Skip to Content Facebook Feature Image

2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics

Business

2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics
Business

Business

2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics

2025-04-17 17:45 Last Updated At:18:05

  • Nearly half of all cyberattacks resulted in stolen data or credentials
  • Identity abuse was the preferred entry point
  • Asia Pacific represented more than one-third of attacks in 2024
  • ARMONK, N.Y., April 17, 2025 /PRNewswire/ -- IBM (NYSE: IBM) today released the 2025 X-Force Threat Intelligence Index highlighting that cybercriminals continued to pivot to stealthier tactics, with lower-profile credential theft spiking, while ransomware attacks on enterprises declined. IBM X-Force observed an 84% increase in emails delivering infostealers in 2024 compared to the prior year, a method threat actors relied heavily on to scale identity attacks.

    The 2025 report tracks new and existing trends and attack patterns – pulling from incident response engagements, dark web and other threat intelligence sources.

    Some key findings in the 2025 report include:

    • Critical infrastructure organizations accounted for 70% of all attacks that IBM X-Force responded to last year, with more than one quarter of these attacks caused by vulnerability exploitation.
    • More cybercriminals opted to steal data (18%) than encrypt it (11%) as advanced detection technologies and increased law enforcement efforts pressure cybercriminals to adopt faster exit paths.
    • Nearly one in three incidents observed in 2024 resulted in credential theft, as attackers invest in multiple pathways to quickly access, exfiltrate and monetize login information.

    ARMONK, N.Y., April 17, 2025 /PRNewswire/ -- IBM (NYSE: IBM) today released the 2025 X-Force Threat Intelligence Index highlighting that cybercriminals continued to pivot to stealthier tactics, with lower-profile credential theft spiking, while ransomware attacks on enterprises declined. IBM X-Force observed an 84% increase in emails delivering infostealers in 2024 compared to the prior year, a method threat actors relied heavily on to scale identity attacks.

    The 2025 report tracks new and existing trends and attack patterns – pulling from incident response engagements, dark web and other threat intelligence sources.

    Some key findings in the 2025 report include:

    "Cybercriminals are most often breaking in without breaking anything – capitalizing on identity gaps overflowing from complex hybrid cloud environments that offer attackers multiple access points," said Mark Hughes, Global Managing Partner of Cybersecurity Services at IBM. "Businesses need to shift away from an ad-hoc prevention mindset and focus on proactive measures such as modernizing authentication management, plugging multi-factor authentication holes and conducting real-time threat hunting to uncover hidden threats before they expose sensitive data."

    Patching Challenges Expose Critical Infrastructure Sectors to Sophisticated Threats
    Reliance on legacy technology and slow patching cycles prove to be an enduring challenge for critical infrastructure organizations as cybercriminals exploited vulnerabilities in more than one-quarter of incidents that IBM X-Force responded to in this sector last year.

    In reviewing the common vulnerabilities and exposures (CVEs) most mentioned on dark web forums, IBM X-Force found that four out of the top ten have been linked to sophisticated threat actor groups, including nation-state adversaries, escalating the risk of disruption, espionage and financial extortion. Exploit codes for these CVEs were openly traded on numerous forums —fueling a growing market for attacks against power grids, health networks and industrial systems. This sharing of information between financially motivated and nation-state adversaries highlights the increasing need for dark web monitoring to help inform patch management strategies and detect potential threats before they are exploited. 

    Automated Credential Theft Sparks Chain Reaction
    In 2024, IBM X-Force observed an uptick in phishing emails delivering infostealers and early data for 2025 reveals an even greater increase of 180% compared to 2023. This upward trend fueling follow-on account takeovers may be attributed to attackers leveraging AI to create phishing emails at scale.

    Credential phishing and infostealers have made identity attacks cheap, scalable and highly profitable for threat actors. Infostealers enable the quick exfiltration of data, reducing their time on target and leaving little forensic residue behind. In 2024, the top five infostealers alone had more than eight million advertisements on the dark web and each listing can contain hundreds of credentials. Threat actors are also selling adversary-in-the-middle (AITM) phishing kits and custom AITM attack services on the dark web to circumvent multi-factor authentication (MFA). The rampant availability of compromised credentials and MFA bypass methods indicates a high-demand economy for unauthorized access that shows no signs of slowing down.

    Ransomware Operators Shift to Lower-Risk Models
    While ransomware made up the largest share of malware cases in 2024 at 28%, IBM X-Force observed a reduction in ransomware incidents overall compared to the prior year, with identity attacks surging to fill the void.

    International takedown efforts are pushing ransomware actors to restructure high-risk models towards more distributed, lower-risk operations. For example, IBM X-Force observed previously well-established malware families including ITG23 (aka Wizard Spider, Trickbot Group) and ITG26 (QakBot, Pikabot) to either completely shut down operations or turn to other malware, including the use of new and short-lived families, as cybercrime groups attempt to find replacements for the botnets that were taken down last year.

    Additional findings from the 2025 report include:

    • Evolving AI threats. While large-scale attacks on AI technologies didn't materialize in 2024, security researchers are racing to identify and fix vulnerabilities before cybercriminals exploit them. Issues like the remote code execution vulnerability that IBM X-Force discovered in a framework for building AI agents will become more frequent. With adoption set to grow in 2025, so will the incentives for adversaries to develop specialized attack toolkits targeting AI, making it imperative that businesses secure the AI pipeline from the start, including the data, the model, the usage, and the infrastructure surrounding the models.
    • Asia and North America most attacked regions. Collectively accounting for nearly 60% of all attacks that IBM X-Force responded to globally, Asia (34%) and North America (24%) experienced more cyberattacks than any other region in 2024.
    • Manufacturing felt the brunt of ransomware attacks. For the fourth consecutive year, manufacturing was the most attacked industry. Facing the highest number of ransomware cases last year, the return on investment for encryption holds strong for this sector due to its extremely low tolerance for downtime.
    • Linux threats. In collaboration with Red Hat Insights, IBM X-Force found that more than half of Red Hat Enterprise Linux customers' environments had at least one critical CVE unaddressed, and 18% faced five or more vulnerabilities. At the same time, IBM X-Force found the most active ransomware families (e.g., Akira, Clop, Lockbit, and RansomHub) are now supporting both Windows and Linux versions of their ransomware.

    Additional Resources

    • Download a copy of the 2025 IBM X-Force Threat Intelligence Index.
    • Sign up for the 2025 IBM X-Force Threat Intelligence webinar on Tuesday, April 22nd at 11:00 am ET.
    • Connect with the IBM X-Force team for a personalized review of the findings.
    • Read more about the report's top findings in this IBM blog.

    About IBM 
    IBM is a leading provider of global hybrid cloud and AI, and consulting expertise. We help clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs, and gain a competitive edge in their industries. Thousands of governments and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM's hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently, and securely. IBM's breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and consulting deliver open and flexible options to our clients. All of this is backed by IBM's long-standing commitment to trust, transparency, responsibility, inclusivity, and service. Visit www.ibm.com for more information. 

    Media Contact
    Michele Brancati
    IBM
    mbrancati@ibm.com

    ** The press release content is from PR Newswire. Bastille Post is not involved in its creation. **

    2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics

    2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics

    2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics

    2025 IBM X-Force Threat Index: Large-Scale Credential Theft Escalates, Threat Actors Pivot to Stealthier Tactics

BANGKOK, Dec. 25, 2025 /PRNewswire/ -- This Christmas, MINISO is bringing YOYO and a lineup of its popular characters to Bangkok's Siam Square, creating a festive seasonal setting and marking the close of a strong year for the brand in Thailand. A series of Christmas-themed installations will remain in place across Siam Square's pedestrian streets and at Thailand's first MINISO LAND through the holiday period, running until January 4, 2026.  

Christmas in Thailand may come without snow, but this year, MINISO brings festive cheer to the heart of Bangkok. Its signature characters—YOYO, the Gift Bear, and DUNDUN—headline a 10-day holiday installation anchored by a 60-meter-long Christmas promenade. Featuring five themed photo spots, the route leads visitors from Siam Square to MINISO LAND, ending at a Christmas tree marked by MINISO's iconic red wink. Inside the store, seasonal displays, limited-edition gifts, and wish cards await.

MINISO LAND in Siam Square marks the company's first overseas debut of its new experiential store format. Opened in October, the store features a redesigned storefront and highlights the Zootopia product lineup. Since launch, it has drawn strong foot traffic from both local shoppers and tourists. The opening reinforced MINISO's presence in Thailand, while the brand awareness built earlier in the year positioned the store as a natural hub for year-end holiday activations. Through immersive design, curated assortments, and campaign-led execution, MINISO continues to elevate the in-store experience for Thai consumers.

A Year of Joy: Retail Expansion and Brand Activity

Throughout 2025, MINISO continued to expand its retail footprint and delight Thai consumers with a combination of new stores, exclusive product launches and immersive brand experiences. The year kicked off in January with the opening of the brand's first flagship store at Asiatique The Riverfront in Bangkok, and coincided with Thailand's debut of MINISO's Harry Potter merchandise collection.

In the following months, MINISO introduced multiple newly refreshed and flagship stores in key Bangkok locations, including Megabangna Mall, MBK Center, and The Mall LifeStore Bangkapi. Each opening showcased IP-themed products, and immersive displays, drawing strong foot traffic and social media buzz. The May launch at The Mall LifeStore Bangkapi marked the overseas debut of the Stitch GenZ Street Series vinyl plush, generating high shopper interest.

Beyond Bangkok, MINISO strengthened its presence in northern Thailand by establishing stores across key commercial destinations in Chiang Mai, including Central Festival Chiangmai, Central Chiangmai Airport, and MAYA Lifestyle Shopping Center. The expansion reflects the brand's focus on delivering an elevated and refined store experience, while steadily extending its presence across Thailand.

MINISO's growth strategy also emphasized engaging local consumers through popular IP collaborations. Throughout the year, the brand introduced over 15 new IP collections in Thailand—including Zootopia, Stitch, Harry Potter, and One Piece—alongside more than 5,000 new products.

By combining retail expansion with engaging retail experiences and campaigns, MINISO has positioned its stores as vibrant destinations for Thai consumers. The Christmas and New Year program, anchored by MINISO LAND and a festive promenade in central Bangkok, further strengthened the brand's visibility and engagement during the holiday season, setting the stage for continued growth in 2026.

 

** The press release content is from PR Newswire. Bastille Post is not involved in its creation. **

MINISO Brings Christmas Cheer to Bangkok's Siam Square with YOYO and Signature Characters, Closing Out a Standout Year in Thailand

MINISO Brings Christmas Cheer to Bangkok's Siam Square with YOYO and Signature Characters, Closing Out a Standout Year in Thailand

MINISO Brings Christmas Cheer to Bangkok's Siam Square with YOYO and Signature Characters, Closing Out a Standout Year in Thailand

MINISO Brings Christmas Cheer to Bangkok's Siam Square with YOYO and Signature Characters, Closing Out a Standout Year in Thailand

MINISO Brings Christmas Cheer to Bangkok's Siam Square with YOYO and Signature Characters, Closing Out a Standout Year in Thailand

MINISO Brings Christmas Cheer to Bangkok's Siam Square with YOYO and Signature Characters, Closing Out a Standout Year in Thailand

MINISO Brings Christmas Cheer to Bangkok's Siam Square with YOYO and Signature Characters, Closing Out a Standout Year in Thailand

MINISO Brings Christmas Cheer to Bangkok's Siam Square with YOYO and Signature Characters, Closing Out a Standout Year in Thailand

MINISO Brings Christmas Cheer to Bangkok's Siam Square with YOYO and Signature Characters, Closing Out a Standout Year in Thailand

MINISO Brings Christmas Cheer to Bangkok's Siam Square with YOYO and Signature Characters, Closing Out a Standout Year in Thailand

MINISO Brings Christmas Cheer to Bangkok's Siam Square with YOYO and Signature Characters, Closing Out a Standout Year in Thailand

MINISO Brings Christmas Cheer to Bangkok's Siam Square with YOYO and Signature Characters, Closing Out a Standout Year in Thailand

Recommended Articles