Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CrowdStrike began tracking 26 additional threat groups during 2024, bringing its tracked-adversary total to 257, according to the company’s findings as reported by SecurityWeek on February 27, 2025. “New” here means newly added to CrowdStrike’s tracking—not necessarily groups formed in 2024—and 257 is the vendor’s count, not a census of threat actors worldwide.

What does “26 new threat groups” mean?

The figure refers to 26 groups that CrowdStrike began tracking in 2024. SecurityWeek’s summary does not establish when those groups originated, so the number should not be read as 26 newly formed groups. CrowdStrike’s total of 257 represents adversaries known to and tracked by the company, not every group active globally.

The figures below are CrowdStrike findings relayed by SecurityWeek from the company’s 2025 Global Threat Report. They are vendor telemetry, not independent measurements across all organizations. The article does not provide enough methodological detail to verify how groups are defined, how telemetry was sampled, or the confidence intervals for the reported figures. CrowdStrike’s news archive lists the report coverage under the same headline.

What else changed in CrowdStrike’s 2024 threat picture?

More China-linked activity across several sectors

CrowdStrike reported a 150% increase in China-linked activity across sectors. For financial services, media, manufacturing, and industrials and engineering, the company reported increases of 200–300% versus 2023. These are changes in the activity CrowdStrike observed; they do not establish that every organization in those sectors faced the same increase.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cybercrime intrusions moved faster

Average breakout time for cybercrime intrusions was 48 minutes in 2024, down from 62 minutes in 2023, according to CrowdStrike. Breakout time describes movement from initial access to high-value assets. The fastest observed breakout was 51 seconds; it is an observed extreme, not a typical incident duration.

Initial access and credentials remained prominent

More than half of the vulnerabilities CrowdStrike observed in 2024 related to initial access. The company also reported that access-broker activity increased 50% year over year, while valid credential abuse featured in 35% of cloud incidents. These figures point to risks involving both vulnerability exploitation and stolen or misused identities, but their scope is CrowdStrike’s observed activity.

Most detections were malware-free

CrowdStrike reported that 79% of its detections in 2024 were malware-free, compared with 40% five years earlier. This is a share of the company’s detections, not a claim that 79% of all cyberattacks everywhere used no malware.

Vishing rose sharply between half-year periods

Vishing attacks increased 442% from the first half to the second half of 2024, CrowdStrike reported. This comparison is between two halves of the same year, not a year-over-year increase.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should organizations take from the findings?

The combination of credential abuse, access brokerage, and quick movement after initial access makes identity controls and early detection important alongside vulnerability management. CrowdStrike recommends identity verification, risk-based patching, and early detection of credential abuse to disrupt intrusions before they escalate, as reported by SecurityWeek.

  • Strengthen identity verification for sign-ins and sensitive actions, especially where credentials alone may be insufficient.
  • Prioritize patching according to risk and exposure rather than treating every vulnerability as equally urgent.
  • Watch for signs of credential abuse early, before an intruder can move from initial access to high-value assets.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to compare these figures with another threat report

Threat-report numbers can look comparable while measuring different things. Before drawing conclusions, check:

  • Period: Which activity window was measured, and when was the report published?
  • Meaning of “new”: Does the count refer to newly tracked actors or actors believed to have formed during the period?
  • Coverage: Which regions, sectors, and customer environments are represented?
  • Metric and comparison window: Is a percentage tied to detections, incidents, observed activity, or a particular pair of periods?
  • Evidence source: Are the findings based on one vendor’s telemetry, government reporting, or independently collected data?

Without aligning those definitions and scopes, differences between reports should not be treated as direct measures of which threat landscape is larger or worsening faster.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.