{"id":3657,"date":"2025-05-01T10:04:03","date_gmt":"2025-05-01T10:04:03","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/01\/over-90-of-cybersecurity-leaders-worldwide-encountered-cyberattacks-targeting-cloud-environments\/"},"modified":"2025-05-01T10:04:03","modified_gmt":"2025-05-01T10:04:03","slug":"over-90-of-cybersecurity-leaders-worldwide-encountered-cyberattacks-targeting-cloud-environments","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/01\/over-90-of-cybersecurity-leaders-worldwide-encountered-cyberattacks-targeting-cloud-environments\/","title":{"rendered":"Over 90% of Cybersecurity Leaders Worldwide Encountered Cyberattacks Targeting Cloud Environments"},"content":{"rendered":"<p>    Over 90% of Cybersecurity Leaders Worldwide Encountered Cyberattacks Targeting Cloud Environments<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>In what security experts are describing as a \u201cdistributed crisis,\u201d a staggering 90% of cybersecurity and IT leaders worldwide reported experiencing cyberattacks targeting their cloud environments within the past year.<\/p>\n<p>This alarming statistic emerges from comprehensive research conducted across ten countries, highlighting the increasing vulnerability of organizations as they transition from on-premises systems to hybrid cloud infrastructures.<\/p>\n<p>The study, which surveyed more than 1,600 IT and security leaders, reveals that despite increased investment in cloud security, threat actors continue to find success in breaching these environments.<\/p>\n<p>The nature of cloud-targeted attacks has evolved dramatically, with adversaries shifting away from traditional malware-based approaches toward more sophisticated identity-based intrusion methods.<\/p>\n<p>According to the research, malware-free activity now accounts for 79% of all detected intrusions, a significant increase from just 40% in 2019.<\/p>\n<p>This paradigm shift reflects attackers\u2019 adaptation to modern enterprise environments, where they increasingly exploit valid credentials, engage in hands-on-keyboard intrusions, and deploy social engineering tactics to bypass conventional security measures.<\/p>\n<p>The impact of these breaches has been severe, with 86% of organizations that experienced ransomware attacks ultimately paying the demanded ransom to recover their data or halt the attack.<\/p>\n<p>Even more concerning, 74% of victims reported that attackers were able to harm backup and recovery options, effectively eliminating safety nets designed to mitigate such incidents.<\/p>\n<p>Rubrik Zero Labs researchers <a href=\"https:\/\/www.rubrik.com\/content\/dam\/rubrik\/zero-labs\/reports\/rpt-state-of-data-security-a-distributed-crisis.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> a particularly troubling trend in their analysis: the dramatic reduction in \u201cbreakout time\u201d \u2013 the period between initial compromise and lateral movement across systems.<\/p>\n<p>\u201cIn 2024, the average breakout time for interactive eCrime intrusions fell to 48 minutes, down from 62 minutes in 2023,\u201d noted security analysts.<\/p>\n<p>\u201cAlarmingly, the fastest breakout was recorded at just 51 seconds, meaning defenders may have less than a minute to detect and respond before attackers establish deeper control\u201d.<\/p>\n<h2 class=\"wp-block-heading\"><strong>The Rise of Identity-Based Attack Vectors<\/strong><\/h2>\n<p>The report provides detailed insight into how identity-based attacks have become the preferred method for cloud environment infiltration.<\/p>\n<p>Rather than breaking in through <a href=\"https:\/\/cybersecuritynews.com\/chrome-123-patch\/\" target=\"_blank\" rel=\"noreferrer noopener\">security vulnerabilities<\/a>, attackers are simply logging in using compromised credentials.<\/p>\n<p>This approach proves particularly effective in cloud and SaaS environments where traditional perimeter defenses offer limited protection.<\/p>\n<p>Valid account abuse was responsible for 35% of cloud-related incidents, reflecting attackers\u2019 growing focus on identity compromise as a gateway to broader enterprise environments.<\/p>\n<p>Microsoft\u2019s security telemetry supports this finding, revealing that they block over 600 million identity-based attacks daily.<\/p>\n<p>These attacks typically begin with credential harvesting through phishing campaigns or purchase of <a href=\"https:\/\/cybersecuritynews.com\/stolen-youtube-channel-credentials\/\" target=\"_blank\" rel=\"noreferrer noopener\">stolen credentials<\/a> from access brokers, whose activity surged by nearly 50% compared to the previous year.<\/p>\n<p>The attack sequence typically progresses as follows:-<\/p>\n<pre class=\"wp-block-code\"><code>Initial Access (compromised credentials) \u2192 \n    Cloud Environment Access \u2192 \n        Lateral Movement (using management tools) \u2192 \n            Privilege Escalation \u2192 \n                Data Discovery &amp; Exfiltration<\/code><\/pre>\n<p>To counter this growing threat, the report recommends organizations adopt a comprehensive strategy that includes improved visibility into cloud environments, identity protection measures, and robust backup capabilities that mirror the rigor traditionally applied to on-premises systems.<\/p>\n<p>Without this unified approach to <a href=\"https:\/\/cybersecuritynews.com\/ai-machine-learning-translation\/\" target=\"_blank\" rel=\"noreferrer noopener\">data protection<\/a>, organizations remain vulnerable to increasingly sophisticated cloud-targeted attacks that move at unprecedented speed.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><code>Malware Trends Report Based on 15000 SOC Teams Incidents, Q1 2025 out!-&gt;\u00a0<a href=\"https:\/\/any.run\/cybersecurity-blog\/malware-trends-q1-2025\/?utm_source=cyber-threat-intel_linkedin&amp;utm_medium=post&amp;utm_campaign=q1&amp;utm_content=blog&amp;utm_term=150425\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Get Your Free Copy<\/a><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cybersecurity-leaders-encountered-cyberattacks\/\">Over 90% of Cybersecurity Leaders Worldwide Encountered Cyberattacks Targeting Cloud Environments<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cybersecurity-leaders-encountered-cyberattacks\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Over 90% of Cybersecurity Leaders Worldwide Encountered Cyberattacks Targeting Cloud Environments In what security experts are describing as a \u201cdistributed crisis,\u201d a staggering 90% of cybersecurity and IT leaders worldwide reported experiencing cyberattacks targeting their cloud environments within the past year. This alarming statistic emerges from comprehensive research conducted across ten countries, highlighting the increasing [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[701,63,700],"tags":[130],"class_list":["post-3657","post","type-post","status-publish","format-standard","hentry","category-cyber-attack","category-cyber-security-news","category-cyberattack-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3657"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3657"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3657\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3657"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3657"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3657"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}