https://www.theregister.com/2025/04/23/stolen_credentials_mandiant/
https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2025
Criminals used stolen credentials more frequently than email phishing to gain access into their victims’ IT systems last year, marking the first time that compromised login details claimed the number two spot in Mandiant’s list of most common initial infection vectors. “Credential stealers have been and are a major issue, but we have seen a resurgence recently,” Mandiant Consulting VP Jurgen Kutscher said in an interview with The Register about the nearly 100-page M-Trends 2025 report from the Google-owned security shop. … The annual report also found 55 percent of attackers active in 2024 were financially motivated, up slightly from 52 percent the year before. Only 8 percent were motivated by espionage last year, which represents a 2 percent drop from 2023. …
Regards