SecBriefs
← Industry Reports
MandiantMandiant
INDUSTRY REPORTThreat Landscape8 min read

M-Trends 2026

Mandiant’s 2025 incident investigations show a split threat landscape: cybercrime can hand off access in seconds, while espionage and DPRK-linked activity can remain hidden for months, putting new pressure on edge-device visibility, identity controls and recoverability.

Mandiant
2026

M-Trends 2026

THREAT LANDSCAPE · SECBRIEFS ANALYSIS
THE SHORT VERSION

Executive Takeaway

M-Trends 2026 shows defenders operating against two very different attacker clocks. Financially motivated groups are compressing the path from initial access to high-impact activity, while sophisticated espionage and insider-style operations are extending persistence by hiding in edge devices, virtualization infrastructure and identity pathways that often sit outside traditional endpoint monitoring.

For leaders, the practical message is to connect attack-surface reduction, identity security, telemetry and resilience. Fast patching still matters, but so do help-desk controls for interactive social engineering, long-term logging for EDR-less infrastructure, and recovery designs that survive compromise of production identity, virtualization and backup systems.

Key Findings

  1. 01

    Financially motivated groups represented 41% of threat clusters observed in 2025, down from 55% in 2024, while cyber espionage groups rose to 16% from 8%.

  2. 02

    Exploits remained the leading initial infection vector for the sixth consecutive year at 32%; voice phishing surged to 11% while email phishing declined to 6%.

  3. 03

    Organizations first detected malicious activity internally in 52% of 2025 investigations, up from 43% in 2024; external notifications fell to 34%.

  4. 04

    Global median dwell time increased to 14 days from 11 days, while cyber espionage and DPRK IT worker incidents each showed a 122-day median dwell time.

  5. 05

    The median hand-off from initial access to a secondary threat group fell to 22 seconds in 2025, compared with more than eight hours in 2022.

  6. 06

    Ransomware and extortion operations increasingly target identity services, virtualization management planes and backup infrastructure to deny recovery rather than relying only on encryption.

What the Data Says

32%

Exploit-led initial access

Exploits remained the most common initial infection vector for the sixth consecutive year.

11%

Voice phishing

Highly interactive voice phishing rose to the second-most commonly observed initial infection vector.

52%

Internal detection

Organizations first identified malicious activity internally in just over half of Mandiant’s 2025 investigations.

14 days

Global median dwell time

Median dwell time increased from 11 days, reflecting a larger share of stealthy and persistent operations.

22 sec

Cybercrime hand-off

The median time from initial access to a secondary threat group collapsed from hours to seconds in Mandiant’s observed cases.

What It Doesn’t Say / Limitations

M-Trends 2026 is based on Mandiant Consulting investigations of targeted attack activity conducted between January 1 and December 31, 2025. Those engagements provide high-value frontline evidence but are not a random sample of all organizations, sectors or global intrusions.

Case mix, customer profile, geography, detection maturity and the incidents that escalate to Mandiant can influence percentages and rankings. The findings should therefore be used as directional benchmarks and threat-model inputs, then tested against an organization’s own telemetry, exposure and incident history.

Why It Matters

The report matters because defender speed is no longer a single metric. Some attacks require containment in seconds, while others demand enough telemetry to reconstruct activity that persisted for months or more than a year. Endpoint-centric monitoring alone is insufficient when adversaries deliberately target edge appliances, hypervisors, cloud identities and recovery infrastructure.

For financial services, the combination of vishing, identity abuse, SaaS access, virtualization compromise and recovery denial is especially relevant. Cybersecurity, fraud, IAM, help-desk and resilience teams need shared detection and response assumptions rather than separate control silos.

Who Should Care

  • CISOs and security leaders
  • SOC and incident-response teams
  • Vulnerability and attack-surface management teams
  • Identity, help-desk and fraud teams
  • Infrastructure and virtualization teams
  • Business resilience leaders, boards and risk committees
SECBRIEFS VIEW

SecBriefs Assessment

M-Trends 2026 is strongest when read as a timing and visibility report rather than a list of percentages. The standout message is that organizations now need to defend simultaneously against machine-speed criminal hand-offs and long-duration persistence in parts of the environment that often lack mature telemetry.

SecBriefs would prioritize three outcomes: reduce internet-facing exposure faster, extend high-fidelity monitoring beyond endpoints into identity and Tier-0 infrastructure, and prove that recovery remains possible after compromise of production identity, virtualization and backup systems. Those measures are more actionable than treating global averages as target KPIs.

What To Do Now

  1. Prioritize internet-facing and edge-device vulnerabilities by exploitability, exposure and business criticality, with owners and patch timelines that reflect attacker speed.
  2. Strengthen help-desk, account-recovery and MFA-reset workflows against live voice phishing; require independent verification for privileged or high-risk requests.
  3. Continuously audit identities, SaaS integrations, service principals and remote-contractor access for anomalous privilege and persistence.
  4. Centralize logs from edge devices, identity systems, hypervisors and virtualization management planes, and retain high-value telemetry long enough to investigate long-dwell intrusions.
  5. Isolate Tier-0 identity, virtualization and backup infrastructure; maintain immutable or offline recovery assets and test restoration without relying on the compromised production identity plane.
  6. Update incident-response playbooks so low-severity initial malware or opportunistic access is treated as a possible precursor to immediate secondary-group activity.
ORIGINAL REPORT

M-Trends 2026

Publisher
Mandiant
Published
URL
https://cloud.google.com/security/resources/m-trends
View on publisher site(opens in a new tab)

Get the next SecBriefs report analysis

Clear analysis of major cybersecurity reports, delivered by SecBriefs.