IBM: hackers are finding more opportunities to log in via legitimate credentials, rather than hacking into networks; info-stealing malware grew 266% YoY in 2023
IBM's annual X-Force Threat Intelligence Index report released today highlights an emerging global crisis in identity …
Context & Ripple Effects
IBM's prior breach-cost survey found that average breach costs had risen while only about a third were detected internally, making prevention and detection gaps central to the company's security coverage. This report refocuses that problem on the identity layer rather than a network-perimeter failure.
The pattern is reinforced by later coverage of malware-free intrusions becoming the majority of incidents and credential theft at far greater scale through info-stealing malware, placing IBM's 2023 findings early in a sustained shift in attacker access techniques.
First-order effects
- Security teams face greater immediate pressure to detect misuse of valid accounts, not just block exploits or malware; credentials exposed by info-stealers become a more urgent remediation target.
- IBM's X-Force findings give enterprise buyers a clearer rationale to prioritize identity monitoring and credential hygiene alongside network defenses.
Second-order effects
- Security vendors and service providers are pushed to emphasize controls that distinguish legitimate user activity from account takeover, as conventional malware- or perimeter-led signals catch less of the initial access path.
- Credential theft links endpoint infections to identity compromise, increasing the value of coordinated endpoint, identity and incident-response workflows rather than separate security tools.
Third-order effects
- If credential-led intrusion remains dominant, enterprise security architectures will continue shifting from perimeter trust toward continuous identity verification and behavior-based access controls.
- The durable competitive question for security platforms becomes whether they can correlate identity, endpoint and network evidence quickly enough to contain an attacker using apparently valid access.
The trend: Cyber defense is moving toward identity-centric, cross-domain detection as attackers increasingly convert stolen credentials into low-friction initial access.