In IBM X-Force’s incident-response cases from 2024, valid account credentials and exploitation of public-facing applications each accounted for 30% of cases, according to a CyberScoop report published April 22, 2025. The figures point to two familiar intrusion routes—logging in with usable credentials and exploiting software exposed to the internet—not a census of all cyberattacks.
What IBM X-Force reported about 2024 incidents
CyberScoop’s account of the IBM X-Force Threat Intelligence Index 2025 describes the leading initial-access methods in the cases IBM X-Force handled during 2024. The reported split was tied at the top, and matched the top-vector breakdown reported for the prior year.
| Reported route or activity | Figure | What the figure describes |
|---|---|---|
| Valid account credentials | 30% | Share of IBM X-Force’s 2024 incident-response cases attributed to valid credentials. |
| Exploitation of public-facing applications | 30% | Share of IBM X-Force’s 2024 incident-response cases attributed to this route. |
| Credential harvesting | 28% | Share of IBM X-Force’s 2024 incident-response cases involving credential harvesting. |
| Infostealers delivered through phishing email | 84% increase | Increase in the weekly average in 2024 compared with 2023, according to IBM X-Force. |
| Post-compromise scanning | 25% | Share of the exploited-public-facing-application cases in which responders observed scanning after access. |
| Manufacturing | 26% | Share of 2024 incidents attributed to manufacturing, described as the most attacked industry for the fourth consecutive year. |
These percentages come from IBM X-Force through the CyberScoop account; they are not independently established rates for every organization or the wider threat landscape. The underlying IBM report’s definitions, incident sample, and methodology are not established in the available account, so the figures should be read as descriptions of IBM X-Force’s response cases rather than directly comparable prevalence estimates.
Why valid credentials are an effective way in
Attackers can obtain credentials through phishing or infostealer malware, then use those credentials to access an account. As Michelle Alvarez, manager of the IBM X-Force threat intelligence team, put it to CyberScoop: “They’re logging in, versus hacking in.” A login with valid credentials can resemble routine account activity, making this route different from exploiting a software flaw even though either can lead to a compromise.
#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
Credential harvesting appeared in 28% of the cases IBM X-Force handled in 2024. The weekly average of infostealers delivered through phishing emails rose 84% that year compared with 2023, according to the same report. That comparison describes a change in the weekly average, not an 84% share of incidents.
How exposed applications create another entry route
Exploitation of public-facing applications matched valid credentials at 30% of IBM X-Force’s 2024 incident-response cases. A public-facing application is software reachable over the internet; when it contains a vulnerability that remains unpatched, attackers may be able to exploit it to gain access.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Alvarez told CyberScoop that attackers often leverage vulnerabilities that are “widely unpatched.” She also noted that vulnerabilities with patches available for a long time can remain exploited, underscoring the role of ongoing vulnerability management. The report’s figures do not identify a specific application, vulnerability, or patching schedule as the cause in each case.
What responders saw after exploitation
In 25% of the cases involving exploited public-facing applications, responders observed scanning after the initial compromise. That activity suggests attackers searched for additional weaknesses after getting in; the figure applies to that subset of cases, not to all incidents or all application exploits.
Rank #3
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
- Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
How the two routes differ—and can overlap
| Aspect | Valid credentials | Exploited public-facing application |
|---|---|---|
| Access mechanism | Use of a legitimate account login, potentially with credentials harvested through phishing or infostealers. | Abuse of a vulnerability in software reachable from the internet. |
| Share of IBM X-Force’s 2024 cases | 30%. | 30%. |
| Reported follow-on activity | Credential use can blend into ordinary account activity. | Post-compromise scanning was observed in 25% of this route’s cases. |
The two categories describe different access mechanisms, but the reported percentages do not establish that they are mutually exclusive. The findings support treating account compromise and exposed application vulnerabilities as concurrent concerns; they do not show that any single defensive control will prevent a breach.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Scope and limits of the figures
CyberScoop also reported that 70% of attacks in the report were attributed to critical-infrastructure organizations. Because the underlying IBM report’s denominator and methodology are not established in the available account, that figure should not be read as a general estimate of how often critical infrastructure is attacked.
Rank #4
- USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
- Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
- Slim, keychain-ready form for easy carry and on-the-go authentication
- IP68-rated for dependable performance
- FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.
For details of the reported findings and Alvarez’s comments, see CyberScoop’s April 22, 2025 report on the IBM X-Force Threat Intelligence Index 2025.
Quick Recap
Best Value
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →

