Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

IBM X-Force’s 2025 Threat Intelligence Index describes a shift toward attacks that steal credentials, abuse legitimate accounts and extract data with less visible malware activity. It also warns that AI systems and frameworks are becoming potential targets—but IBM reported no large-scale attacks against AI technologies in 2024. The distinction matters: identity abuse is already a prominent observed threat, while widespread AI attacks were still an emerging risk in that report.

What did IBM X-Force find about stealthier attacks?

The central trend in IBM’s 2025 report is identity abuse: attackers can steal login details, then use valid accounts instead of relying only on conspicuous malware. That can shorten the time between gaining access and taking data, while leaving fewer obvious traces for defenders focused mainly on malicious files or noisy activity.

IBM recorded identity abuse in 30% of cases it analyzed. Nearly half of attacks resulted in stolen data or credentials. These figures describe X-Force’s observations and reporting windows, not a census of every attack worldwide; they indicate the importance of identity-focused defenses without establishing a universal rate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How infostealers enter an organization

Phishing is one route. IBM reported that phishing emails delivering infostealers rose 84% in 2024. Its early-2025 data showed an increase of 180% compared with 2023. Those are different comparison periods, so the figures should not be read as sequential annual growth rates.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Infostealers are malicious software designed to collect information such as account credentials. The scale of the underground market helps explain why stolen logins remain useful to attackers: IBM found that the top five infostealers generated more than 8 million dark-web advertisements in 2024, and advertisements for infostealer credentials were up 12% year over year. An advertised credential may be stale, invalid or already changed; the figures measure listings, not confirmed successful logins.

Why malicious PDFs can evade simple screening

IBM’s analysis of malicious PDFs illustrates how delivery can be made harder to inspect automatically. It found that 42% used obfuscated URLs, 28% hid URLs in PDF streams, and 7% were delivered encrypted with a password. A URL embedded in a compressed stream or represented in an unusual format may not be as readily visible to basic scanning as a plain link in an email. Password-encrypted files can also complicate inspection when the scanner cannot access their contents.

Other low-profile delivery routes

The report also describes trojanized installers promoted through phishing, search-engine optimization poisoning or malvertising. The user may believe they are downloading legitimate software, while the installer provides a route for malicious activity. Combined with credential phishing and valid-account use, these methods shift the defender’s task from spotting a single conspicuous payload to correlating activity across email, endpoints and identity systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Are attackers targeting AI systems yet?

IBM’s 2025 assessment was cautious: it reported no large-scale attacks against AI technologies in 2024. At the same time, security researchers were identifying weaknesses in AI frameworks, including vulnerabilities that could enable remote code execution. IBM warned that such vulnerabilities would become more common targets as AI adoption grows.

That is an emerging-risk assessment, not proof that a particular AI attack toolkit had become widespread. Chris Caridi, a strategic threat analyst with IBM X-Force, put the distinction this way: “While large-scale attacks on AI technologies haven’t materialized yet, security researchers are racing to stay ahead, identifying and fixing vulnerabilities before threat actors can exploit them.”

What IBM’s 2026 update adds

IBM’s 2026 update offers later evidence of AI-related identity risk: it reported more than 300,000 ChatGPT credential sets advertised on the dark web in 2025. That count concerns advertised credential sets; it does not establish how many were valid, used successfully or associated with organizational accounts.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

The same update reported that public-facing-application exploitation rose 44% and represented 40% of incidents IBM observed in 2025. Those figures reinforce the need to protect both accounts and internet-facing systems; they do not show that AI was the cause of those application incidents. IBM also said attackers are using AI to accelerate familiar techniques. Mark Hughes, IBM’s global managing partner for cybersecurity services, summarized that view: “Attackers aren’t reinventing playbooks, they’re speeding them up with AI.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why do stolen credentials and infostealers matter so much?

Credentials can turn an initial compromise into access that resembles ordinary user activity. If an attacker signs in with a valid account, a control designed only to block unknown malware may not be enough. Stolen account details can also be sold or shared, giving other criminals a way to attempt access without repeating the original theft.

For defenders, this changes the question from “Did malware run?” to “Does this account’s behavior make sense?” Useful signals include unusual sign-in patterns, unexpected access to sensitive data, changes to account security settings, and activity that does not fit the user’s role. These are defensive priorities implied by the identity-abuse trend, rather than specific detection rules or thresholds published in the report.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does the shift away from noisy attacks mean ransomware is less important?

No. Identity abuse is prominent, but ransomware remains consequential. In IBM’s 2025 coverage, ransomware accounted for 28% of malware incident-response cases and 11% of security cases; dark-web ransomware activity rose 25% year over year. The two case percentages use different IBM case categories and should not be combined or treated as shares of all cyberattacks.

IBM also noted that critical-infrastructure organizations remain exposed by legacy technology and slow patch cycles. More than one-quarter of the incidents to which X-Force responded in this sector involved vulnerability exploitation. Manufacturing was the most attacked industry for the fourth consecutive year in the 2025 coverage. These findings make patching and recovery planning relevant alongside account protection.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should organizations do about these trends?

Responses should address the whole chain: how credentials are stolen, how exposed systems are entered, how low-noise activity is detected, and how operations recover if ransomware succeeds. The order below is a practical prioritization, not a claim that any single control will prevent every attack.

1. Make stolen credentials harder to use

  • Use phishing-resistant multifactor authentication where available, especially for administrators and accounts that can reach sensitive systems. Prioritize it over weaker methods that can be captured through phishing.
  • Monitor for account takeover: unusual sign-ins, unexpected privilege changes, suspicious access to data, and activity that differs from the account’s normal use.
  • Have a clear process to revoke sessions, reset credentials and investigate related accounts when a credential is exposed. Changing a password alone may not end access if active sessions or other credentials remain compromised.

2. Reduce routes in through exposed systems

  • Maintain an inventory of public-facing applications and their owners so that exposed systems are not missed during patching.
  • Prioritize vulnerabilities according to exposure and potential impact, and shorten patch delays for internet-facing systems. IBM’s critical-infrastructure findings make slow patch cycles a particularly important concern for organizations in that sector.
  • Review software installers and downloads used by staff. Clear approved sources and monitoring for unexpected installations can help address the risk of trojanized installers promoted through phishing, poisoned search results or malvertising.

3. Inspect email and detect activity across systems

  • Use email security that can inspect attachments and embedded links, including PDFs with obfuscated URLs or encrypted contents. Apply additional review when a password-protected attachment arrives through an unexpected message or workflow.
  • Correlate email, endpoint and identity telemetry. A suspicious attachment, a new process and an unusual account sign-in are more informative together than as isolated alerts.
  • Include identity and data-access activity in incident investigations, not only malware alerts. This is especially important when an attacker may be using valid credentials to limit visible signs of compromise.

4. Prepare for ransomware disruption

  • Keep backups isolated or otherwise protected from the systems they are meant to restore, and test recovery rather than relying on backup-job success alone.
  • Plan how to contain affected accounts and systems while preserving the ability to restore critical services. Organizations with legacy technology should factor patch constraints and recovery dependencies into that plan.

5. Govern AI services and their credentials

  • Inventory organization-approved AI services, associated accounts and integrations so that teams know which credentials and data flows need protection.
  • Protect chatbot and model-related credentials with the same care as other business accounts, and review AI frameworks for security updates and known vulnerabilities.
  • Distinguish observed incidents from forecasts when setting priorities. IBM’s 2025 report described AI-framework vulnerabilities as an emerging concern, while its 2026 update documented large-scale dark-web advertising of ChatGPT credential sets.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.