SecBriefs
← Industry Reports
CrowdStrike
INDUSTRY REPORTThreat Landscape8 min read

Identity, Cloud and Social Engineering Are Collapsing the Defender’s Response Window

CrowdStrike’s 2025 Global Threat Report shows attackers increasingly avoiding traditional malware in favor of stolen identities, social engineering, cloud access and trusted sessions. The result is a shrinking response window in which identity visibility, cloud telemetry and rapid containment become as important as traditional endpoint defense.

CrowdStrike
2025

Data Breach
Investigations
Report

INCIDENT DATA · PATTERNS · PRIORITIES
THE SHORT VERSION

Executive Takeaway

The most important message in CrowdStrike’s 2025 Global Threat Report is not simply that attackers are becoming more sophisticated. It is that they are increasingly avoiding traditional malware altogether. Stolen identities, social engineering, cloud access and trusted sessions are becoming preferred routes into organizations, while attackers are moving faster once inside. That combination reduces the value of perimeter-heavy security and makes identity visibility, cloud telemetry and rapid response increasingly central to defense.

Key Findings

  1. 01

    China-nexus cyber activity increased by 150% across sectors, with some targeted industries experiencing substantially larger increases.

  2. 02

    Voice phishing increased 442% between the first and second halves of 2024, highlighting the growing role of social engineering and AI-assisted deception.

  3. 03

    CrowdStrike recorded a fastest eCrime breakout time of just 51 seconds, showing how little time defenders may have once an attacker establishes access.

  4. 04

    79% of CrowdStrike detections were malware-free, reinforcing the shift toward credential abuse, legitimate tools and trusted access.

  5. 05

    New and unattributed cloud intrusions increased 26% year over year, while valid-account abuse was the leading initial-access method in the cloud incidents CrowdStrike observed.

What the Data Says

79%

Malware-free detections

The report points to a threat landscape where trusted access is increasingly dangerous. Attackers are not always trying to deploy obvious malware; they are using compromised identities, legitimate remote sessions, SaaS access and cloud credentials to behave like real users.

51 seconds

Fastest eCrime breakout

Attack speed is also compressing. CrowdStrike recorded a fastest eCrime breakout time of 51 seconds. Even when that extreme is not representative of every incident, the direction is clear: manual escalation chains and delayed investigation are becoming increasingly risky.

26%

Growth in cloud intrusions

The cloud dimension is equally important. CrowdStrike reports a 26% year-over-year increase in new and unattributed cloud intrusions. Valid-account abuse accounted for 35% of cloud incidents in the first half of 2024, making identity controls, session monitoring and cross-domain visibility central defensive requirements.

What It Doesn’t Say / Limitations

CrowdStrike’s findings are derived from its own intelligence, telemetry, threat-hunting and incident-response visibility. That gives the report strong frontline value, but it also means the dataset reflects environments and organizations where CrowdStrike has visibility rather than the entire global threat landscape.

The percentages should therefore not be interpreted as universal prevalence rates for every organization or geography. A 442% increase in vishing, for example, indicates a significant trend within CrowdStrike’s observed data but does not mean every organization experienced a fourfold increase.

The same caution applies to cloud-intrusion and malware-free detection figures. CrowdStrike also has a commercial interest in emphasizing the importance of integrated endpoint, identity and cloud security, so its recommendations should be considered alongside independent and other vendor sources.

Why It Matters

For enterprises, the practical implication is that identity is now part of the primary attack surface. A valid credential can bypass controls that would stop traditional malware. This is especially important in banking, cloud-heavy environments, outsourced operations and organizations with extensive SaaS use.

The increasing speed of adversary movement also changes operational risk. Security teams need to detect and contain suspicious activity before it becomes lateral movement, privilege escalation or data theft. Delayed triage and fragmented monitoring become more dangerous as attack timelines shrink.

Who Should Care

  • CISOs and security leaders
  • Identity and access teams
  • SOC and incident-response teams
  • Cloud security teams
  • Fraud and account-takeover teams
  • Financial-services risk leaders
  • Executive management responsible for cyber resilience
SECBRIEFS VIEW

SecBriefs Assessment

CrowdStrike’s 2025 Global Threat Report is particularly strong in describing attacker behavior and operational speed. Its most useful insight is the convergence of identity abuse, social engineering and cloud intrusion rather than any single headline statistic.

The report is less useful as a universal measurement of cybercrime prevalence because the underlying observations come from CrowdStrike’s own visibility. The right way to use it is as a high-quality directional indicator: attackers are increasingly operating through legitimate access paths, and organizations that still treat endpoint malware as the center of the threat model risk missing the larger shift.

What To Do Now

  1. Treat identity telemetry as core security data, not merely IAM administration.
  2. Require phishing-resistant MFA for privileged and high-risk users wherever practical.
  3. Correlate endpoint, identity, SaaS and cloud activity rather than monitoring them independently.
  4. Reduce incident escalation time and measure whether critical detections can be investigated and contained within minutes rather than hours.
  5. Review help-desk identity-verification processes because social engineering increasingly targets password resets, MFA recovery and remote-access workflows.
ORIGINAL REPORT

2025 Global Threat Report — The Rise of the Enterprising Adversary

Publisher
CrowdStrike
Published
URL
https://www.crowdstrike.com/en-us/resources/reports/global-threat-report-executive-summary-2025/
View on publisher site(opens in a new tab)

Get the next SecBriefs report analysis

Clear analysis of major cybersecurity reports, delivered by SecBriefs.