X-Force Threat Intelligence Index 2026

Top initial access vectors

Rise of vulnerability exploitation

For the past 2 years, X-Force reported on the abuse of valid credentials as a top initial access vector used by adversaries across industries and regions.

The appeal of using legitimate credentials to gain access to infrastructures has drawn attackers in for its relative simplicity and high success rate. However, in 2025, X-Force observed a dramatic shift in this trend. We witnessed a 44% increase in incidents caused by the exploitation of public-facing applications. This increase accounted for 40% of cases, whereas use of valid credentials made up only 32% of cases. Public-facing applications are subject to exploitation through vulnerabilities or misconfigurations associated with application deployment, configuration, or both.

Chart comparing the prevalence of top initial access vectors in 2025 and 2024.
Top initial access vectors X-Force observed in 2025 and 2024. Source: IBM X-Force.

This trend was compounded by a rise in supply‑chain attacks increasingly targeting development ecosystems and trusted infrastructure—meaning vulnerabilities were being exploited earlier in the software lifecycle and at a much larger scale. This shift may also be connected to weaknesses in client environments observed by X‑Force Red (described later in this report), where misconfigurations, weak authentication and insecure code—identified by Common Attack Pattern Enumeration and Classification’s CAPEC‑180, CAPEC‑49 and CAPEC‑242—consistently provided easy entry points. Together, the systemic fragility in supply‑chain ecosystems and the prevalence of these foundational CAPEC weaknesses significantly accelerated the exploitation of vulnerabilities throughout 2025.

In addition, we observed heightened discovery and reporting efforts in 2025. X-Force maintains a database tracking vulnerabilities over time, and our data indicated a notable upward trend, year over year, for new vulnerabilities. This trend marks the growing complexity of software ecosystems and available attack surface to include AI systems. It’s also plausible this increase in vulnerability reporting could result in part from both researchers and attackers using AI and machine‑learning tools to identify vulnerabilities.

Chart showing vulnerabilities tracked each year from 2020 through 2025
The growth of vulnerabilities since 2020. Source: IBM X-Force.

Additionally, the tracked vulnerabilities can be placed into two categories determined by whether authentication was required for exploitation. The data reveals most (56%) vulnerabilities could be exploited without authentication, significantly increasing the potential attack surface. This trend underscores a critical security concern. Systems lacking authentication controls are more susceptible to unauthorized access and exploitation, making it essential for organizations to implement robust authentication mechanisms and enforce strict access policies.

Area chart showing vulnerabilities that required authentication to exploit vs. those that didn't, 2020 through 2025
Most vulnerabilities tracked in 2025 did not require authentication to exploit. Source: IBM X-Force.

Continued use of valid credentials

Although no longer the leading initial access vector, the misuse of valid accounts represented nearly a third of the cases, indicating a continued reliance on legitimate credentials. Legitimate credentials remain one of the preferred entry points for attackers because they eliminate the need for exploits and let adversaries blend seamlessly into the normal authentication process. This theme is clear across multiple IBM X-Force investigations.

Campaigns built around credential theft as the enabling step show the same pattern:

  • Hive0145’s 2025 operation against German organizations delivered Strela Stealer specifically to harvest Microsoft Outlook and Mozilla Thunderbird logins. Once obtained, those real credentials allowed attackers to access mailboxes and impersonate users.

  • Similarly, the France-focused spear-phishing wave used leaked ISP customer data to lure victims into entering their Amazon credentials on a fake login page, enabling immediate account takeover without any technical exploitation.

Together the system fragility in supply chain ecosystems and the prevalence of foundational CAPEC weaknesses significantly accelerated the exploitation of vulnerabilities throughout 2025.


Beyond phishing credential‑theft campaigns, attackers also target systems that store or manage high‑value credentials. Our X-Force Red Adversary Services team published research around SCCM (Microsoft’s System Center Configuration Manager) credential-decryption. Analysts showed once an attacker gains a foothold on a Configuration Manager site server, they can extract and decrypt service-account passwords stored in the SCCM database. They can then use those valid credentials to pivot across the environment with the same trust and reach as the organization’s own management infrastructure. The attacker doesn’t need an exploit at that stage—they simply “log in” with SCCM accounts that automate software deployment and have broad network permissions, turning a single compromised server into enterprise-wide access.

The use of legitimate credentials—either phished or stolen—can allow attackers to shift from outsider to authorized user, bypassing controls and gaining persistent, low-visibility access.

Understanding how valuable credentials are to attackers, it’s not surprising these are some of the most sought-after items within cybercriminal marketplaces. Our analysis found credential harvesting topped the list of impacts experienced by victim organizations in 2025.

AI chatbot credentials

The proliferation of AI chatbots in business operations created a new attack vector for cybercriminals utilizing infostealer malware. As organizations increasingly integrate AI chatbot technologies into their workflows, the risk of infected systems with stored credentials for these platforms has emerged. Furthermore, the theft of AI chatbot credentials that enable access to other systems—illustrated by the Salesloft/Drift incident, where attackers stole Drift OAuth tokens and used them to break into multiple Salesforce environments—shows chatbot‑token-based access into other systems is already happening and may be occurring more widely.

The top 5 platforms—ChatGPT (OpenAI), Microsoft Copilot, Google Gemini, Perplexity and Claude AI (Anthropic)—were reviewed for accounts for sale on the dark web containing credentials for the platforms.  Visibility varies significantly from platform to platform included in the dataset. Ones that use third-party providers—such as SSO, Apple, Google or Microsoft—do not have platform-specific credentials stored and cannot be identified in credential data. In 2025, over 300,000 ChatGPT credentials were observed for sale.

Additionally, in February 2025, a threat actor posted example ChatGPT credentials on BreachForums and claimed to have stolen over 20 million accounts.  While none of the example credentials posted were still valid, the credentials consistently corresponded to infostealer infections and leaked credentials collections observed in 2024 and earlier. This illustrates how large‑scale credential theft from past infostealer activity can resurface as renewed criminal leverage, transforming previously compromised data into fresh opportunities for exploitation.

While 2025 saw considerable takedowns of infostealer malware infrastructure—such as with Lumma and Rhadamanthys—the use of infostealer malware remains an easy method for threat actors to gain access.

As with the adoption of other new technologies, companies should first assess policies and adoption of AI chatbots within their organization.  Next, they should prioritize cybersecurity awareness education and enhancements to credential protection—such as the use of multi-factor authentication and passkeys, detection of abnormal login patterns and monitoring of credential exposure.

3d sphere and cube shapes surrounded by locks
Related solutions
Identity and access management (IAM) services

Strengthen security and compliance with IBM IAM services, streamlining identity across hybrid cloud environments.

Explore IAM services
Threat detection and response services

Optimize your security program with IBM’s global, vendor-independent threat response services.

Explore threat detection services
IBM Verify

Build a secure identity foundation with IBM Verify to simplify access, improve authentication, and scale with confidence.

Explore IBM Verify
Take the next step

Book a personalized discovery briefing to explore how IBM X-Force® can help you reduce cyber risk, validate your defenses and build lasting cyber resilience with offensive and defensive expertise.

  1. Schedule a discovery session with X-Force
  2. Explore IBM X-Force