Account Compromise Surged 389% in 2025, Says eSentire
ID: ed25efd6-896a-5f4c-9957-85c51b838e48
STIX ID: report--ed25efd6-896a-5f4c-9957-85c51b838e48
Feed Name: Infosecurity Magazine (News)
eSentire's 2025 Year in Review reports a dramatic surge in credential compromise—accounting for 75% of observed malicious activity and a 389% YoY rise in account compromises—driven primarily by phishing-as-a-service (PhaaS) kits that enable MFA bypass and rapid business email compromise; malware (notably ClickFix-related delivery and CastleLoader) comprised about 25% of threats. The report highlights targeted sectors (software, finance, real estate, retail, construction), increased email-bombing/help-desk impersonation attacks, and the widespread availability and evolution of PhaaS operations as key risk drivers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
