in ...

19/05/2026

GC Audio & Looptrotter announce the Emperor Signature Cartridge

Popular design joins Inherit cartridge line-up When GC Audio introduced their modular Inherit system, it was available with a selection of the company's...

19/05/2026

oeksound introduce Soothe3

Resonance-suppression plug-in gets ground-up rebuild Following on from its 10-year anniversary, oeksound's flagship plug-in has just reached its third m...

19/05/2026

Novation unveil the FLKey 2

Dedicated FL Studio controller keyboard range refreshed Novation's dedicated FL Studio controller family has just been upgraded, with four new models ex...

19/05/2026

Rohde & schwarz strengthens its in-vehicle networks test portfolio with the launch of new ASA-ML compliance solution

Rohde & schwarz strengthens its in-vehicle networks test portfolio with the laun...

19/05/2026

Lawful Intelligence: Rohde & Schwarz stellt neues Portfolio fr moderne Polizeiarbeit vor

Lawful Intelligence: Rohde & Schwarz stellt neues Portfolio f r moderne Polizeia...

19/05/2026

Clear-Com Enhances Musikal Perahu Kertas with Eclipse HX and FreeSpeak II

eds3_5_jq(document).ready(function($) { $(#eds_sliderM519).chameleonSlider_2_1({ content_source:......

19/05/2026

Ross Production Services Flexes Infrastructure with Console Switch

Celebrating its ability to quickly adapt to changing requirements, Ross Production Services (RPS) has put its flexible infrastructure to good use, switching one...

19/05/2026

98% of CMOs use AI. So why do only 1 in 3 see results?

Hilde Nielsen Last updated on: 20. May 2026 Last week, I returned from the Gartner CMO Symposium in London with loads of new insight and inspiration. AI do...

19/05/2026

Wireless vocals, zero compromise

The engineer behind the sound Martijn Van Renterghem has built his career across theater productions, concerts and large-scale touring. As director of A-Live So...

19/05/2026

VEON Successfully Prices USD 1.4 Billion Bond Offering

19 May 2026 VEON Successfully Prices USD 1.4 Billion Bond Offering Dubai and New York, May 19, 2026 - VEON Ltd. (Nasdaq: VEON), a global digital operator ( VEO...

19/05/2026

Sky makes waves with all-new Baywatch, coming to the UK and Ireland in 2027

Tuesday 19 May 2026 Sky makes waves with all-new Baywatch, coming to the UK and Ireland in 2027 CREDIT: FOX Sky is heading to the sun-soaked shores of Southe...

19/05/2026

DNA Finland Extends Fiber-Grade Connectivity to Lower-Density MDUs with Harmonic

Harmonic's SeaStar Optical Node Enables Cost-Effective Broadband Service Expansion in Previously Underserved Brownfield MDU Environments SAN JOSE, Calif. - ...

18/05/2026

And the Winners of the 2026 Spotify Podcast Awards in Mexico Are. . .

Last night, the Spotify Podcast Awards in Mexico returned to the country's capital. Now in its second year, the evening honors creators whose voices are hel...

18/05/2026

Roland launch Zenology GX for iPad

ZEN-Core synth goes mobile Roland's powerful ZEN-Core software synthesizer has just been introduced to the iPad, offering a convenient entry point into ...

18/05/2026

leONE from fedDSP

Versatile new limiter plug-in announced Based in Sheffield, UK, fedDSP offer a range of plug-ins that span the music production, live sound and high-end med...