CrowdStrike: in 2024, 79% of cyber intrusions were malware-free, up from 40% in 2019, voice phishing overtook phishing as the main first access method, and more
Duncan Riley / SiliconANGLE :
Context & Ripple Effects
CrowdStrike’s findings extend a trajectory already visible in its earlier coverage: cloud intrusions surged while attackers increasingly worked through legitimate access rather than exploiting networks directly. IBM likewise reported a growing preference for legitimate credentials as an entry route, making malware-free activity a material detection problem rather than a marginal tactic.
The reported rise of voice phishing as an initial-access route shifts attention from email-centric controls to attacks that target people and identity workflows.
First-order effects
- Security teams must prioritize identity, authentication, endpoint behavior and help-desk verification alongside malware detection, since a large share of intrusions may not produce a conventional malicious-file signal.
- Organizations face a more immediate social-engineering exposure as voice phishing becomes a leading entry method, increasing the importance of procedures for credential resets, payment changes and access requests.
Second-order effects
- Endpoint-security vendors are pushed to demonstrate detection of credential abuse and hands-on-keyboard activity, not just file-based prevention; identity-security and phishing-defense tools gain strategic relevance.
- Attackers that obtain valid access can move quickly inside an environment, a concern reinforced by CrowdStrike’s later finding that breakout times had fallen to 29 minutes. This raises the value of rapid containment and tightly scoped privileges.
Third-order effects
- If malware-free intrusion continues to dominate, cyber-defense buying is likely to shift toward integrated identity, endpoint and response telemetry rather than treating antivirus-style malware detection as the primary control.
- The pattern points to security operations becoming more behavior- and identity-led, though the pace of that shift will depend on whether organizations can reduce credential theft and voice-based manipulation at the access layer.
The trend: Cyber intrusions are moving from malware delivery toward identity compromise and interactive abuse of legitimate access, compressing defenders’ time to detect and contain attackers.