Attackers are now extracting data in just over an hour. This acceleration, detailed in the 2026 Global Incident Response Report by Palo Alto Networks’ Unit 42, suggests the window for defending enterprise assets is shutting.
The fastest quartile of attacks now reach the exfiltration stage in 72 minutes; a sharp contraction from the nearly five hours recorded the previous year.
Unit 42’s report, analysing over 750 incident response cases from the past year, points to AI being a friction reducer for adversaries. It allows actors to operate with machine-like efficiency. Attackers now begin scanning for newly discovered vulnerabilities within 15 minutes of public disclosure.
The identity crisis in the cloud
While speed provides the pressure, identity weaknesses provide the path. Identity gaps played a material role in almost 90 percent of investigations.
As organisations migrate deeper into cloud and SaaS environments, the traditional network perimeter has effectively dissolved. In its place, identity – the link between users, machines, and data – has become the primary control point, and frequently the primary point of failure.
Data shows that 65 percent of initial access incidents were driven by identity-based techniques, such as phishing or credential misuse. Attackers rarely need complex exploits when they can log in using stolen credentials or valid session tokens.
Once inside, lateral movement is often unrestricted. Unit 42 analysis of over 680,000 cloud identities found that 99 percent of permissions granted to cloud users, roles, and services were excessive.
This “governance drift” creates a scenario where a single compromised account can grant access to vast swathes of an organisation’s infrastructure. Attackers exploit these over-permissioned roles and unmonitored service accounts to escalate privileges without triggering alarms.
The issue is compounded by fragmentation; most enterprises operate multiple identity stores, such as Active Directory alongside Okta and various cloud-native IAM systems, creating visibility gaps that prevent security teams from seeing the full picture.
Supply chains and the browser interface
Supply chain risks have evolved from vulnerable code to the misuse of trusted connectivity, such as SaaS integrations and vendor management tools. In 2025, SaaS application data was relevant to 23 percent of cases, rising from just six percent in 2022.
These integrations often rely on OAuth tokens and API keys that carry inherited permissions. If an upstream provider is compromised, those permissions allow access to downstream customer data. The report details instances where attackers used valid OAuth tokens from compromised sales platforms to access Salesforce environments, blending in with routine automation traffic.
Simultaneously, the browser has solidified its position as the primary workspace, and consequently, a frequent target.
Browser-based activity played a role in 48 percent of investigations. Adversaries use techniques like SEO poisoning to direct users to spoofed sites, where they are tricked into executing malicious code. In one case involving a global industrial firm, an employee searching for a restaurant was led to a compromised site that facilitated a malware infection.
Nation-state adaptation and AI
Nation-state actors are adapting tradecraft to these modern operating environments. Groups affiliated with China, North Korea, and Iran are relying on persona-driven infiltration and deep compromises of virtualisation platforms.
North Korean operators have continued to target the software development sector. The ‘Contagious Interview’ campaign targets developers with fictitious job interviews that deliver malware through coding challenges.
In 2025 alone, Unit 42 removed infections related to this campaign from more than 10 enterprise networks. There is evidence of these actors using AI to generate deepfake personas to pass remote hiring workflows, allowing them to obtain unauthorised employment.
Chinese-nexus activity has shifted towards the infrastructure layer. The ‘Phantom Taurus’ group evolved from email espionage to targeting web servers and databases directly. Investigations revealed campaigns where attackers compromised virtualisation platforms used by IT service providers, deploying malware that concealed command-and-control traffic within encrypted web sessions.
The shifting economics of extortion
The economics of extortion are also changing. While ransomware remains potent, encryption is declining. Encryption appeared in 78 percent of extortion cases in 2025, a drop from levels consistently near or above 90 percent in previous years. Attackers are finding that data theft alone often provides sufficient leverage to demand payment.
This decoupling of extortion from encryption means that the ability to restore from backups, while vital for operational continuity, does not neutralise the threat of data exposure.
Median ransom demands rose to $1.5 million in 2025, with median payments increasing to $500,000. Attackers are operating with business-like structures, including negotiation playbooks and brand reputation management.
Countering the threats
To counter these threats, security operations must also move at machine speed. The 72-minute exfiltration window renders manual response processes obsolete for the fastest attacks. Automation is required to ingest telemetry, correlate signals, and execute containment actions such as revoking tokens or isolating workloads.
Organisations must address root causes by implementing strict identity governance. This involves treating identity as a dynamic lifecycle rather than a static list of credentials. Continuous discovery of machine identities, rotation of static credentials, and the removal of standing admin rights are necessary steps to reduce the attack surface.
Zero-trust remains essential, specifically to eliminate implicit trust for users and devices after the initial login. Continuous verification of identity context and device health can detect session hijacking attempts that static perimeter controls miss.
By hardening the browser and securing the application lifecycle from code to cloud, enterprises can restrict the lateral movement that turns a minor compromise into a systemic breach.
See also: Google: Hiring, devices, and supply chains are under attack
Want to learn more about cybersecurity from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the AI & Big Data Expo. Click here for more information.
TechHQ is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
Author
- View all posts
Ryan Daws is a senior editor at TechForge Media with over a decade of experience in weaving narratives and dissecting complex topics. His articles and interviews with industry leaders have earned him recognition as a key tech influencer from numerous organisations. Under his leadership, publications have been praised by analyst firms for their excellence and performance. Connect with him on X, Mastodon, Bluesky, Threads, and/or LinkedIn.
